Identified a Python-based backdoor used by RansomHub affiliate to spread encryptors
In a recent incident response analysis, GuidePoint Security has uncovered a sophisticated use of a Python-based backdoor by a threat actor affiliated with RansomHub. This development highlights a...
The FBI and DOJ have successfully removed PlugX malware from thousands of U.S. computers
In a cyber operation, the U.S. Department of Justice (DOJ) and the FBI have successfully removed the PlugX malware from over 4,200 computers across the United States. This...
Amazon S3 buckets targeted by new ransomware attacks
A new wave of ransomware attacks has emerged, targeting Amazon Web Services (AWS) by exploiting its Server-Side Encryption with Customer Provided Keys (SSE-C). This tactic allows threat actors...
WordPress threats targeting website with credit card skimmer
A new wave of cyber threats has emerged, targeting WordPress websites with a sophisticated credit card skimmer that operates through database injections. This malware, which stealthily embeds itself...
HexaLocker V2: double extortion and Skuld Stealer
The notorious HexaLocker ransomware has resurfaced with a revamped version, HexaLocker V2, which is now being disseminated through the Skuld Stealer. This new iteration introduces advanced functionalities that...
3.1 million fake “stars” on GitHub projects
A recent study has unveiled a troubling trend on GitHub, revealing that over 3.1 million fake “stars” have been used to artificially inflate the popularity of certain projects....
North Korean threat actors adopt infostealer spreading tactics
In a recent development, North Korean hackers have adopted advanced malware distribution techniques reminiscent of the notorious Clickfix campaigns, marking a significant evolution in their cybercrime strategies. This...
Captcha abuse attack
Cybersecurity experts at ReliaQuest have recently uncovered a troubling trend in cybercrime: the use of fake CAPTCHA pages to distribute malware. This tactic has seen a significant rise...