GodFather Android Banking Trojan Targeting Users of Over 400 Banking and Crypto Apps

December 22, 2022 An Android banking trojan known as GodFather is being used to target users of more than 400 banking and cryptocurrency apps spanning across 16 countries. This includes 215 banks, 94 crypto wallet providers, and 110 crypto exchange platforms serving users in the U.S., Turkey, Spain, Italy, Canada, and Canada, among others, Singapore-headquartered Group-IB said in a …

GodFather Android Banking Trojan Targeting Users of Over 400 Banking and Crypto Apps Read More »

Ransomware Hackers Using New Way to Bypass MS Exchange ProxyNotShell Mitigations

December 22, 2022 Threat actors affiliated with a ransomware strain known as Play are leveraging a never-before-seen exploit chain that bypasses blocking rules for ProxyNotShell flaws in Microsoft Exchange Server to achieve remote code execution (RCE) through Outlook Web Access (OWA). “The new exploit method bypasses URL rewrite mitigations for the Autodiscover endpoint,” CrowdStrike researchers Brian Pitchford, Article …

Ransomware Hackers Using New Way to Bypass MS Exchange ProxyNotShell Mitigations Read More »

Ukraine’s DELTA Military System Users Under Attack from Info Stealing Malware

December 22, 2022 The Computer Emergency Response Team of Ukraine (CERT-UA) this week disclosed that users of the Delta situational awareness program received phishing emails from a compromised email account belonging to the Ministry of Defense. The attacks, which have been attributed to a threat cluster dubbed UAC-0142, aimed to infect systems with two pieces of data-stealing …

Ukraine’s DELTA Military System Users Under Attack from Info Stealing Malware Read More »

Beware: Cybercriminals Launch New BrasDex Android Trojan Targeting Brazilian Banking Users

December 21, 2022 The threat actors behind the Windows banking malware known as Casbaneiro has been attributed as behind a novel Android trojan called BrasDex that has been observed targeting Brazilian users as part of an ongoing multi-platform campaign. BrasDex features a “complex keylogging system designed to abuse Accessibility Services to extract credentials specifically from a set …

Beware: Cybercriminals Launch New BrasDex Android Trojan Targeting Brazilian Banking Users Read More »

Russian Hackers Targeted Petroleum Refinery in NATO Country During Ukraine War

December 21, 2022 The Russia-linked Gamaredon group attempted to unsuccessfully break into a large petroleum refining company within a NATO member state earlier this year amid the ongoing Russo-Ukrainian war. The attack, which took place on August 30, 2022, is just one of multiple attacks orchestrated by the advanced persistent threat (APT) that’s attributed to …

Russian Hackers Targeted Petroleum Refinery in NATO Country During Ukraine War Read More »

KmsdBot Botnet Suspected of Being Used as DDoS-for-Hire Service

December 21, 2022 An ongoing analysis of the KmsdBot botnet has raised the possibility that it’s a DDoS-for-hire service offered to other threat actors. This is based on the different industries and geographies that were attacked, web infrastructure company Akamai said. Among the notable targets included FiveM and RedM, which are game modifications for Grand Theft Auto V and Red …

KmsdBot Botnet Suspected of Being Used as DDoS-for-Hire Service Read More »

FTC Fines Fortnite Maker Epic Games $275 Million for Violating Children’s Privacy Law

December 21, 2022 Epic Games has reached a $520 million settlement with the U.S. Federal Trade Commission (FTC) over allegations that the Fortnite creator violated online privacy laws for children and tricked users into making unintended purchases in the video game. To that end, the company will pay a record $275 million monetary penalty for breaching the …

FTC Fines Fortnite Maker Epic Games $275 Million for Violating Children’s Privacy Law Read More »

Microsoft Details Gatekeeper Bypass Vulnerability in Apple macOS Systems

December 21, 2022 Microsoft has disclosed details of a now-patched security flaw in Apple macOS that could be exploited by an attacker to get around security protections imposed to prevent the execution of malicious applications. The shortcoming, dubbed Achilles (CVE-2022-42821, CVSS score: 5.5), was addressed by the iPhone maker in macOS Ventura 13, Monterey 12.6.2, and Big Sur 11.7.2, describing …

Microsoft Details Gatekeeper Bypass Vulnerability in Apple macOS Systems Read More »

Researchers Discover Malicious PyPI Package Posing as SentinelOne SDK to Steal Data

December 20, 2022 Cybersecurity researchers have discovered a new malicious package on the Python Package Index (PyPI) repository that impersonates a software development kit (SDK) for SentinelOne, a major cybersecurity company, as part of a campaign dubbed SentinelSneak. The package, named SentinelOne and now taken down, is said to have been published between December 8 and 11, 2022, …

Researchers Discover Malicious PyPI Package Posing as SentinelOne SDK to Steal Data Read More »

Open Whatsapp chat
Whatsapp Us
Chat with us for faster replies.