The Russian threat group Fancy Bear appears to be behind a recent campaign that may have targeted Italy's navy with an updated version of the APT group's XAgent backdoor malware, according to researchers.
There is no doubt the World Cup has a negative impact on business productivity, but it may come as a surprise to find cybercriminals are no different and take the day off when their nation's squad is playing.
An ongoing malware campaign that attempts to exploit web servers susceptible to the Drupalgeddon 2.0 bug in order to infect them with an XMRig-based cryptominer has generated around $11,000 in profits since commencing last April and peaking on May 20.
Cybercriminals managed to again compromise the Ammyy Admin website, this time on June 13 and 14 they managed to have it serve malware in addition to the site's legitimate free remote administration tool.
The breach occurred between March 1, 2017 and May 8, 2018, and hackers may have walked away with card numbers, names, expiration dates, internal verification codes and other payment data.
A cryptojacking operation that injects legitimate websites with secret Coinhive shortlinks was recently discovered to be part of an even larger malicious infrastructure that redirects innocent site visitors to servers that distribute both web-based and standard cryptominers.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.