Tag

Backdoor

All articles tagged with #backdoor

Lazarus Group Exploits Windows Zero-Day to Deploy Backdoor Worldwide
technology12 days ago

Lazarus Group Exploits Windows Zero-Day to Deploy Backdoor Worldwide

North Korea’s Lazarus Group exploited a Windows zero-day (CVE-2026-68820) to gain SYSTEM privileges and install a backdoor named Troy as part of Operation Dream Job, targeting defense and aerospace firms in France, Germany, Brazil and India. The campaign blends social engineering (fake LinkedIn recruiters) with a trojanized SecurityPDF viewer to trigger a DLL side-loading chain, dropping the MISTPEN downloader and ForestTiger/ScoringMathTea for remote access, while hijacking compromised WordPress/SharePoint/Roundcube infrastructure for C2 via Microsoft Graph API/OneDrive and using AFD.sys privilege escalation to stay hidden.

Mac malware ClickLock uses fake Terminal prompts to steal passwords
technology1 month ago

Mac malware ClickLock uses fake Terminal prompts to steal passwords

ClickLock is a Mac malware campaign that tricks users with a fake verification page prompting Terminal input; once run, it stealthily downloads payloads to steal passwords, browser data, crypto wallets and other data, and installs a persistent backdoor via LaunchAgents. It can close apps to pressure password entry, with exfiltration via Telegram Bot API. Group-IB reports at least 100 infected systems in 33 countries since May. To stay safe: never paste commands from suspicious pages, boot in Safe Mode if compromised, keep macOS updated, use reputable antivirus, and secure accounts from another device.

Backdoor Flaw Threatens Several Tenda Routers, CERT Warns
technology1 month ago

Backdoor Flaw Threatens Several Tenda Routers, CERT Warns

Researchers from CERT at Carnegie Mellon University have identified a login bypass embedded in several older Tenda router firmwares that can grant an attacker administrator access simply by using a specific password, regardless of the username. This could enable traffic redirection, opening network ports to devices, ransomware installation, man‑in‑the‑middle attacks, or locking users out of their own router. Affected models include FH1201, W15E, AC10 v1, AC5 v1, and AC6 v2, and there is no confirmed patch yet. Mitigations include disabling remote web management, verifying firmware versions via the router interface (usually at 192.168.0.1), and changing the LAN IP to another private address or considering a replacement if needed.

ClickLock: macOS malware coerces password entry to steal data and plant a backdoor
security1 month ago

ClickLock: macOS malware coerces password entry to steal data and plant a backdoor

A new macOS information-stealing malware named ClickLock uses social engineering and a fake Cloudflare verification to force users into typing their system login password, exfiltrates credentials, browser data and wallet information, and installs a persistent backdoor via two LaunchAgent components; it suppresses notifications, runs password-dialog loops for hours or days, and uploads stolen data through Telegram while maintaining persistence for weeks, with infections in 33 countries and at least 100 observed since May. Defenders are advised to avoid pasting unknown Terminal commands and to boot into Safe Mode if prompted for a password.

Hackers Hide in Linux Login Gateways, Persisting for a Decade
technology2 months ago

Hackers Hide in Linux Login Gateways, Persisting for a Decade

A China-linked group known as Velvet Ant spent nearly a decade quietly compromising the Linux login stack (PAM and OpenSSH), replacing trusted login binaries with backdoors that harvest credentials and commands and, in some cases, accept secret passwords. They first breached internet-facing systems to reach an isolated network, then lurked inside the login process itself, making containment difficult. The operation adds to the group's history of targeting infrastructure such as F5 BIG-IP appliances and Cisco NX-OS devices (CVE-2024-20399). The recommended defense is integrity-based: monitor and compare PAM/OpenSSH binaries and key files against known-good copies, test replacements in a lab, and perform careful cleanup before resets. Patching alone won’t suffice when the login layer itself is compromised.

YellowKey sparks backdoor debate as BitLocker bypass claim surfaces
technology3 months ago

YellowKey sparks backdoor debate as BitLocker bypass claim surfaces

A security researcher known as Nightmare-Eclipse released YellowKey, a vulnerability they say can bypass BitLocker full-disk encryption, reportedly enabling unrestricted access to protected volumes after copying an FsTx folder to a USB drive or the EFI partition and rebooting into Windows Recovery Environment. The researcher alleges this points to an intentional backdoor in a WinRE component present in Windows 11 and some Server 2022/2025 images (Windows 10 allegedly unaffected), and also introduced a second exploit, GreenPlasma, for privilege escalation. Some third-party researchers reportedly corroborate aspects of YellowKey in public GitHub materials, though full PoC details were not published and Microsoft has not publicly commented. Mitigation suggestions include not relying on a single encryption system and considering alternatives like VeraCrypt. Further details are expected around Patch Tuesday.

