New Magniber Ransomware Targets South Korea, Asia Pacific

Researchers identified a new ransomware family called Magniber that uniquely only targets users in South Korea and the Asia Pacific regions. Continue reading New Magniber Ransomware Targets South Korea, Asia Pacific

Another change with Locky delivery methods today. Payload embedded in a large .js file

The next in the never ending series of Locky downloaders is an email with a blank / empty subject   pretending to come from random names and email addresses. The body content pretends to be an invoice notification.  There are no attachments with these emails but a link in the email body Continue reading → Continue reading Another change with Locky delivery methods today. Payload embedded in a large .js file

Week in Security (August 7 – August 13)

A compilation of security news and blog posts from Monday the 7th of August to August 14th. We looked at security certificates and the new bloated Cerber ransomware.

Categories:

Tags:

(Read more…)

The post Week in Security (August 7 – August 13) appeared first on Malwarebytes Labs.

Continue reading Week in Security (August 7 – August 13)

Cerber ransomware delivered in format of a different order of Magnitude

We review a trick that the Magnitude exploit kit uses to bypass security scanners.
Categories:
Exploits
Threat analysis
Tags: binary paddingcerberexploit kitgateMagnigatemagnitude EKransomwareXML

(Read more…)

The post Cerber ransomware delivered… Continue reading Cerber ransomware delivered in format of a different order of Magnitude

Enemy at the gates: Reviewing the Magnitude exploit kit redirection chain

This post shines some light on a ‘gate’ belonging to the geo-targeted Magnitude exploit kit.
Categories:
Cybercrime
Exploits
Tags: cerberEKexploit kitkoreaMagnigateMagnitudemalvertisingransomware

(Read more…)

The post Enemy at the gates: Reviewi… Continue reading Enemy at the gates: Reviewing the Magnitude exploit kit redirection chain

Report: Second quarter dominated by ransomware outbreaks

The second quarter of 2017 left the security world wondering, “What the hell happened?” With leaks of government-created exploits being deployed against users in the wild, a continued sea of ransomware constantly threatening our ability to work online, and the lines between malware and potentially unwanted programs continuing to blur, every new incident was a wakeup call.In this report, we are going to discuss some of the most important trends, tactics, and attacks of Q2 2017, including an update on ransomware, what is going on with all these exploits, and a special look at all the breaches that happened this quarter.

Categories:

Tags:

(Read more…)

The post Report: Second quarter dominated by ransomware outbreaks appeared first on Malwarebytes Labs.

Continue reading Report: Second quarter dominated by ransomware outbreaks

Spoofed Royal mail Your parcel has been shipped today malspam delivers what looks like new Cerber

Continuing with the never ending series of malware downloaders is an email with the subject of Your parcel has been shipped today  pretending to come from Royal Mail with zip attachment in the format recieptTN880209824GB6.zip which matches the normal tracking numbers that Royal Mail do use. This delivers an unknown malware at this time. Continue reading → Continue reading Spoofed Royal mail Your parcel has been shipped today malspam delivers what looks like new Cerber