Hijacking Trust: how Gmail and Google APIs are being weaponized for stealthy C2 channels
In the ever-evolving landscape of cybersecurity, attackers are increasingly exploiting trusted services to establish covert command-and-control (C2) channels. By leveraging platforms like Gmail and Google Drive, threat actors...
Crocodilus: a sophisticated new Android banking trojan emerges
A new Android banking trojan, dubbed Crocodilus, has been discovered targeting users primarily in Spain and Turkey. This malware isn’t just another clone; it’s a fully-fledged threat employing...
New Android spyware “KoSpy” linked to North Korean APT37
A new Android spyware, dubbed “KoSpy,” has been discovered by researchers at Lookout, adding another concerning tool to the arsenal of North Korean threat actors. This spyware, attributed...
Pegasus spyware detected on 11 of 18,000 devices during one month of testing
Recent findings from iVerify have raised alarms about the pervasive threat of Pegasus spyware, traditionally associated with high-profile targets, now extending its reach to ordinary users. The security...
RedMike (Salt Typhoon) continues global Telecom attacks
Despite widespread awareness and U.S. sanctions, the Chinese state-sponsored threat group RedMike (also known as Salt Typhoon) remains a persistent danger to telecommunications providers worldwide. Recent activity reveals...
Meta’s recent disclosure on ZeroClick WhatsApp spyware campaign
Meta-owned WhatsApp confirmed the disruption of a sophisticated spyware campaign targeting journalists and civil society members. This revelation underscores the ongoing challenges in cybersecurity and the misuse of...
Linked a newly discovered Android malware named “Tanzeem” to the APT group DoNot Team
The recent research by CYFIRMA unveils a sophisticated Android malware operation linked to the Indian APT group known as DONOT, which appears to be leveraging a seemingly innocuous...
Glutton: a new PHP backdoor
On April 29, 2024, XLab’s threat analysis system detected unusual activities linked to a new malware named Glutton, designed to stealthily infiltrate popular PHP frameworks. This malware was...