Remove categories threat-research
article thumbnail

Black Basta ransomware now supports encrypting VMware ESXi servers

Security Affairs

Researchers from Uptycs first reported the discovery of the new Black Basta ransomware variant that supports encryption of VMWare ESXi servers. Researchers from NCC Group recently spotted a new partnership in the threat landscape between the Black Basta ransomware group and the QBot malware operation. Pierluigi Paganini.

article thumbnail

Experts believe that Russian Gamaredon APT could fuel a new round of DDoS attacks

Security Affairs

Researchers at 360 Qihoo observed a wave of DDoS attacks launched by Russia-linked APT-C-53 (aka Gamaredon) and reported that the threat actors also released as open-source the code of a DDoS Trojan called LOIC. ” concludes the researchers that also shared Indicators of compromise for the attacks. Pierluigi Paganini.

DDOS 142
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

New DFSCoerce NTLM relay attack allows taking control over Windows domains

Security Affairs

Researchers warn of a new Windows NTLM relay attack dubbed DFSCoerce that can be exploited by threat actors to take control over a Windows domain. The security researcher Filip Dragovic published a proof-of-concept script for the new NTLM relay attack. Yep, this works. Just like the attack chain starting with PetitPotam works.

article thumbnail

Clipminer Botnet already allowed operators to make at least $1.7 Million

Security Affairs

million, according to a report published by security researchers at Symantec. Researchers at Symantec’s Threat Hunter Team uncovered a cryptomining operation that has potentially made the actors behind it at least $1.7 Please vote for Security Affairs and Pierluigi Paganini in every category that includes them (e.g.

article thumbnail

Symbiote, a nearly-impossible-to-detect Linux malware?

Security Affairs

Researchers uncovered a high stealth Linux malware, dubbed Symbiote, that could be used to backdoor infected systems. Joint research conducted by security firms Intezer and BlackBerry uncovered a new Linux threat dubbed Symbiote. For this reason, security researchers defined this threat as nearly impossible to detect.

Malware 145
article thumbnail

Black Basta ransomware operators leverage QBot for lateral movements

Security Affairs

Researchers from NCC Group spotted a new partnership in the threat landscape between the Black Basta ransomware group and the QBot malware operation. Experts reported that the threat actor used two main techniques to evade anti-virus detection by disabling Windows Defender. exe: regsvr32.exe

article thumbnail

Android pre-installed apps are affected by high-severity vulnerabilities

Security Affairs

The Microsoft 365 Defender Research Team discovered four vulnerabilities ( CVE-2021-42598 , CVE-2021-42599 , CVE-2021-42600 , and CVE-2021-42601 ) in a mobile framework, owned by mce Systems , that is used by several mobile carriers in pre-installed Android System apps. BROWSABLE Activity with the “mcedigital://” scheme (source Microsoft).

Mobile 145