ClickFix: Fake Windows Updates and PNG Steganography Make a Darker Play for User Machines
For those deeply involved with cybersecurity, the past few years have seen a dramatic rise in sophisticated phishing campaigns leveraging social engineering to deliver malware onto unsuspecting victims....
How Hackers are using Open-Source repositories to steal crypto
A new wave of malware targeting cryptocurrency users is hitting developers hard, showcasing the growing sophistication and accessibility of attacks in 2023. The root cause? A well-executed supply...
ToddyCat’s new tricks: email hacking evolves with the cloud
The age-old adage “if it ain’t broke, don’t fix it” doesn’t always hold true in cybersecurity. As attackers are increasingly leveraging cloud services to protect sensitive data, their...
APT24: three years of obscure espionage with the “BadAudio” download
For years, APT24, a sophisticated cyber espionage group linked to China’s People’s Republic, has been quietly crafting targeted attacks against key players across global industries. Their latest offensive...
Nova Stealer: macOS cryptocurrency theft
The cybersecurity landscape is consistently shaped by increasingly sophisticated threats, and the latest to garner significant attention is Nova Stealer – a meticulously crafted malware campaign specifically targeting...
The Payroll Pirates: a malvertising and layered attack infrastructure
The “Payroll Pirates,” as Check Point researchers have dubbed them, represent a particularly insidious threat – a coordinated campaign targeting payroll systems, credit unions, and trading platforms across...
SmartApeSG: the persistent evolution of a ClickFix-based RAT campaign
The SmartApeSG campaign, previously identified by aliases like ZPHP and HANEY MANEY, continues to demonstrate a remarkable capacity for adaptation, moving beyond initial tactics of deceptive browser update...
Sophos exposes massive GitHub campaign distributing backdoored malware
A sophisticated malware campaign targeting hackers, gamers, and cybersecurity researchers has been uncovered on GitHub, leveraging fake exploits, game cheats, and open-source tools to distribute backdoors. The operation,...