Lazarus impersonated Meta recruiter to breach Spanish aerospace firm

Operators of the North Korea-linked Lazarus APT obtained initial access to the network of an aerospace company in Spain last year after a successful spearphishing campaign, by masquerading as a recruiter for Meta — the company behind Facebook, Instagra… Continue reading Lazarus impersonated Meta recruiter to breach Spanish aerospace firm

Trojanized Signal, Telegram apps found on Google Play, Samsung Galaxy Store

ESET researchers have identified two active campaigns targeting Android users, where the threat actors behind the tools for Telegram and Signal are attributed to the China-aligned APT group GREF. Most likely active since July 2020 and since July 2022, … Continue reading Trojanized Signal, Telegram apps found on Google Play, Samsung Galaxy Store

Zimbra users in Europe, Latin America face phishing threat

ESET researchers have uncovered a mass-spreading phishing campaign aimed at collecting Zimbra account users’ credentials. Zimbra Collaboration is an open-core collaborative software platform, a popular alternative to enterprise email solutions. About t… Continue reading Zimbra users in Europe, Latin America face phishing threat

Hackers with links to Pro-Russian groups compromised foreign embassies in Belarus, researchers say

The work has been carried out by a newly identified group dubbed “MustachedBouncer,” according to researchers with ESET.

The post Hackers with links to Pro-Russian groups compromised foreign embassies in Belarus, researchers say appeared first on CyberScoop.

Continue reading Hackers with links to Pro-Russian groups compromised foreign embassies in Belarus, researchers say

Same code, different ransomware? Leaks kick-start myriad of new variants

Threat landscape trends demonstrate the impressive flexibility of cybercriminals as they continually seek out fresh methods of attack, including exploiting vulnerabilities, gaining unauthorized access, compromising sensitive information, and defrauding… Continue reading Same code, different ransomware? Leaks kick-start myriad of new variants

Infosec products of the month: June 2023

Here’s a look at the most interesting products from the past month, featuring releases from: 1Password, Bitdefender, Cequence Security, ConnectSecure, Cymulate, Cytracom, Datadog, Delinea, Edgescan, Enveedo, ESET, Index Engines, Island, iStorage, Lacew… Continue reading Infosec products of the month: June 2023

Legitimate Android app transforms into data-snooping malware

ESET researchers have discovered a trojanized Android app named iRecorder – Screen Recorder. It was available on Google Play as a legitimate app in September 2021, with malicious functionality most likely added in August 2022. During its existenc… Continue reading Legitimate Android app transforms into data-snooping malware