DirtyFrag Drives Linux Privilege Escapes, Ubuntu Offline, and a Wave of Security Breaches
security3 months ago

DirtyFrag Drives Linux Privilege Escapes, Ubuntu Offline, and a Wave of Security Breaches

DirtyFrag chains CopyFail and a new RPC flaw to corrupt the Linux page cache, enabling root-level code execution and potential persistence or container escapes with no patches yet; Ubuntu endured a prolonged DDoS outage that knocked update services offline; ShinyHunters breached the education software provider Infrastructure, exposing Canvas student data; other notes include Edge password vault memory exposure and DaemonTools backdoored, with continued TETRA-related activity and Oracle shifting to monthly security updates.

Stealthy Python RAT Uses Hidden C2 Tunnel to Harvest Browser and Cloud Credentials
technology3 months ago

Stealthy Python RAT Uses Hidden C2 Tunnel to Harvest Browser and Cloud Credentials

Security researchers uncovered DEEP#DOOR, a Python-based backdoor that embeds its payload in a dropper and gains persistence via Startup scripts, Run keys, Scheduled Tasks, and optional WMI subscriptions. It uses a Rust-based tunneling service (bore.pub) for C2 and offers full RAT capabilities—reverse shell, reconnaissance, keylogging, screen/audio capture, webcam access, and credential theft from browsers, cloud services, and Windows Credential Manager—while employing anti-analysis and defense-evasion techniques. Distribution appears phishing-based and targeted, with a modular, fileless design; it could be repurposed by different actors.

Batch of 108 Chrome extensions steals Google and Telegram data from about 20,000 users
technology4 months ago

Batch of 108 Chrome extensions steals Google and Telegram data from about 20,000 users

Researchers uncovered a campaign of 108 Chrome extensions that funnel user data to a shared command-and-control backend, stealing Google account credentials via OAuth2, exfiltrating Telegram sessions, stripping security headers, and injecting ads and arbitrary scripts across every page you visit, in a campaign affecting roughly 20,000 installs. The extensions masqueraded as Telegram clients, gaming tools, and video enhancers, making the backdoor hard to spot; users should remove these extensions and log out of Telegram Web immediately.

Fake Moltbot VS Code Extension Delivers Stealth Remote-Access Backdoor
technology6 months ago

Fake Moltbot VS Code Extension Delivers Stealth Remote-Access Backdoor

Security researchers flagged a fake Moltbot AI coding assistant extension for Visual Studio Code that auto-runs on launch, fetches payloads from malicious domains, and installs a remote-access backdoor (via ScreenConnect) with a DLL sideloading fallback, highlighting broader Moltbot misconfigurations and credential exposure across deployments.

Chinese Hackers Deploy BRICKSTORM Malware to Target U.S. Legal and Tech Sectors
cybersecurity11 months ago

Chinese Hackers Deploy BRICKSTORM Malware to Target U.S. Legal and Tech Sectors

A suspected China-linked cyber espionage group, UNC5221, is using the sophisticated BRICKSTORM backdoor to infiltrate U.S. legal, tech, and SaaS sectors, maintaining long-term stealthy access to steal sensitive information and potentially exploit zero-day vulnerabilities, with ongoing development and active deployment across multiple systems.

Hackers Exploit Zero-Day Flaw in Sitecore for Backdoors and Malware
cybersecurity11 months ago

Hackers Exploit Zero-Day Flaw in Sitecore for Backdoors and Malware

Threat actors exploited a zero-day vulnerability in legacy Sitecore systems (CVE-2025-53690) involving a ViewState deserialization flaw caused by reused sample ASP.NET machine keys, leading to remote code execution and deployment of reconnaissance malware WeepSteel. The attack involved multi-stage exploits including privilege escalation and persistence techniques. Sitecore recommends immediate replacement and encryption of static machine keys to mitigate the vulnerability.

GhostRedirector: A New China-Aligned Threat Targeting Windows Servers
cybersecurity11 months ago

GhostRedirector: A New China-Aligned Threat Targeting Windows Servers

ESET researchers uncovered GhostRedirector, a China-aligned threat actor that compromised at least 65 Windows servers mainly in Brazil, Thailand, and Vietnam, using custom tools like the passive backdoor Rungan and the malicious IIS module Gamshen to facilitate SEO fraud and maintain persistent access, with activities dating back to at least August 2024.