Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Monday, 1 June 2020

GitHub’s warning to Java Developers.




GitHub warns Java developers of the new malware in NetBeans projects.
A malware, named Octopus Scanner, was found in Apache NetBeans projects. The final goal of the malware is to install a remote access trojan (RAT) to give hackers access to the sensitive projects.
GitHub found 26 repos with Octopus Scanner uploaded on the site. They said that the oldest sample of this malware has been uploaded in August 2018. GitHub didn’t publish the list of all infected projects but provided details about a malware’s infection process so Java developers can be aware.


New TrickBot update makes it harder to detect a malware.




Well known banking Trojan, TrickBot, got a new update which makes it harder to detect.
From 2016 this banking Trojan is continuously evolving.
It is commonly used to steal banking information and provide a backdoor access to the infected machine.
Also, it can operate as a botnet, sending the phishing emails with malicious attachments to help spread itself to additional machines and after that move around the network exploiting the EternalBlue vulnerability.
Recently researchers at Palo Alto Networks provided details regarding the latest Trickbot update which makes a detection harder.
New module, Nworm, was replacing Mworm, which makes sure that after infecting a machine no artifacts are left on it. In addition, Nworm is encrypted at transport. These features make malware detection harder.
Researchers said that to protect themselves users need to have an updated version of Microsoft Windows.


Wednesday, 27 May 2020

Silent Night: Zeus Banking Trojan.




According to researches Zeus, a famous banking Trojan, has been recently sold in the underground markets. As was published by Malwarebytes and HYAS, the Trojan, dubbed Silent Night, was distributed via COVID-19 spam campaigns and RIG exploit kit.
According to Malwarebytes, Silent Night is compatible with all operating system and known by collecting information from online forms. It also performs web injections in different web browsers (Chrome, Firefox, IE), takes screenshots, steals cookies, passwords from Chrome, banking credentials.
In 2011 Zeus’s source code was leaked. Since then, different Zeus’ “versions” were developed and released. Recently banks observed an attack from one of this developed Trojans, Zeus Sphinx.


Thursday, 14 May 2020

Microsoft warns about new phishing campaign.



Microsoft has found a new COVID-19 phishing campaign targeting businesses using the LokiBot information-stealing Trojan.
Microsoft Security Intelligence twitted today details of detected campaign.
LokiBot steals login credentials from different browsers, mail, FTPs, save them and then send to the attackers’ server. Microsoft was able to detect this attack using Microsoft Threat Protection’s machine learning algorithms.
According to Microsoft, new phishing campaign used COVID-19 lures to trick victims to open malicious attachment.
The first email pretends to be from the Centers for Disease Control (CDC) with COVID-19 update and “Business continuity plan announcement starting May 2020”.

The second email pretends to be from a vendor and asking to update banking information.

Both emails contain malicious ARJ (archive skipped by anti-malware scanners) attachment. When victims open attachment, they get infected by LokiBot Trojan.

Tuesday, 5 May 2020

Microsoft warns users about malicious disk image files in spam emails.



Microsoft was able to detect multiple malicious spam due to advance machine learning thereat detection model. Attackers are using COVID-19 email subject line to trick users.  In multiple tweets Microsoft Security Intelligence mentioned that ISO or IMG from these emails are infected by Remcos remote access trojan (RAT) which allows hackers to get a full control.
One of the campaigns targeted small businesses that are looking for disaster loan with a fake “application form”, another one is targeting manufacturing companies in South Korea with malicious ISO attachment, third was focused on US accountants with an “update” for American Institute of CPAs.

Sunday, 3 May 2020


Recently IBM X-Force discovered a TrickBot trojan attacks which abused people’s interest in the Department of Labor’s Family and Medical Leave Act (FMLA). Using fake messages that claim to be from the department attackers “inform” families about changes in family-leave benefits related to COVID-19. Emails contain a weaponized attachment that acts as a dropper for the malware.
TrickBot is a well-known banking trojan developed in 2016. Originally created to attack big corporations it seems it changed a target audience at this time.
TrickBot trojan allows to takeover bank accounts and to conduct high-value wire fraud.
IBM X-Force says: “In the spam samples we looked at, the eventual TrickBot payload started out in a DocuSign-type attachment titled Family and Medical Leave of Act 22.04.doc. Once opened, the document asks the recipient to enable macros (ThisDocument.cls), from which, upon closing the file, malicious scripts will be launched to fetch the malware from the attacker’s designated domain.”
This campaign shows that cybercriminals continue to take advantage of the current COVID-19 pandemic state.

Friday, 1 May 2020


Cybereason security researchers are warning of a new mobile banking trojan. It has ability to steal financial apps data, read user’s SMS and hijack two-factor authentication codes.
EventBot(malware name given by Cybereason) the malware is capable of targeting 200+ different financial apps, including banking, money transfer services, and crypto-currency wallets such as Paypal Business, Revolut, Barclays, CapitalOne, HSBC, Santander, TransferWise, and Coinbase.
Cybereason’s researchers warn that EventBot “has real potential to become the next big mobile malware.”
So, if you are Android user, keep your device updated with the latest official security patches, use official sources to download apps and be careful with every permission request.