Are Malware operators using NSIS Installers to bombard Stealers and avoid detection?

Credit to Author: Tejaswini Sandapolla| Date: Fri, 21 Oct 2022 08:01:28 +0000

  Threat actors have been using new techniques to hide their codes and avoid detection in every manner….

The post Are Malware operators using NSIS Installers to bombard Stealers and avoid detection? appeared first on Quick Heal Blog | Latest computer security news, tips, and advice.

Read more

A DEEP DIVE INTO NEW 64 BIT EMOTET MODULES

Credit to Author: Tejaswini Sandapolla| Date: Tue, 18 Oct 2022 06:45:52 +0000

Emotet is usually delivered by SPAM campaigns containing document files. This self-propagating Trojan is a downloader malware that…

The post A DEEP DIVE INTO NEW 64 BIT EMOTET MODULES appeared first on Quick Heal Blog | Latest computer security news, tips, and advice.

Read more

Winnti APT group docks in Sri Lanka for new campaign

Categories: Threat Intelligence

Tags: Winnti

Tags: APT

Tags: China

Tags: Sri Lanka

Tags: India

Tags: Keyplug

Tags: malware

Tags: dropbox

Tags: C2

Tags: DBoxAgent

In this research paper, we document a new campaign we attribute to the Winnti APT group. The victims are located in Sri Lanka at a point in time where the country is going through economic hardship while China makes headlines for docking on of its special vessels there.

(Read more…)

The post Winnti APT group docks in Sri Lanka for new campaign appeared first on Malwarebytes Labs.

Read more

Beware: SOVA Android Banking Trojan emerges more powerful with new capabilities

Credit to Author: Digvijay Mane| Date: Thu, 06 Oct 2022 09:34:49 +0000

  SOVA is an Android banking Trojan with significant capabilities like credential theft, capturing keystrokes, taking screenshots, etc.,…

The post Beware: SOVA Android Banking Trojan emerges more powerful with new capabilities appeared first on Quick Heal Blog | Latest computer security news, tips, and advice.

Read more

Bogus job offers hide trojanised open-source software

Categories: News

Tags: malware

Tags: ZINC

Tags: microsoft

Tags: infection

Tags: C&C

Tags: open source

Tags: job offer

Tags: fake

Tags: LinkedIn

A North Korean ZINC group is accused of creating compromised versions of KiTTY, PuTTY, TightVNC, and other popular open-source software apps

(Read more…)

The post Bogus job offers hide trojanised open-source software appeared first on Malwarebytes Labs.

Read more

Erbium stealer on the hunt for data

Categories: News

Tags: erbium

Tags: malware

Tags: data theft

Tags: stealer

Tags: wallets

Tags: cryptocurrency

Tags: browsers

Tags: browser

Tags: infection

Tags: malware as a service

We take a look at reports of new data theft malware relying on sold old tricks

(Read more…)

The post Erbium stealer on the hunt for data appeared first on Malwarebytes Labs.

Read more

Cryptojackers growing in numbers and sophistication

Categories: News

Categories: Cryptomining

Tags: Cryptojacking

Tags: fileless

Tags: malware

Tags: LOLBins

Tags: RiskWare.BitCoinMiner

Tags: Trojan.BitCoinMiner

Tags: c2

Tags: mining pools

Probably due to rising energy costs and the volatility in crypto-currencies, we can see a rise in malicious crypto mining, aka cryptojacking.

(Read more…)

The post Cryptojackers growing in numbers and sophistication appeared first on Malwarebytes Labs.

Read more