PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

This New Fileless Malware Hides Shellcode in Windows Event Logs

samedi 7 mai 2022 à 06:03
A new malicious campaign has been spotted taking advantage of Windows event logs to stash chunks of shellcode for the first time in the wild. "It allows the 'fileless' last stage trojan to be hidden from plain sight in the file system," Kaspersky researcher Denis Legezo said in a technical write-up published this week. The stealthy infection process, not attributed to a known actor, is believed

QNAP Releases Firmware Patches for 9 New Flaws Affecting NAS Devices

samedi 7 mai 2022 à 05:20
QNAP, Taiwanese maker of network-attached storage (NAS) devices, on Friday released security updates to patch nine security weaknesses, including a critical issue that could be exploited to take over an affected system. "A vulnerability has been reported to affect QNAP VS Series NVR running QVR," QNAP said in an advisory. "If exploited, this vulnerability allows remote attackers to run arbitrary

Researchers Warn of 'Raspberry Robin' Malware Spreading via External Drives

vendredi 6 mai 2022 à 13:07
Cybersecurity researchers have discovered a new Windows malware with worm-like capabilities and is propagated by means of removable USB devices. Attributing the malware to a cluster named "Raspberry Robin," Red Canary researchers noted that the worm "leverages Windows Installer to reach out to QNAP-associated domains and download a malicious DLL." The earliest signs of the activity are said to

Hackers Using PrivateLoader PPI Service to Distribute New NetDooka Malware

vendredi 6 mai 2022 à 11:24
A pay-per-install (PPI) malware service known as PrivateLoader has been spotted distributing a "fairly sophisticated" framework called NetDooka, granting attackers complete control over the infected devices. "The framework is distributed via a pay-per-install (PPI) service and contains multiple parts, including a loader, a dropper, a protection driver, and a full-featured remote access trojan (

Experts Uncover New Espionage Attacks by Chinese 'Mustang Panda' Hackers

vendredi 6 mai 2022 à 09:17
The China-based threat actor known as Mustang Panda has been observed refining and retooling its tactics and malware to strike entities located in Asia, the European Union, Russia, and the U.S. "Mustang Panda is a highly motivated APT group relying primarily on the use of topical lures and social engineering to trick victims into infecting themselves," Cisco Talos said in a new report detailing