Stone Wolf employs Meduza Stealer to hack Russian companies


BI.ZONE Threat Intelligence reports an increase in criminal activity employing commercial malware available on underground resources. Recently, the researchers identified a malicious campaign by a cluster later dubbed Stone Wolf.

The adversaries send out phishing emails on behalf of a legitimate provider of industrial automation solutions. The goal of the attackers is to deliver Meduza Stealer to the infrastructures of their interest. Cybercriminals often disseminate phishing emails on behalf of large well‑known organizations. Recognizable logos and other elements of the brands’ visual identity help adversaries gain user trust and boost the chances for their malicious messages to be opened.

Read more…
Source: BI.ZONE Threat Intelligence 


Sign up for our Newsletter


Related:

  • Unmasking Tycoon 2FA: A Stealthy Phishing Kit Used to Bypass Microsoft 365 and Google MFA

    May 9, 2024

    Tycoon 2FA is a phishing-as-a-service (PhaaS) platform that was first seen in August 2023. Like many phish kits, it bypasses multifactor authentication (MFA) protections and poses a significant threat to users. Lately, Tycoon 2FA has been grabbing headlines because of its role in ongoing campaigns designed to target Microsoft 365 and Gmail accounts. Read more… Source: Proofpoint Sign up ...

  • U.S. Patent Office data leak exposes private addresses

    May 9, 2024

    USPTO has acknowledged yet another incident in which the filers’ address data was leaked. Following a second data breach within two years, the federal agency responsible for patent and trademark grants notified thousands of filers whose private addresses were exposed. As a result, the USPTO is now reaching out to thousands of affected filers to inform ...

  • European Parliament election prep unearthed data breach

    May 8, 2024

    The breach, dating back to early 2024, was uncovered two weeks ago as the European Parliament intensified efforts to reinforce its cybersecurity in preparation for the upcoming European elections in June, a press officer from the European Parliament told Euronews. The compromised application which has now been taken offline is called ‘PEOPLE’, and collated sensitive information ...

  • Kansas: First responders impacted by City of Wichita cyber attack

    May 8, 2024

    The City of Wichita is staying tight-lipped on details about a cyber attack that led to the shutdown of some of its online systems. Getting details on the cybersecurity attack, how it happened and what information could be at risk has been a challenge. The City has not had answers to many of KSN’s questions. What ...

  • Dmitry Khoroshev named as alleged leader of ransomware gang LockBit

    May 7, 2024

    The alleged leader of what was once the world’s largest ransomware outfit, LockBit, has been named as Russian national Dmitry Khoroshev by the UK’s National Crime Agency (NCA), after the seizure of the criminal gang’s infrastructure. Khoroshev, who lived his online life under the name LockBitSupp, has been sanctioned by the UK, US and Australia as ...

  • China suspected of hacking UK armed forces payroll

    May 7, 2024

    The government suspects China was behind the hack of an armed forces payroll system, the BBC understands. Defence Secretary Grant Shapps will not identify a specific culprit when he addresses MPs today, but is expected to warn of the dangers posed by cyber espionage from hostile states. The system used by the Ministry of Defence (MoD) ...