New Neutrino Bot comes in a protective loader

We take another look at the Neutrino bot, known for its diverse feature set ranging from snooping on victims to performing DDos attacks. This latest version includes a hardened protective layer aimed at defeating sandboxes and hiding the bot from disc… Continue reading New Neutrino Bot comes in a protective loader

Mac ransomware on piracy sites

February has been a relatively busy month in the world of Mac malware, and now it has gotten busier with the appearance of the second piece of ransomware ever to affect macOS. Categories: Mac
Threat analysisTags: Adobe Premier ProAppleFindzipmacmacOSm… Continue reading Mac ransomware on piracy sites

Rogue Chrome extension pushes tech support scam

Google Chrome may be one of the more secure browsers but an increasing number of malicious extensions are being forced onto users. The one we analyze can hide itself and receive commands from a remote server in order to hijack the browser with incessan… Continue reading Rogue Chrome extension pushes tech support scam

MacDownloader malware targeting defense industry

Researchers Claudio Guarnieri and Collin Anderson recently discovered new Mac malware, which they have dubbed MacDownloader.Categories: Mac
Malware
Threat analysisTags: Adobe Flash PlayerApplemacMacDownloadermacOSmalwarephishingspearphishing(Read mor… Continue reading MacDownloader malware targeting defense industry

A look back at the Zyns iframer campaign

Behind compromised sites or malvertising, you will often find trails that can take you back years and see how infection chains evolved, or didn’t, over time.Categories: Exploits
Threat analysisTags: campaigneitestexploit kitsiframemalvertisingmalwarer… Continue reading A look back at the Zyns iframer campaign

Locky Bart ransomware and backend server analysis

The developers of Locky Bart already had very successful ransomware campaigns running called “Locky” and “Locky v2”. After some users reported being infected with Locky Bart, we investigated it to find the differences as to gain greater knowledge and understanding of this new version.

Categories:

Tags:

(Read more…)

Continue reading Locky Bart ransomware and backend server analysis

Zbot with legitimate applications on board

Recently, among the payloads delivered by exploit kits, we often find Terdot.A/Zloader – a downloader installing on the victim machine a ZeuS-based malware.Categories: Cybercrime
Malware
Malware
Threat analysisTags: bankerbanking malwaremalwareterdo… Continue reading Zbot with legitimate applications on board

VirLocker’s comeback; including recovery instructions

Virlocker is back, the nightmare is still real. But we have found a way to at least recover your important files even if the affected machine can be considered a loss.Categories: Malware
Threat analysisTags: file infectingfile recoverymalwarepolymorph… Continue reading VirLocker’s comeback; including recovery instructions

VirLocker’s comeback; including recovery instructions

Virlocker is back, the nightmare is still real. But we have found a way to at least recover your important files even if the affected machine can be considered a loss.Categories: Malware
Threat analysisTags: file infectingfile recoverymalwarepolymorph… Continue reading VirLocker’s comeback; including recovery instructions

Tech support scams, stolen data, and botnets

We’ve found a scam in a box company that also offers intelligence leads. That is, they’ll sell you the scam and point you at the most vulnerable targets first.

Categories:

Tags:

(Read more…)

Continue reading Tech support scams, stolen data, and botnets