FIN8 Group Using Modified Sardonic Backdoor for BlackCat Ransomware Attacks

19/07/2023 0 Comments 0 tags

The financially motivated threat actor known as FIN8 has been observed using a “revamped” version of a backdoor called Sardonic to deliver the BlackCat ransomware. According to the Symantec Threat Hunter Team, part

Go Beyond the Headlines for Deeper Dives into the Cybercriminal Underground

19/07/2023 0 Comments 0 tags

Discover stories about threat actors’ latest tactics, techniques, and procedures from Cybersixgill’s threat experts each month. Each story brings you details on emerging underground threats, the threat actors involved, and

VirusTotal Data Leak Exposes Some Registered Customers’ Details

19/07/2023 0 Comments 0 tags

Data associated with a subset of registered customers of VirusTotal, including their names and email addresses, were exposed after an employee inadvertently uploaded the information to the malware scanning platform.

Pakistani Entities Targeted in Sophisticated Attack Deploying ShadowPad Malware

19/07/2023 0 Comments 0 tags

An unidentified threat actor compromised an application used by multiple entities in Pakistan to deliver ShadowPad, a successor to the PlugX backdoor that’s commonly associated with Chinese hacking crews. Targets included a

Cybercriminals Exploiting WooCommerce Payments Plugin Flaw to Hijack Websites

18/07/2023 0 Comments 0 tags

Threat actors are actively exploiting a recently disclosed critical security flaw in the WooCommerce Payments WordPress plugin as part of a massive targeted campaign. The flaw, tracked as CVE-2023-28121 (CVSS score: 9.8),

Owner of BreachForums Pleads Guilty to Cybercrime and Child Pornography Charges

18/07/2023 0 Comments 0 tags

Conor Brian Fitzpatrick, the owner of the now-defunct BreachForums website, has pleaded guilty to charges related to his operation of the cybercrime forum as well as having child pornography images.

JumpCloud Blames ‘Sophisticated Nation-State’ Actor for Security Breach

18/07/2023 0 Comments 0 tags

A little over a week after JumpCloud reset API keys of customers impacted by a security incident, the company said the intrusion was the work of a sophisticated nation-state actor. The adversary

CERT-UA Uncovers Gamaredon’s Rapid Data Exfiltration Tactics Following Initial Compromise

17/07/2023 0 Comments 0 tags

The Russia-linked threat actor known as Gamaredon has been observed conducting data exfiltration activities within an hour of the initial compromise. “As a vector of primary compromise, for the most

Cybercriminals Exploit Microsoft Word Vulnerabilities to Deploy LokiBot Malware

17/07/2023 0 Comments 0 tags

Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware called LokiBot on compromised systems. “LokiBot, also known as Loki PWS, has been a

Malicious USB Drives Targetinging Global Targets with SOGU and SNOWYDRIVE Malware

17/07/2023 0 Comments 0 tags

Cyber attacks using infected USB infection drives as an initial access vector have witnessed a three-fold increase in the first half of 2023,  That’s according to new findings from Mandiant,