SpyNote RAT Masquerades as Netflix App to Infect Android Devices

A new variant of the SpyNote remote access trojan (RAT) is infecting Android devices by masquerading as a mobile Netflix app. The malware, which is based off the SpyNote RAT builder leaked in 2016, displays the same icon used by the official Netflix app that’s found on Google Play. But it’s a fake. Clicking on […]… Read More

The post SpyNote RAT Masquerades as Netflix App to Infect Android Devices appeared first on The State of Security.

Continue reading SpyNote RAT Masquerades as Netflix App to Infect Android Devices

IoT Botnets Fueling Bigger and Badder DDoS Attacks, Finds Report

2017 promises to be the most challenging year yet for information security professionals. The security community will need to defend users and organizations against a host of new digital threats. In preparation for the year ahead, infosec experts should take a moment to reflect on the operational hurdles confronting them and the strategies they can […]… Read More

The post IoT Botnets Fueling Bigger and Badder DDoS Attacks, Finds Report appeared first on The State of Security.

Continue reading IoT Botnets Fueling Bigger and Badder DDoS Attacks, Finds Report

Sage 2.0 Ransomware Using Malspam and Macros to Infect Windows Users

A malspam campaign is leveraging malicious Word document macros and .js files to infect Windows users with Sage 2.0 ransomware. On 20 January, SANS Internet Storm Center handler Brad Duncan looked into a malspam campaign that’s known to drop Cerber ransomware onto victims’ machines. This campaign sends out emails without any subject lines. The only […]… Read More

The post Sage 2.0 Ransomware Using Malspam and Macros to Infect Windows Users appeared first on The State of Security.

Continue reading Sage 2.0 Ransomware Using Malspam and Macros to Infect Windows Users

NeverQuest Banking Trojan Operator Arrested by Spanish Authorities

Spanish authorities have arrested a Russian national who they believe is responsible for having helped develop and operate the NeverQuest banking trojan. On 13 January, Spain’s law enforcement agency Guardia Civil placed 32-year-old Stanislav Lisov under arrest on charges of having used electronic means to hack computers and commit fraud. Authorities converged at El Prat […]… Read More

The post NeverQuest Banking Trojan Operator Arrested by Spanish Authorities appeared first on The State of Security.

Continue reading NeverQuest Banking Trojan Operator Arrested by Spanish Authorities

EITest Corners Chrome Users with Social Engineering, Delivers Fleercivet Trojan

There are numerous ways to redirect a user to an exploit kit. Some of these methods are quite sophisticated. Take pseudo-Darkleech, for instance. This attack campaign injects malicious code into WordPress core files. That code creates a malicious iframe that redirects the user to a landing page for an exploit kit. In so doing, the […]… Read More

The post EITest Corners Chrome Users with Social Engineering, Delivers Fleercivet Trojan appeared first on The State of Security.

Continue reading EITest Corners Chrome Users with Social Engineering, Delivers Fleercivet Trojan

Satan: A New Ransomware-as-a-Service Attracting Affiliates with Free Licenses

A new ransomware-as-a-service (RaaS) called Satan is attracting amateur computer criminals on the dark web with free licenses. Once a user creates an account for Satan and logs in, they can use the provided affiliate console to customize their ransomware campaign. The criminal can use the “Malwares” page, for instance, to specify Satan’s ransom amount, […]… Read More

The post Satan: A New Ransomware-as-a-Service Attracting Affiliates with Free Licenses appeared first on The State of Security.

Continue reading Satan: A New Ransomware-as-a-Service Attracting Affiliates with Free Licenses