The Wonderland malware, formerly known as WretchedCat, facilitates real-time command execution and SMS theft, masquerading as Google Play or common file types.
This campaign utilizes a commodity loader that shares common features with other attack campaigns, suggesting a unified malware delivery framework used by multiple high-capability threat actors.
Fake software distribution sites and hacked YouTube accounts have been leveraged to spread the upgraded CountLoader and novel GachiLoader malware loaders, respectively, The Hacker News reports.
New malware attack campaign involves widely used sophisticated loader Manufacturing and government organizations in Europe and the Middle East have been targeted by a novel malware attack campaign that harnessed obfuscation and User Account Control bypass to facilitate the deployment of a sophisticated commodity loader leveraged by other threat operations to deliver information-stealing payloads and remote access trojans, according to The Cyber Express.
Virginia-based Richmond Behavioral Health Authority had data from 113,232 individuals stolen following a ransomware attack in late September that has been claimed by the Qilin ransomware operation, SecurityWeek reports.
Online Gladinet CentreStack file servers are already being scoured and compromised by the Clop ransomware group as part of a new data extortion campaign, reports BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.