Lionel Sigal, head of the CTI division at CYE, details a recent C2 malware campaign in which Nobelium actors sought to compromise targets by first spying on their supply chain partners.
Threat actors have been delivering an Emotet loader through the TrickBot malware as part of "Operation Reacharound," following the disruption of Emotet by law enforcement authorities earlier this year, according to researchers from Cryptolaemus, GData and Advanced Intel.
Threat actors have been targeting users of devices running on Windows 10 with a new malware campaign that delivers malware through a compromised website on Google Chrome in an effort to exfiltrate sensitive data and cryptocurrency.
A CISA official told legislators that in the fast-moving aftermath of an emergency, a vast disparate network of public and private actors must quickly share information, including documents, images or texts. That process can be corrupted if a threat actor got organizations to share files laced with malware.
The researchers said the bug, which they trace back to a Black Hat presentation in 2013, was fixed by AWS on Oct. 1, with public disclosure coming on Wednesday.
The proposed regulation makes exceptions for exchanges of technology for the purposes of vulnerability disclosure, cyber incident response or basic software patching.
Researchers performed a large-scale analysis of a data set of malicious samples that crashed in the Zscaler Cloud Sandbox, studying coding errors to determine if there are ways to leverage vulnerabilities to prevent malware from loading in the first place.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.