TeamTNT resurfaces: cybersecurity experts warn of new cloud server attacks
The notorious hacking group TeamTNT has returned with a new campaign targeting Virtual Private Server (VPS) infrastructures running on the CentOS operating system. This attack highlights the escalating...
Fileless Remcos RAT: a threat to watch out for in weaponized Excel documents
Remcos, a Remote Access Trojan (RAT), has been actively used in cybercriminal campaigns since 2016. Recently, cybersecurity researchers have uncovered a new wave of malware operations involving Excel...
Preta Power: innovative tools empower cyber enhancement initiatives
Earth Preta, the notorious Chinese Advanced Persistent Threat (APT) group, has been active for over a decade, targeting government entities, academia, and research organizations globally. Their recent addition...
Persistent backdoors via Linux pluggable authentication modules: a new threat
Recent research by the Group-IB Digital Forensics and Incident Response (DFIR) team has revealed a novel technique exploiting Linux’s Pluggable Authentication Modules (PAM) to create persistent backdoors on...
North Korean hackers targeting NPM packages
In recent weeks, the cybersecurity landscape has witnessed a concerning uptick in malicious activities targeting developers through compromised NPM (Node Package Manager) packages. Researchers from Phylum have uncovered...
Escalating iranian cyber influence operations ahead of the 2024 US elections
As the 2024 US presidential election looms, the Microsoft Threat Analysis Center (MTAC) has unveiled an alarming uptick in cyber-enabled influence operations orchestrated by Iranian actors, marking a...
SharpRhino: the emerging C# RAT from Hunters International
In late 2023, the ransomware group Hunters International emerged on the cyber threat landscape, drawing attention due to their sophisticated tactics and tools. Recently, researchers at Quorum Cyber...
Analysis of NetSupport RAT campaigns by Cisco Talos
In recent months, Cisco Talos has heightened its monitoring efforts concerning malicious campaigns centered around the NetSupport Remote Access Trojan (RAT). The emergence of these campaigns signifies an...