Neverquest Gang Takes Leave — Is It the End of the Quest?

IBM X-Force researchers recently observed a massive drop in Neverquest malware campaigns. Is it the end of an era for this Trojan?

The post Neverquest Gang Takes Leave — Is It the End of the Quest? appeared first on Security Intelligence.

Continue reading Neverquest Gang Takes Leave — Is It the End of the Quest?

fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

Continuing with the regular series of Japanese language malspam emails is today’s overnight onslaught with the subject of Express Mail Service (EMS) pretending to come from japanexpress@post.japanpost.jp. I am also getting a lot of emails with a malformed subject line ?iso-2022-jp?B?RU1TGyRCR1tDIz51NjckTjNORycbKEIgLSAbJEJNOUpYNkkbKEIgLSAbJEJGfEtcTTlALxsoQg==?=   or  ?iso-2022-jp?B?GyRCTT05cEw1JDckTk8iTW1AaEpROTkkZCUiJUklbCU5SlE5ORsoQiA=?=  which I assume is an encoding error and it is … Continue reading → Continue reading fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

Continuing with the regular series of Japanese language malspam emails is today’s overnight onslaught with the subject of Express Mail Service (EMS) pretending to come from japanexpress@post.japanpost.jp. I am also getting a lot of emails with a malformed subject line ?iso-2022-jp?B?RU1TGyRCR1tDIz51NjckTjNORycbKEIgLSAbJEJNOUpYNkkbKEIgLSAbJEJGfEtcTTlALxsoQg==?=   or  ?iso-2022-jp?B?GyRCTT05cEw1JDckTk8iTW1AaEpROTkkZCUiJUklbCU5SlE5ORsoQiA=?=  which I assume is an encoding error and it is … Continue reading → Continue reading fake Japan Post Express Mail Service (EMS) malspam delivers Ursnif /Gozi /Papras banking trojan

Anatomy of an hVNC Attack

Cybercriminals who rely on remote control tactics to commit financial fraud may use hidden virtual network computing (hVNC) modules to cover their tracks.

The post Anatomy of an hVNC Attack appeared first on Security Intelligence.

Continue reading Anatomy of an hVNC Attack

GozNym’s Euro Trip: Launching Redirection Attacks in Germany

GozNym continued its trip around Europe by launching redirection attacks against 13 German banks. The volume of these attacks has spiked in recent months.

The post GozNym’s Euro Trip: Launching Redirection Attacks in Germany appeared first on Security Intelligence.

Continue reading GozNym’s Euro Trip: Launching Redirection Attacks in Germany

Two Heads Are Better Than One: Going Under the Hood to Analyze GozNym

IBM X-Force researchers recognized that the GozNym banking malware leverages features from two types of malware to make it double the threat.

The post Two Heads Are Better Than One: Going Under the Hood to Analyze GozNym appeared first on Security Intelligence.

Continue reading Two Heads Are Better Than One: Going Under the Hood to Analyze GozNym