Malware - Tagged - Security Boulevard The Home of the Security Bloggers Network Thu, 20 Jul 2023 14:37:38 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Malware - Tagged - Security Boulevard 32 32 133346385 The Rise of QR Codes Spurs Rise in ‘Fresh Phish’ https://securityboulevard.com/2023/07/the-rise-of-qr-codes-spurs-rise-in-fresh-phish/ Fri, 21 Jul 2023 12:00:11 +0000 https://securityboulevard.com/?p=1981769 QR codes ransomware, attacks, RaaS, SlashNext ransomware phishing attack

Miscreants have ramped up their use of QR codes to phish for credentials, according to INKY threat researchers.

The post The Rise of QR Codes Spurs Rise in ‘Fresh Phish’ appeared first on Security Boulevard.

]]>
1981769
FIN8 Group Using Modified Sardonic Malware for Deployment of BlackCat Ransomware https://securityboulevard.com/2023/07/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware/ https://securityboulevard.com/2023/07/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware/#respond Thu, 20 Jul 2023 14:37:38 +0000 https://blog.eclecticiq.com/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware tap 13 - 2023

FIN8 Group Using Modified Sardonic Malware for Deployment of BlackCat Ransomware     

According to the Symantec Threat Hunter Team, the financially motivated threat actor known as FIN8 has been observed using an updated version of a malware called Sardonic to deliver the BlackCat ransomware. The update on the Sardonic malware is an attempt on the part of the e-crime group to diversify its focus and maximize profits from infected entities. [1

The C++ based Sardonic backdoor has the ability to harvest system information and execute commands, and has a plugin system designed to load and execute additional malware payloads delivered as DLLs. Unlike the previous variant of Sardonic, which was designed in C++, the latest iteration packs in significant alterations, with most of the source code rewritten in C and modified so as to deliberately avoid similarities. 

In the latest incident analyzed by Symantec, Sardonic malware is embedded into a PowerShell script that was deployed into the targeted system after obtaining initial access. The script is designed to launch a .NET loader, which then decrypts and executes an injector module to ultimately run the implant. Successful infection leads to the deployment of BlackCat ransomware.    

The post FIN8 Group Using Modified Sardonic Malware for Deployment of BlackCat Ransomware appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/fin8-group-using-modified-sardonic-malware-for-deployment-of-blackcat-ransomware/feed/ 0 1982184
ChatGPT Provides Limited Help Identifying Malware https://securityboulevard.com/2023/07/chatgpt-provides-limited-help-identifying-malware/ Wed, 19 Jul 2023 13:00:39 +0000 https://securityboulevard.com/?p=1981977 ChatGPT Spyderbat Lacework Zerologon Malware Complacency

Current LLM-based tech like ChatGPT can accurately classify malware risk in only 5% of cases—and they may never be able to recognize novel approaches used to create malware.

The post ChatGPT Provides Limited Help Identifying Malware appeared first on Security Boulevard.

]]>
1981977
A Look at the Email Threat Landscape in Q1 2023 https://securityboulevard.com/2023/07/a-look-at-the-email-threat-landscape-in-q1-2023/ Tue, 18 Jul 2023 14:00:42 +0000 https://securityboulevard.com/?p=1981690 email cyber, resilience, Dell Lacework Adds Time Series Modeling to Cybersecurity Platform

VIPRE's Email Threat Trends Report for Q1 2023 analyzed 1.8 billion emails to provide a comprehensive understanding of contemporary email threats.

The post A Look at the Email Threat Landscape in Q1 2023 appeared first on Security Boulevard.

]]>
1981690
Protect Your Systems from Malicious Packages: What You Need to Know https://securityboulevard.com/2023/07/protect-your-systems-from-malicious-packages-what-you-need-to-know/ https://securityboulevard.com/2023/07/protect-your-systems-from-malicious-packages-what-you-need-to-know/#respond Tue, 18 Jul 2023 10:39:13 +0000 https://wesecureapp.com/?p=34657 Malicious packages are a growing threat to businesses and organizations of all sizes. These packages are often disguised as legitimate software, but they can contain harmful code that can steal data, install malware, or disrupt operations. In 2022, there was […]

The post Protect Your Systems from Malicious Packages: What You Need to Know appeared first on WeSecureApp :: Simplifying Enterprise Security.

The post Protect Your Systems from Malicious Packages: What You Need to Know appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/protect-your-systems-from-malicious-packages-what-you-need-to-know/feed/ 0 1981826
APT Group Red Menshen is Rapidly Evolving its BPFDoor Malware https://securityboulevard.com/2023/07/apt-group-red-menshen-is-rapidly-evolving-its-bpfdoor-malware/ Mon, 17 Jul 2023 17:12:16 +0000 https://securityboulevard.com/?p=1981703 Red Menshen budgets semiconductor data, secure, conflict, oil security tools budget dark, web, threat

Red Menshen is an APT group that is rapidly evolving its BPFDoor backdoor malware that targets systems running Linux or Solaris.

The post APT Group Red Menshen is Rapidly Evolving its BPFDoor Malware appeared first on Security Boulevard.

]]>
1981703
Addressing the Mobile Malware Threat With Zero-Trust https://securityboulevard.com/2023/07/addressing-the-mobile-malware-threat-with-zero-trust/ Mon, 17 Jul 2023 13:00:46 +0000 https://securityboulevard.com/?p=1981512 mobile geofence 911 firmware

AI-enabled zero-trust solutions can help address the rising threat of mobile malware.

The post Addressing the Mobile Malware Threat With Zero-Trust appeared first on Security Boulevard.

]]>
1981512
SlashNext Report Shows How Cybercriminals Use Generative AI https://securityboulevard.com/2023/07/slashnext-report-shows-how-cybercriminals-use-generative-ai/ Fri, 14 Jul 2023 12:10:35 +0000 https://securityboulevard.com/?p=1981522 SlashNext BEC phishing

A SlashNext report detailed how cybercriminals use generative AI capabilities to launch phishing and BEC attacks in greater volume.

The post SlashNext Report Shows How Cybercriminals Use Generative AI appeared first on Security Boulevard.

]]>
1981522
Concerns About Infostealer Malware on the Rise https://securityboulevard.com/2023/07/concerns-about-infostealer-malware-on-the-rise/ Wed, 12 Jul 2023 12:23:32 +0000 https://securityboulevard.com/?p=1981156 SpyCloud MFA Systems Vulnerable Authentication Bypass

A SpyCloud report found more than half of respondents are extremely concerned about their ability to thwart attacks that exfiltrate authentication data.

The post Concerns About Infostealer Malware on the Rise appeared first on Security Boulevard.

]]>
1981156
Today’s cybersecurity health checks must identify AI based threats. Does yours? https://securityboulevard.com/2023/06/todays-cybersecurity-health-checks-must-identify-ai-based-threats-does-yours/ https://securityboulevard.com/2023/06/todays-cybersecurity-health-checks-must-identify-ai-based-threats-does-yours/#respond Mon, 26 Jun 2023 22:27:20 +0000 https://slashnext.com/?p=53808 Your organization will most likely face AI based threats in cybersecurity at some point this year. And as such, you can’t rely on outdated risk assessment methodologies that struggle to keep pace with the new highly sophisticated AI phishing techniques used for Business Email Compromise (BEC), smishing, link and file-based attacks. Threat actors now use […]

The post Today’s cybersecurity health checks must identify AI based threats. Does yours? first appeared on SlashNext.

The post Today’s cybersecurity health checks must identify AI based threats. Does yours? appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/06/todays-cybersecurity-health-checks-must-identify-ai-based-threats-does-yours/feed/ 0 1980086