Hermes ransomware distributed to South Koreans via recent Flash zero-day

An uncommon exploit kit adds a fresh Flash Player exploit to distribute the Hermes ransomware in South Korea.
Categories:

Exploits
Threat analysis

Tags: CVE-2018-4878EKexploit kitFashHermesransomware

(Read more…)

The post Hermes rans… Continue reading Hermes ransomware distributed to South Koreans via recent Flash zero-day

Hancitor: fileless attack with a kernel trick

Evading detection when distributing payloads is a key part of an effective malware campaign. Hancitor shows that it has yet another trick up its sleeve for that.
Categories:

Malware
Threat analysis

Tags: filelessHancitormacromalwarepayloads

Continue reading Hancitor: fileless attack with a kernel trick

A week in security (March 05 – March 11)

A roundup of notable security news from March 5 to 11, including another takedown of GeekHelp tech support scammers, a lame Android app, AI and ML in cybersecurity, Mac malware, and more.
Categories:

Security world
Week in security

Tags: Androi… Continue reading A week in security (March 05 – March 11)

Tech support scammers GeeksHelp caught again, two years later

Almost two years after exposing a group of tech support scammers, we stumbled upon them again, this time under the moniker GeeksHelp.
Categories:

Social engineering
Threat analysis

Tags: AmericaGeeksGeeksFranceGeeksHelptech support scammers

Continue reading Tech support scammers GeeksHelp caught again, two years later

Week in security (February 26 – March 4)

Last week in infosec, cryptomining kept chugging along, exploits were spotted in the wild, and a massive DDoS attack targeted GitHub.
Categories:

Security world
Week in security

Tags: filelessgerman governmentmalicious cryptominingtorrentweekly… Continue reading Week in security (February 26 – March 4)

A week in security (February 19 – February 25)

A roundup of notable news stories from February 19–25, including drive-by download attacks on Chinese websites, Deepfakes programs being paired with cryptominers, and a review of GDPR guidelines.
Categories:

Security world
Week in security… Continue reading A week in security (February 19 – February 25)

A week in security (February 12 – February 18)

A roundup of notable news stories from February 12–18, including Android cryptomining, phishing on a massive scale, Apple scams, and bug bounties.
Categories:

Security world
Week in security

Tags: Androidcryptomininghealthcareinfosecsecur… Continue reading A week in security (February 12 – February 18)

A week in security (February 5 – February 11)

We bring you an overview of what happened in cybersecurity during the last week, including new developments in drive-by cryptomining, including Mac and Android miners, and yet another abusing the fact that Deepfakes content was banned from most ma… Continue reading A week in security (February 5 – February 11)

A week in security (January 29 – February 04)

A compilation of notable security news from January 28 to February 4, featuring PUPs, a new Mac malware, two new ransomware variants, robocalls, and more.
Categories:

Security world
Week in security

Tags: a week in securitycryptominingmac malwa… Continue reading A week in security (January 29 – February 04)

GandCrab ransomware distributed by RIG and GrandSoft exploit kits

Ransomware may have slowed its growth but is still a go-to payload for threat actors looking to monetize drive-by download attacks. The latest attempt: GandCrab ransomware.
Categories:

Exploits
Threat analysis

Tags: exploit kitsgandcrabgandcrab… Continue reading GandCrab ransomware distributed by RIG and GrandSoft exploit kits