Latest Cybersecurity News and Articles


Carbanak Banking Malware Resurfaces with New Ransomware Tactics

26 December 2023
The banking malware known as Carbanak has been observed being used in ransomware attacks with updated tactics. "The malware has adapted to incorporate attack vendors and techniques to diversify its effectiveness," cybersecurity firm NCC Group said in an analysis of ransomware attacks that took place in November 2023. "Carbanak returned last month through new

Cloud Atlas' Spear-Phishing Attacks Target Russian Agro and Research Companies

25 December 2023
The threat actor referred to as Cloud Atlas has been linked to a set of spear-phishing attacks on Russian enterprises. Targets included a Russian agro-industrial enterprise and a state-owned research company, according to a report from F.A.C.C.T., a standalone cybersecurity company formed after Group-IB's formal exit from Russia earlier this year. Cloud Atlas, active since at

British LAPSUS$ Teen Members Sentenced for High-Profile Attacks

24 December 2023
Two British teens part of the LAPSUS$ cyber crime and extortion gang have been sentenced for their roles in orchestrating a string of high-profile attacks against a number of companies. Arion Kurtaj, an 18-year-old from Oxford, has been sentenced to an indefinite hospital order due to his intent to get back to cybercrime "as soon as possible," BBC reported. Kurtaj, who is autistic, was

UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware

23 December 2023
The LONEPAGE malware, deployed through phishing messages and malicious attachments, can contact a command-and-control server to retrieve additional payloads and carry out activities like keylogging and stealing screenshots.

ESET Fixed a High-Severity Bug in the Secure Traffic Scanning Feature of Several Products

23 December 2023
The vulnerability was due to improper validation of server certificates, allowing browsers to trust sites with certificates signed with outdated algorithms. ESET has released security patches and is not aware of any attacks exploiting this flaw.

Real Estate Agency Exposes Details of 690K Customers in Dubai

23 December 2023
The leaked data included personal information such as names, emails, phone numbers, and scanned copies of receipts, checks, contracts, and IDs, increasing the likelihood of targeted scams and unauthorized access to sensitive accounts.

Bandook - A Persistent Threat That Keeps Evolving

23 December 2023
Bandook malware, a remote access trojan, has evolved with a new variant that uses a PDF file to distribute its payload and injects it into msinfo32.exe, allowing remote attackers to gain control of infected systems.

Experts Detail Multi-Million Dollar Licensing Model of Predator Spyware

23 December 2023
A new analysis of the Predator spyware reveals that it now has the ability to persist between reboots on infected Android systems. Predator, developed by the Intellexa Alliance, is a sophisticated commercial spyware sold on a licensing model.

Ukrainian Hackers Claim Attack on Popular Russian CRM Provider

23 December 2023
A group of Ukrainian hackers known as the IT Army claimed responsibility for disrupting the operations of Bitrix24, a Russian provider of customer relationship management (CRM) services.

Online Platform Carousell Violated Hong Kong Privacy Laws, Watchdog Finds

23 December 2023
The violation comes after the personal data of over 320,000 local users was discovered being sold on the dark web. Carousell reported the incident last year, attributing it to a loophole exploited by hackers in its system migration process.

Cyber-Espionage Group Cloud Atlas Targets Russian Companies With War-Related Phishing Attacks

23 December 2023
The hacker group known as Cloud Atlas has recently targeted a Russian agro-industrial enterprise and a state-owned research company in an espionage campaign. The group, believed to be state-backed, primarily attacks Russia and surrounding countries.

Crypto Drainer Steals $59 Million From 63K People in Twitter Ad Push

23 December 2023
The MS Drainer operates through phishing websites, tricking users into approving malicious contracts and transferring their money to the attacker's wallet address without their consent.

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft

22 December 2023
Threat hunters have discovered a rogue WordPress plugin that's capable of creating bogus administrator users and injecting malicious JavaScript code to steal credit card information. The skimming activity is part of a Magecart campaign targeting e-commerce websites, according to Sucuri. "As with many other malicious or fake WordPress plugins it contains some deceptive information at

Android Banking Trojan Chameleon can Now Bypass Any Biometric Authentication

22 December 2023
The Chameleon banking trojan has evolved with new advanced features, including the ability to bypass biometric prompts and display HTML pages for enabling Accessibility Services on Android 13, making it a potent threat to mobile banking security.

Operation RusticWeb: Rust-Based Malware Targets Indian Government Entities

22 December 2023
Indian government entities and the defense sector have been targeted by a phishing campaign that's engineered to drop Rust-based malware for intelligence gathering. The activity, first detected in October 2023, has been codenamed Operation RusticWeb by enterprise security firm SEQRITE. "New Rust-based payloads and encrypted PowerShell commands have been utilized to exfiltrate

BidenCash Dark Web Marketplace Leaks 1.6 Million Credit Card Details

22 December 2023
Unlike a previous leak, this one does not include names or emails of cardholders. While the absence of names reduces the risk of identity theft, the leaked financial details still pose a significant risk for unauthorized transactions.

Decoy Microsoft Word Documents Used to Deliver Nim-Based Malware

22 December 2023
A new phishing campaign is leveraging decoy Microsoft Word documents as bait to deliver a backdoor written in the Nim programming language. "Malware written in uncommon programming languages puts the security community at a disadvantage as researchers and reverse engineers' unfamiliarity can hamper their investigation," Netskope researchers Ghanashyam Satpathy and Jan Michael Alcantara 

Iran’s Peach Sandstorm Group Deploys FalseFont Backdoor Against Defense Sector

22 December 2023
FalseFont is a custom backdoor with various capabilities that allow operators to remotely access compromised systems, execute files, and transmit information to Command and Control servers.

New Rules in UK Could Reimburse Fraud Victims up to £415,000 ($525,000)

22 December 2023
The UK's Payment Systems Regulator (PSR) announced that victims could be repaid up to £415,000 ($525,000) unless the bank can prove "gross negligence" on the part of the individual.

BattleRoyal Threat Cluster Spread DarkGate RAT via Email and Fake Browser Updates

22 December 2023
The BattleRoyal cluster, using DarkGate and NetSupport malware, demonstrates the use of multiple attack chains and social engineering techniques to deliver payloads via email and fake update lures.