The Cyber Express

Researchers Study Evolution of Ransomware Gang UNC4393’s Campaigns After Qakbot Takedown

Initially relying on Qakbot botnet infections, UNC4393 now uses custom malware and diverse access techniques after the crackdown on Qakbot. They have quick reconnaissance and encryption objectives, with a median time of 42 hours to ransomware.

New Malware Campaign Exploiting RDPWrapper and Tailscale Targets Cryptocurrency Users

By configuring multiple RDP sessions with RDPWrapper and using Tailscale for secure network connections, attackers can maintain access and exfiltrate sensitive data discreetly.

Malvertising Campaign Lures Mac Users with Fake Microsoft Teams Ad

The malicious ad campaign employed advanced filtering techniques to evade detection and appeared as a top search result for Microsoft Teams. It redirected users through deceptive links despite displaying microsoft.com as its URL.

ViperSoftX Info-Stealing Malware Being Distributed Through Fake Ebooks

Originally detected in 2020, the ViperSoftX malware now incorporates more sophisticated evasion tactics by using the Common Language Runtime (CLR) to run PowerShell commands within AutoIt scripts distributed through pirated eBook copies.

Splunk Addresses Critical Vulnerabilities in Enterprise and Cloud Platforms

Splunk has released a set of security updates to address 16 vulnerabilities in Splunk Enterprise and Cloud Platform, including high-severity issues. CVE-2024-36985 allows remote code execution via External Lookup in Splunk Enterprise.

Indian Government Issues Serious Warning on Phishing Scams Alleging Sexual Offenses

The emails falsely accuse recipients of sexual offences, using names and seals of authorities to appear authentic. Citizens are advised not to respond to such emails and report them to authorities.

Pro-Bangladeshi Hacktivists Enter Global Stage with Matryoshka 424 Alliance

Team ARXU gained recognition earlier this year for targeting Romania over its support for Israel. The hacker group has a history of cyberattacks against Israel and its allies.

RCE, DoS Exploits Found in Rockwell PanelView Plus: Patch Now

Microsoft has exposed two significant vulnerabilities in Rockwell Automation's PanelView Plus devices that could be exploited by attackers to execute remote code and launch denial-of-service attacks.

Understanding the FakeBat Loader: Distribution Tactics and Cybercriminal Infrastructure

In the early part of 2024, the FakeBat loader, also known as EugenLoader or PaykLoader, emerged as a significant threat utilizing the drive-by download technique to spread malware.

National Australia Bank Raises Alarm About Cyber Threats to Major Banks

Australia's four major banks, including ANZ Bank, Commonwealth Bank, National Australia Bank (NAB), and Westpac, are constantly under attack from threat actors seeking to steal sensitive information and money from unsuspecting customers.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags