According to the researchers, the attack primarily targets individuals who are searching for documents, book titles, and charts on search engines like Google.
Intrusions not only entailed the mounting adoption of device-aware phishing approaches and fingerprinting techniques for greater stealthiness but also the utilization of geolocation-based redirection to facilitate localized scams, according to a report from Zimperium ZLabs researchers.
Downloading the trojanized installers for the BeamNG.drive, Universe Sandbox, Garry's Mod, Plutocracy, and Dyson Sphere Program games uploaded to torrent sites in September triggers an installer screen luring targets to continue with the setup process when dropper extraction and execution occurs, according to an analysis from Kaspersky.
Aside from utilizing Hangul half-width and full-width characters to hide malicious code in a blank space that could be retrieved using a 'get()trap' JavaScript proxy, threat actors have also adopted base64 encoding and anit-debugging measures to further bypass analysis and detection systems, according to a report from Juniper Networks.
Malicious device-linking QR codes have not only been added to phishing pages or spread via group invite links but also leveraged in close-access attacks, as conducted by the Sandworm operation, a report from Mandiant revealed.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.