Tonto Team Uses Anti-Malware File to Launch Attacks on South Korean Institutions

28/04/2023 0 Comments 0 tags

South Korean education, construction, diplomatic, and political institutions are at the receiving end of new attacks perpetrated by a China-aligned threat actor known as the Tonto Team. “Recent cases have revealed

Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware

27/04/2023 0 Comments 0 tags

Microsoft has confirmed that the active exploitation of PaperCut servers is linked to attacks that are designed to deliver Cl0p and LockBit ransomware families. The tech giant’s threat intelligence team is attributing

RTM Locker’s First Linux Ransomware Strain Targeting NAS and ESXi Hosts

27/04/2023 0 Comments 0 tags

The threat actors behind RTM Locker have developed a ransomware strain that’s capable of targeting Linux machines, marking the group’s first foray into the open source operating system. “Its locker ransomware infects

LimeRAT Malware Analysis: Extracting the Config

27/04/2023 0 Comments 0 tags

Remote Access Trojans (RATs) have taken the third leading position in ANY. RUN’s Q1 2023 report on the most prevalent malware types, making it highly probable that your organization may face this

Paperbug Attack: New Politically-Motivated Surveillance Campaign in Tajikistan

27/04/2023 0 Comments 0 tags

A little-known Russian-speaking cyber-espionage group has been linked to a new politically-motivated surveillance campaign targeting high-ranking government officials, telecom services, and public service infrastructures in Tajikistan. The intrusion set, dubbed Paperbug by

Chinese Hackers Spotted Using Linux Variant of PingPull in Targeted Cyberattacks

26/04/2023 0 Comments 0 tags

The Chinese nation-state group dubbed Alloy Taurus is using a Linux variant of a backdoor called PingPull as well as a new undocumented tool codenamed Sword2033. That’s according to findings from Palo

Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks

26/04/2023 0 Comments 0 tags

The maintainers of the Apache Superset open source data visualization software have released fixes to plug an insecure default configuration that could lead to remote code execution. The vulnerability, tracked as CVE-2023-27524 (CVSS score:

Browser Security Survey: 87% of SaaS Adopters Exposed to Browser-borne Attacks

26/04/2023 0 Comments 0 tags

The browser serves as the primary interface between the on-premises environment, the cloud, and the web in the modern enterprise. Therefore, the browser is also exposed to multiple types of

Chinese Hackers Using MgBot Malware to Target International NGOs in Mainland China

26/04/2023 0 Comments 0 tags

The advanced persistent threat (APT) group referred to as Evasive Panda has been observed targeting an international non-governmental organization (NGO) in Mainland China with malware delivered via update channels of legitimate applications

Charming Kitten’s New BellaCiao Malware Discovered in Multi-Country Attacks

26/04/2023 0 Comments 0 tags

The prolific Iranian nation-state group known as Charming Kitten targeted multiple victims in the U.S., Europe, the Middle East and India with a novel malware dubbed BellaCiao, adding to its ever-expanding list of