Remove malicious-vpn-installers-used-to-infect-devices-with-spyware
article thumbnail

Malicious VPN Installers Used to Infect Devices with Spyware

Heimadal Security

The VPN market has grown considerably in the last few years due to the increasing popularity of VPN technologies. However, corrupted VPN installers have been used by threat actors to deliver a piece of spyware called EyeSpy, as part of a malware campaign that started in May 2022.

Spyware 80
article thumbnail

APT trends report Q3 2022

SecureList

This is our latest installment, focusing on activities that we observed during Q3 2022. On July 7, CISA issued an alert, “ North Korean State-Sponsored Cyber Actors Use Maui Ransomware To Target the Healthcare and Public Health Sector “, based on a Stairwell report about Maui ransomware.

Malware 142
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

APT trends report Q1 2021

SecureList

This is our latest installment, focusing on activities that we observed during Q1 2021. In our initial report on Sunburst , we examined the method used by the malware to communicate with its C2 (command-and-control) server and the protocol used to upgrade victims for further exploitation. The most remarkable findings.

Malware 142
article thumbnail

APT trends report Q3 2021

SecureList

This is our latest installment, focusing on activities that we observed during Q3 2021. The backdoor, dubbed Tomiris, bears a number of similarities to the second-stage malware, Sunshuttle (aka GoldMax), used by DarkHalo last year. Following this, they were tricked into downloading previously unknown malware. Russian-speaking activity.

Malware 143