Bad Actors Sizing Up Systems Via Lightweight Recon Malware

These stealthy downloaders initially infect systems and then only install additional malware on systems of interest. Well-known financial crime gang Cobalt Group and other threat actors have recently shifted tactics to incorporate lightweight modular downloaders that “vet” target machines for Read More …

Russian domestic security service launch new dedicated center to counter cyberattacks

Russia’s Federal Security Service, the FSB, now has a separate coordination center created in order to prevent, detect and counter cyberattacks on critical infrastructure facilities as well as repair damage from such attacks. The new agency is officially titled ‘National Read More …

British Airways breach caused by the same group that hit Ticketmaster

A cyber-criminal operation known as Magecart is believed to have been behind the recent card breach announced last week by British Airways. The operation has been active since 2015 when RisqIQ and ClearSky researchers spotted the malware for the first time. The group’s regular mode Read More …

LuckyMouse uses malicious NDISProxy Windows driver to target gov’t entities

The LuckyMouse advanced persistent threat (APT) is back with a twist in tactics that harnesses LeagSoft certificates to spread Trojans by way of malicious NDISProxy drivers. It was back in June that researchers discovered that LuckyMouse, also known as EmissaryPanda and Read More …

GCHQ intelligence chief threatens ‘brazen’ Russia with UK’s ‘tools’

British spies are ready to counter an “active and real threat” posed by the “brazen Kremlin”, the head of GCHQ has warned. Jeremy Fleming said the government’s cyber intelligence agency could “deploy the full range of tools from across our Read More …

‘Domestic Kitten’ Mobile Spyware Campaign Aims at Iranian Targets

Spreading via fake Android apps, the malware lifts a range of sensitive information from victims’ devices. A mobile spyware campaign against mainly Iranian citizens has been spotted – with evidence that the Iranian government might be involved. The operation is Read More …

U.S. Ties Lazarus to North Korea and Major Hacking Conspiracy

The DoJ said a DPRK spy, Park Jin-hyok, was involved in “a conspiracy to conduct multiple destructive cyberattacks around the world.” The Justice Department has charged a North Korean man in the hacking of Sony Pictures Entertainment (SPE) in 2014 Read More …