Skip to content

English

Russia-linked Sandworm APT group is behind SwiftSlicer wiper, that hit Ukraine

Russia-linked Sandworm APT group is behind SwiftSlicer wiper, that hit Ukraine

Researchers from ESET discovered a new Golang-based wiper, dubbed SwiftSlicer, that was used in attacks aimed at Ukraine. The experts believe that the Russia-linked APT group Sandwork (aka BlackEnergy and TeleBots) is behind the wiper attacks. #BREAKING On January 25th #ESETResearch discovered a new cyberattack in 🇺🇦 Ukraine. Attackers deployed a

Members Public
CyberAttack Techniques of MacOS Ransomware

CyberAttack Techniques of MacOS Ransomware

Microsoft has shed light on four different ransomware families – KeRanger, FileCoder, MacRansom, and EvilQuest – that are known to impact Apple macOS systems. "While these malware families are old, they exemplify the range of capabilities and malicious behavior possible on the platform," the Microsoft's Security Threat Intelligence

Members Public
Russian hackers targeted U.S. nuclear scientists

Russian hackers targeted U.S. nuclear scientists

A Russian hacking team known as Cold River targeted three nuclear research laboratories in the United States this past summer, according to internet records reviewed by Reuters and five cyber security experts. Between August and September, as President Vladimir Putin indicated Russia would be willing to use nuclear weapons to

Members Public
Russian Turla Cyberspies Leveraged Other Hackers' USB-Delivered Malware

Russian Turla Cyberspies Leveraged Other Hackers' USB-Delivered Malware

In September 2022, Mandiant discovered a suspected Turla Team operation distributing the Kopiluwak reconnaissance utility and Quietcanary backdoor to Andromeda malware victims in Ukraine. Active since at least 2006 and linked to the Russian government, the cyberespionage group is also tracked as Snake, Venomous Bear, Krypton, and Waterbug, and has

Members Public
Raspberry Robin Detected ITW Targeting Insurance & Financial Institutes In Europe

Raspberry Robin Detected ITW Targeting Insurance & Financial Institutes In Europe

Recent attacks documented in previous months seem to be orchestrated by hacking groups using a framework called Raspberry Robin. This well-designed automated framework allows attackers post-infection capabilities to evade detection, move laterally and leverage trusted cloud infrastructures of known data hosting providers such as Discord, Azure & Github, among rest.

Members Public
North Korean Hackers Created 70 Fake Bank, Venture Capital Firm Domains

North Korean Hackers Created 70 Fake Bank, Venture Capital Firm Domains

North Korea’s BlueNoroff hackers have updated their arsenal and delivery techniques in a new wave of attacks targeting banks and venture capital firms, cybersecurity firm Kaspersky reports. Part of Lazarus, a hacking group linked to the North Korean government, BlueNoroff is financially motivated and has been blamed for numerous

Members Public
Russian Hackers Targeted Petroleum Refinery in NATO Country During Ukraine War

Russian Hackers Targeted Petroleum Refinery in NATO Country During Ukraine War

The Russia-linked Gamaredon group attempted to unsuccessfully break into a large petroleum refining company within a NATO member state earlier this year amid the ongoing Russo-Ukrainian war. The attack, which took place on August 30, 2022, is just one of multiple attacks orchestrated by the advanced persistent threat (APT) that&

Members Public
Ukraine's DELTA military system users targeted by info-stealing malware

Ukraine's DELTA military system users targeted by info-stealing malware

A compromised Ukrainian Ministry of Defense email account was found sending phishing emails and instant messages to users of the 'DELTA' situational awareness program to infect systems with information-stealing malware. The campaign was highlighted in a report today by CERT-UA (Computer Emergency Response Team of Ukraine), which warned

Members Public
New Agenda Ransomware Variant Targets Critical Sectors

New Agenda Ransomware Variant Targets Critical Sectors

This year, various ransomware-as-a-service groups have developed versions of their ransomware in Rust, including Agenda. Agenda's Rust variant has targeted vital industries like its Go counterpart. In this blog, we will discuss how the Rust variant works. This year, ransomware-as-a-service (RaaS) groups like BlackCat, Hive, and RansomExx have

Members Public
Ukrainian govt networks breached via trojanized Windows 10 installers

Ukrainian govt networks breached via trojanized Windows 10 installers

Ukrainian government entities were hacked in targeted attacks after their networks were first compromised via trojanized ISO files posing as legitimate Windows 10 installers. These malicious installers delivered malware capable of collecting data from compromised computers, deploying additional malicious tools, and exfiltrating stolen data to attacker-controlled servers. One of the

Members Public