article thumbnail

Ransomware en masse on the wane: top threats inside web-phishing in H1 2020

Security Affairs

Every third email, meanwhile, contained spyware , which is used by threat actors to steal payment data or other sensitive info to then put it on sale in the darknet or blackmail its owner. Another 17 percent contained downloaders, while backdoors and banking Trojans came third with a 16- and 15-percent shares, respectively. About Group-IB.

Phishing 102
article thumbnail

Evilnum Group targets European and British fintech companies

Security Affairs

A threat actor tracked as Evilnum targeted financial technology companies, mainly the British and European ones, ESET researchers reported. The group aimed at harvesting financial information from financial technology companies, such as trading platforms. Evilnum threat actor was first spotted in 2018 while using the homonym malware.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Amnesty International employee targeted with NSO group surveillance malware

Security Affairs

. “In June 2018, an Amnesty International staff member received a malicious WhatsApp message with Saudi Arabia-related bait content and carrying links Amnesty International believes are used to distribute and deploy sophisticated mobile spyware. com , and ecommerce-ads[.]org.” com , pine-sales[.]com Country Nexus.

article thumbnail

NullMixer: oodles of Trojans in a single dropper

SecureList

NullMixer is a dropper that includes more than just specific malware families; it drops a wide variety of malicious binaries to infect the machine with, such as backdoors, bankers, downloaders, spyware and many others. NullMixer execution chain. The real infection occurs when the user extracts the ‘win-setup-i864.exe’

Malware 114