FormBook Malware Bypasses Microsoft Patch

FormBook Malware Bypasses Microsoft Patch

Researchers have detected the use of a novel exploit able to bypass a patch for a critical vulnerability CVE-2021-40444 affecting the Microsoft Office file format. The attackers took a publicly…

Discord Servers Hijacked By Malicious NPM Packages

Researchers discovered 17 malicious packages in the NPM (Node.js package manager) repository that were developed to hijack Discord servers. The libraries allow stealing access tokens and environment variables from systems running giving…

Emotet Directs Cobalt Strike Now !

Emotet now directly installs the Cobalt Strike Beacon, giving threat actors immediate network access and making ransomware attacks imminent. Ironically, Emotet is a malware that spreads by spam emails containing…
CEELoader added to Nobelium Arsenal

CEELoader added to Nobelium Arsenal

Researchers have identified two distinct clusters of activity, tracked UNC3004 and UNC2652, that were associated with the Russia-linked Nobelium APT group (aka UNC2452). The NOBELIUM APT is the threat actor…
New BazarLoader TTP

New BazarLoader TTP

BazarLoader, the nasty information stealer, is now using new delivery methods that include compromised software installers and ISO files. The variations in the arrival mechanism seem to be an attempt…

Huawei App Gallery Malvertised

Millions of Android devices have been infected by a new class of malware that disguises itself as dozens of arcade, shooter, and strategy games on Huawei's App Gallery marketplace to…