‘BusySnake’ Infostealer Slithers into Critical Infrastructure Networks

A sophisticated threat group known as “Armored Likho” has infiltrated critical infrastructure networks in Russia, Brazil, and Kazakhstan, leaving a trail of sensitive data theft in its wake. This brazen campaign, which has been ongoing for several months, has caught the attention of cybersecurity researchers at Kaspersky, who have dubbed it one of the most … Read more

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors have devised a sophisticated scheme to trick employees into installing malware on their work computers, using Microsoft Teams voice calls as the entry point. By impersonating corporate IT support staff, attackers are gaining initial access to corporate networks, paving the way for further exploitation and data theft. The campaign, uncovered by Palo Alto … Read more

Phishing poses as big-brand job interview to steal Google accounts

Phishing Campaign Targets Marketing Pros with Fake Job Interviews, Steals Google Accounts A sophisticated phishing campaign has been uncovered, using over 30 well-known brands to trick marketing professionals into handing over their Google account credentials. The operation is particularly insidious, as it leverages legitimate cloud-based platforms and domain names associated with major companies like Salesforce … Read more

Vietnam arrests suspects behind HiAnime anime piracy service

A massive anime piracy operation has been brought to a halt in Vietnam, with authorities arresting seven suspects behind the popular HiAnime streaming service. The move marks a significant victory for the Alliance for Creativity and Entertainment (ACE), a coalition of media and entertainment companies that have been working tirelessly to shut down illicit streaming … Read more

Fake IT support calls on Microsoft Teams push EtherRAT malware

Cybersecurity Threat Actors Abusing Microsoft Teams to Spread Malware Threat actors have been using a sophisticated tactic to trick employees into installing malware on their computers, exploiting a vulnerability in corporate networks. The attackers are impersonating IT support staff via Microsoft Teams voice calls, convincing victims to grant remote access and ultimately downloading the EtherRAT … Read more

Phishing poses as big-brand job interview to steal Google accounts

Cyber Attackers Pose as Top Brands to Steal Google Accounts, Targeting Marketing Professionals A sophisticated phishing campaign has been uncovered, where attackers are impersonating over 30 well-known brands in fake job interviews to steal Google account credentials from marketing professionals. The operation is notable for its use of legitimate cloud-based platforms and domains associated with … Read more

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A 16-year-old flaw in the Linux KVM (Kernel-based Virtual Machine) hypervisor allows guest virtual machines on Intel and AMD x86 systems to escape their containment and gain unauthorized access to the host machine, putting thousands of servers and data centers at risk. This critical vulnerability, tracked as CVE-2022-3430, was discovered by a researcher using an … Read more

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

A sophisticated Iranian hacking group has been using a novel command and control (C2) framework called Cavern to launch targeted attacks on Israeli organizations, according to a recent analysis by experts. The hackers’ arsenal includes a range of tools designed to evade detection and compromise victims’ systems. The Cavern C2 framework is a bespoke solution … Read more

Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks

Sophisticated Malware Framework Delivers Stealthy Payloads via Compromised Websites and Social Engineering A highly complex malware delivery framework has been uncovered by Securonix, exploiting compromised websites and social engineering tactics to infect users with information stealers. Dubbed “Veil#Drop”, this multi-stage framework uses JavaScript launchers, PowerShell download cradles, and Blogspot-hosted payloads to evade traditional antivirus solutions … Read more

Vietnam arrests suspects behind HiAnime anime piracy service

Vietnam Cracks Down on Massive Anime Piracy Service, Arresting Seven Suspects Behind HiAnime In a significant blow to online piracy, Vietnamese authorities have arrested and are prosecuting seven individuals suspected of running HiAnime, one of the largest anime piracy streaming services in the world. The platform, which offered a vast library of English-subbed and dubbed … Read more