Month: October 2024
-
Hadooken and K4Spreader: The 8220 Gangs Latest Arsenal
This analysis uncovers a significant infection chain targeting Windows and Linux systems through Oracle WebLogic vulnerabilities. The attackers, likely the…
-
Midnight Blizzard conducts largescale spearphishing campaign using RDP files
On October 22, 2024, Microsoft identified a spear-phishing campaign in which Midnight Blizzard sent phishing emails to thousands of users…
-
Strela Stealer Targets Europe Stealthily Via WebDav
Strela Stealer, first identified by DCSO in late 2022, is a type of information-stealing malware primarily designed to exfiltrate email…
-
Strela Stealer Targets Europe Stealthily Via WebDav
Strela Stealer, first identified by DCSO in late 2022, is a type of information-stealing malware primarily designed to exfiltrate email…
-
Malicious CAPTCHA delivers Lumma and Amadey Trojans
An adware campaign targets online users by presenting them with fake CAPTCHA or update prompts, tricking them into running malicious…
-
Inside the Dragon: DragonForce Ransomware Group
In this blog, Group-IB delves into the inner workings of the DragonForce ransomware group. Discovered in August 2023, DragonForce has…
-
Increased Fog and Akira Ransomware Activity Linked to SonicWall SSL VPN
Since early August, there has been a significant increase in Fog and Akira ransomware intrusions targeting SonicWall SSL VPN users…
-
Increased Fog and Akira Ransomware Activity Linked to SonicWall SSL VPN
Since early August, there has been a significant increase in Fog and Akira ransomware intrusions targeting SonicWall SSL VPN users…
-
Investigating FortiManager ZeroDay Exploitation (CVE202447575)
A new threat cluster, UNC5820, has been observed exploiting a zero-day vulnerability in FortiManager appliances across multiple industries. The vulnerability…
-
Investigating FortiManager ZeroDay Exploitation (CVE202447575)
A new threat cluster, UNC5820, has been observed exploiting a zero-day vulnerability in FortiManager appliances across multiple industries. The vulnerability…