Yokai Backdoor campaign using DLL side-loading techniques
Thai government officials are currently facing a sophisticated cyber threat as they become the primary targets of a new malware campaign utilizing a technique known as DLL side-loading....
November 2024 APT attack trends in South Korea
In November 2024, South Korea faced a surge in Advanced Persistent Threats (APTs), with spear phishing being the most prevalent attack vector. This report by AhnLab highlights key...
Unmasking north korean IT workers targeting global tech sectors
In today’s digital landscape, organizations face an escalating threat from cybersecurity attacks, leading to severe financial and reputational consequences. Cybersecurity encompasses a comprehensive arsenal of technologies, processes, and...
TeamTNT resurfaces: cybersecurity experts warn of new cloud server attacks
The notorious hacking group TeamTNT has returned with a new campaign targeting Virtual Private Server (VPS) infrastructures running on the CentOS operating system. This attack highlights the escalating...
Fileless Remcos RAT: a threat to watch out for in weaponized Excel documents
Remcos, a Remote Access Trojan (RAT), has been actively used in cybercriminal campaigns since 2016. Recently, cybersecurity researchers have uncovered a new wave of malware operations involving Excel...
Preta Power: innovative tools empower cyber enhancement initiatives
Earth Preta, the notorious Chinese Advanced Persistent Threat (APT) group, has been active for over a decade, targeting government entities, academia, and research organizations globally. Their recent addition...
Persistent backdoors via Linux pluggable authentication modules: a new threat
Recent research by the Group-IB Digital Forensics and Incident Response (DFIR) team has revealed a novel technique exploiting Linux’s Pluggable Authentication Modules (PAM) to create persistent backdoors on...
North Korean hackers targeting NPM packages
In recent weeks, the cybersecurity landscape has witnessed a concerning uptick in malicious activities targeting developers through compromised NPM (Node Package Manager) packages. Researchers from Phylum have uncovered...