BleepingComputer reports that initial access broker Storm-0249 has moved to exploiting SentinelOne endpoint detection and response to facilitate stealthier attacks after initially launching widespread phishing intrusions.
The Broadside botnet, a modification of the decade-old Mirai, employs a custom command and control protocol and unique modules for stealth and evasion.
Attacks with the new UDPGangster backdoor exploiting User Datagram Protocol for command-and-control have been launched by Iranian state-backed threat operation MuddyWater against Azerbaijan, Israel, and Turkey as part of a cyberespionage campaign, The Hacker News reports.
ChimeraWire operates by automating searches, loading target websites, and simulating clicks using a hidden instance of Chrome downloaded and run in debug mode.
The group, which allegedly stole over 200 million rubles (approximately $2.6 million), distributed a malicious mobile application through WhatsApp and Telegram, disguised as legitimate banking software.
Threat actors have continued leveraging USB drives to spread the CoinMiner cryptocurrency mining malware as part of an ongoing attack campaign aimed at South Korean workstations, Cyber Security News reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.