article thumbnail

A new Stantinko Bot masqueraded as httpd targeting Linux servers

Security Affairs

Researchers spotted a new variant of an adware and coin-miner botnet operated by Stantinko threat actors that now targets Linux servers. Researchers from Intezer have spotted a new variant of an adware and coin-miner botnet that is operated by Stantinko threat actors since 2012. SecurityAffairs – hacking, malware).

Adware 137
article thumbnail

China-based Fangxiao group behind a long-running phishing campaign

Security Affairs

Researchers from Cyjax reported that a China-based financially motivated group, dubbed Fangxiao, orchestrated a large-scale phishing campaign since 2017. “The Fangxiao campaigns are effective lead generation methods which have been redirected to various domains, from malware, to referral links, to ads and adware.”

Phishing 108
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Breach Exposes Users of Microleaves Proxy Service

Krebs on Security

” Microleaves has long been classified by antivirus companies as adware or as a “potentially unwanted program” (PUP), the euphemism that antivirus companies use to describe executable files that get installed with ambiguous consent at best, and are often part of a bundle of software tied to some “free” download.

article thumbnail

IT threat evolution Q1 2021. Non-mobile statistics

SecureList

The most common vulnerability in the suite remains CVE-2017-11882 , a stack buffer overflow that occurs when processing objects in the Equation Editor component. Updated adware for the new Macs also immediately appeared, in particular the Pirrit family (whose members placed high in our Top 20 threats for macOS). into the system.

Mobile 96
article thumbnail

Experts spotted a new strain of Shlayer macOS Malware

Security Affairs

. “After the second stage payload is downloaded and executed, it attempts to escalate privileges with sudo using a technique invoking / usr / libexec /security_authtrampoline as discussed in Patrick Wardle’s DEFCON 2017 talk “ Death by 1000 Installers ”.” SecurityAffairs – Shlayer , hacking). Pierluigi Paganini.

Malware 81
article thumbnail

Data Leak Strategy Fueling the Ransomware Economy

SecureWorld News

Back in 2017, these folks compromised Netflix and spilled 10 unreleased episodes of "Orange Is the New Black" TV series via a shady online marketplace after the production company refused to pay the ransom. For the record, this phenomenon isn't exactly new. Remember the news-making story of a hacker group calling themselves The Dark Overlord?

article thumbnail

IT threat evolution in Q2 2021. PC statistics

SecureList

Also seen in Q2 was the similar vulnerability CVE-2017-11882 , which causes a buffer overflow on the stack in the same component. Lastly, we spotted an attempt to exploit the CVE-2017-8570 vulnerability, which, like other bugs in Microsoft Office, permits the execution of arbitrary code in vulnerable versions of the software. .

Adware 102