Threat actors have been leveraging link wrapping services for clandestine malware delivery as part of a new phishing campaign aimed at credential exfiltration, reports The Hacker News.
Users of the Python Package Index repository are being targeted by an ongoing phishing scheme redirecting to fraudulent PyPI sites that facilitate credential pilfering activities, The Hacker News reports.
Attacks spreading the EAGLET information-stealing backdoor have been deployed by the threat operation UNG0901 against aerospace and defense organizations across Russia, according to The Hacker News.
A new malware called CastleLoader has been targeting devices through campaigns delivering a variety of information stealers and remote access trojans, according to The Hacker News.
Zimperium warns of 'SarangTrap' malware disguised as dating, networking apps Zimperium released a report on Wednesday uncovering a large-scale malware campaign called SarangTrap that uses fake dating and social networking apps to steal sensitive personal data, Infosecurity Magazine reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.