HackDig : Dig high-quality web security articles

PSA: Ongoing Webex malvertising campaign drops BatLoader

A new malvertising campaign is targeting corporate users who are downloading the popular web conferencing software Webex. Threat actors have bought an advert that impersonates Cisco's brand and is displayed first when performing a Google search. We are releasing this blog to warn users about this threat as the malicious ad has been online for almost one
Publish At:2023-09-13 22:07 | Read:137571 | Comments:0 | Tags:Threat Intelligence malvertising batloader

Ransomware review: September 2023

This article is based on research by Marcelo Rivero, Malwarebytes' ransomware specialist, who monitors information published by ransomware gangs on their Dark Web sites. In this report, "known attacks" are those where the victim did not pay a ransom. This provides the best overall picture of ransomware activity, but the true number of attacks is far hig
Publish At:2023-09-12 22:07 | Read:122109 | Comments:0 | Tags:Threat Intelligence ransomware

Mac users targeted in new malvertising campaign delivering Atomic Stealer

Summary Malicious ads for Google searches are targeting Mac users Phishing sites trick victims into downloading what they believe is the app they want The malware is bundled in an ad-hoc signed app so it cannot be revoked by Apple The payload is a new version of the recent Atomic Stealer for OSX Introduction The majority of the malvertising campaign
Publish At:2023-09-07 02:05 | Read:112040 | Comments:0 | Tags:Threat Intelligence amos apple malvertising atomic stealer w

DarkGate reloaded via malvertising and SEO poisoning campaigns

In July 2023, we observed a malvertising campaign that lured potential victims to a fraudulent site for a Windows IT management tool. Unlike previous similar attacks, the final payload was packaged differently and not immediately recognizable. The decoy file came as an MSI installer containing an AutoIT script where the payload was obfuscated
Publish At:2023-08-23 22:06 | Read:296642 | Comments:0 | Tags:Threat Intelligence darkgate autoit malvertising seo poisoni

Catching up with WoofLocker, the most elaborate traffic redirection scheme to tech support scams

Back in January 2020, we blogged about a tech support scam campaign dubbed WoofLocker that was by far using the most complex traffic redirection scheme we had ever seen. In fact, the threat actor had started deploying infrastructure in earnest as early as 2017, about 3 years prior to our publication. Fast forward to 2023, another 3 years have gone
Publish At:2023-08-17 22:06 | Read:135132 | Comments:0 | Tags:Threat Intelligence tech support scams fingerprinting stegan

Malvertisers up their game against researchers

Threat actors constantly take notice of the work and takedown efforts initiated by security researchers. In this constant game of cat and mouse chasing, tactics and techniques keep evolving from simple to more complex, and more covert. This is a trend we have observed time and time again, no matter the playing field, from exploit kits to credit car
Publish At:2023-08-17 02:04 | Read:153784 | Comments:0 | Tags:Threat Intelligence malvertising google ads malware fingerpr

Old exploit kits still kicking around in 2023

The year is 2023 and there still are some people using Internet Explorer on planet Earth. More shocking perhaps, is the fact there are still threat actors maintaining exploit kit infrastructure and dropping new malware. In this quick blog post, we review two well-known toolkits from the past, namely RIG EK and PurpleFox EK with the latest traffic captures we
Publish At:2023-08-11 22:06 | Read:314531 | Comments:0 | Tags:Threat Intelligence exploit kits eks rigek purplefoxek explo

Ransomware review: August 2023

This article is based on research by Marcelo Rivero, Malwarebytes' ransomware specialist, who monitors information published by ransomware gangs on their Dark Web sites. In this report, "known attacks" are those where the victim did not pay a ransom. This provides the best overall picture of ransomware activity, but the true number of attacks is far hig
Publish At:2023-08-10 22:06 | Read:233597 | Comments:0 | Tags:Threat Intelligence ransomware

Digital assets continue to be prime target for malvertisers

Cyber-criminals continue to impersonate brands via well-crafted phishing websites. We previously covered attacks on both consumers and businesses via online searches for popular brands leading to scams or malware. Digital assets such as cryptocurrencies or NFTs are highly coveted by threat actors due to the high gains that can be made, even via a simple
Publish At:2023-08-08 22:06 | Read:322311 | Comments:0 | Tags:Threat Intelligence malvertising nft crypto wallet bing goog

Global ransomware attacks at an all-time high, shows latest 2023 State of Ransomware report

Ransomware attacks have shown no signs of slowing down in 2023. A new report from the Malwarebytes Threat Intelligence team shows 1,900 total ransomware attacks within just four countries—the US, Germany, France, and the UK—in one year. The findings, compiled together in the 2023 State of Ransomware Report, show alarming trends in the global rans
Publish At:2023-08-03 22:05 | Read:256373 | Comments:0 | Tags:Threat Intelligence ransomware

FakeSG enters the 'FakeUpdates' arena to deliver NetSupport RAT

Over 5 years ago, we began tracking a new campaign that we called FakeUpdates (also known as SocGholish) that used compromised websites to trick users into running a fake browser update. Instead, victims would end up infecting their computers with the NetSupport RAT, allowing threat actors to gain remote access and deliver additional payloads. As w
Publish At:2023-07-18 22:05 | Read:282442 | Comments:0 | Tags:Threat Intelligence fakeupdates socgholish netsupport RAT

Ransomware review: July 2023

This article is based on research by Marcelo Rivero, Malwarebytes' ransomware specialist, who monitors information published by ransomware gangs on their Dark Web sites. In this report, "known attacks" are those where the victim did not pay a ransom. This provides the best overall picture of ransomware activity, but the true number of attacks is far hig
Publish At:2023-07-14 02:03 | Read:430014 | Comments:0 | Tags:Threat Intelligence ransomware

Criminals target businesses with malicious extension for Meta's Ads Manager and accidentally leak stolen accounts

Like all social media platforms, Facebook constantly has to deal with fake accounts, scams and malware. We have written about scams targeting consumers that redirect to fake Microsoft alert pages, but there are also threats targeting businesses that use Facebook to promote their products and services. In the past few weeks, there's been a
Publish At:2023-07-12 22:04 | Read:383933 | Comments:0 | Tags:Threat Intelligence Meta Facebook malware ads manager chrome

Malicious ad for USPS fishes for banking credentials

We often think of malvertising as being malicious ads that push malware or scams, and quite rightly so these are probably the most common payloads. However, malvertising is also a great vehicle for phishing attacks which we usually see more often via spam emails. Threat actors continue to abuse and impersonate brands, posing as verified advert
Publish At:2023-07-05 22:04 | Read:442152 | Comments:0 | Tags:Threat Intelligence malvertising google usps phishing

Ransomware review: June 2023

This article is based on research by Marcelo Rivero, Malwarebytes' ransomware specialist, who monitors information published by ransomware gangs on their Dark Web sites. In this report, "known attacks" are those where the victim didn't pay a ransom. This provides the best overall picture of ransomware activity, but the true number of attacks is far higher. I
Publish At:2023-06-09 22:03 | Read:447239 | Comments:0 | Tags:Ransomware Threat Intelligence ransomware

Announce

Share high-quality web security related articles with you:)
Tell me why you support me <3

Tag Cloud