E-commerce targeted by GuLoader malware attacks E-commerce organizations in the U.S., South Korea, Saudi Arabia, Japan, Taiwan, and Germany are being subjected to ongoing GuLoader malware attacks that involved the use of Nullsoft Scriptable Install System executables rather than malicious Word documents for malware distribution, according to The Hacker News.
BleepingComputer reports that more threat actors have been leveraging Microsoft Visual Studio Tools for Office to enable .NET-based malware integration within Office add-ins after Microsoft moved to block VBA and XL4 macro execution in Office by default.
Cybercriminals have been launching malvertising attacks to facilitate the distribution of virtualized .NET loaders, dubbed "MalVirt," that deploy the Formbook and newer XLoader information-stealing malware strains, both of which have keylogging, credential theft, and additional malware staging capabilities, reports The Register.
The surge comes after malicious actors impersonated well-known brands such as Adobe Reader and Microsoft Teams to deliver numerous malware strains, including AuroraStealer, IcedID, Meta Stealer, RedLine Stealer and Vidar.
At least 1,200 Redis database servers worldwide have been compromised by a sophisticated piece of malware since September 2021, while more than 2,800 uninfected servers remain at high risk of exploitation.