Tag

Malware Campaign

All articles tagged with #malware campaign

Crypto-Theft via Trusted-Looking Extensions: 19 Chrome/Edge Add-Ins Harbor Hidden Malware
security11 hours ago

Crypto-Theft via Trusted-Looking Extensions: 19 Chrome/Edge Add-Ins Harbor Hidden Malware

Security researchers uncovered 19 Chrome/Edge extensions that mask legitimate functionality while stealing wallet data and draining crypto. The campaign, tracked as Superior by Socket, updates compromised extensions with malicious code after initial benign versions, establishing C2 channels via WebSocket, rotating endpoints, and per‑victim exfiltration. The extensions strip CSP headers to inject 16 malicious modules—ranging from seed-phrase harvesters to credential grabbers—enabling broad data theft. One lead extension, 'Enable Right Click & Copy — Smart Unlock + OCR,' has about 80,000 installs. The attackers reportedly acquired some legitimate extensions or bought them; the operation has been ongoing since February 2024, with broader scope than previously believed. Attribution remains unknown.

"DarkGate Malware Exploits Unpatched Windows Flaw in Zero-Day Attack"
cybersecurity2 years ago

"DarkGate Malware Exploits Unpatched Windows Flaw in Zero-Day Attack"

A DarkGate malware campaign exploited a recently patched Microsoft Windows flaw in a zero-day attack, using bogus software installers and Google DoubleClick Digital Marketing open redirects to lead victims to compromised sites hosting the vulnerability. The attack chain involved phishing emails with PDF attachments, open redirects, and fake software installers to deliver the DarkGate malware. Additionally, counterfeit installers for popular software like Adobe Reader and Notion are being used to distribute information stealers, while new stealer malware families like Planet Stealer and Tweaks are being exploited through platforms like YouTube and Discord. Malvertising and social engineering campaigns are also being used to disseminate a wide range of stealer and remote access trojans.

"Ars Technica Targeted in Unprecedented Malware Campaign with Advanced Obfuscation"
cybersecurity2 years ago

"Ars Technica Targeted in Unprecedented Malware Campaign with Advanced Obfuscation"

Security firm Mandiant reported a never-before-seen malware campaign that used Ars Technica and Vimeo to serve second-stage malware, employing obfuscation techniques to cover its tracks. The campaign, attributed to threat actor UNC4990, involved embedding malicious strings in benign content on the websites, which were automatically retrieved by devices infected with the first-stage malware. This novel approach, along with previous techniques used by UNC4990, demonstrates a sophisticated and evolving threat landscape in cybersecurity.