News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Ukraine War: CommonMagic APT campaign expands
Kaspersky_news

Recent Kaspersky research shows that the threat actor behind the CommonMagic campaign is expanding its malicious activities, both regionally and from a technical perspective. According to them, the newly discovered framework 'CloudWizard' has extended its victimology to organizations in central and western Ukraine; so far, companies in the Russian-Ukrainian war zone have been affected. In addition, Kaspersky experts were able to link the initially unknown actor to previous APT campaigns such as Operation BugDrop and Operation Groundbait (Prikormka). Back in March of this year, Kaspersky reported on a new APT campaign in the Russian-Ukrainian war zone called CommonMagic, which will use PowerMagic and CommonMagic implants...

Read more

Emotet campaign picks up steam again
B2B Cyber ​​Security ShortNews

TA542, a cybercriminal group that distributes Emotet malware, has ended its summer break and is launching more and more new campaigns. However, also with modified Emotet variants. Group TA542 was absent for almost four months and was last seen in action in the summer of July 13, 2022. Since November 2, Proofpoint's security specialists have been monitoring new activities by TA542 - especially in Germany. Key learnings about the Emotet campaigns TA542 uses customized Emotet variants in the new campaigns. The changes (see below) affect the payloads and lures used as well as changes to...

Read more

Germany affected: espionage with stealer agent Tesla
Kaspersky_news

As Kaspersky has noted, there is a recent campaign by cybercriminals using malware stealer Agent Tesla for espionage. The malware is distributed via well-crafted spam emails. Almost 15.000 users in Germany are already affected. Kaspersky experts have discovered a spam email campaign targeting companies worldwide using the notorious stealer Agent Tesla. For the spam campaign, the cyber criminals imitated e-mails from providers or contractors in detail in order to obtain the login data of the organizations concerned - the cyber criminals only revealed the wrong sender address. These credentials are shared on Darkweb forums...

Read more

Chinese disinformation campaign with HaiEnergy

New research from Mandiant reveals a Chinese disinformation campaign. Mandiant has christened this "HaiEnergy". The campaign distributes content on fake news sites. In addition to the websites in North America, Europe, the Middle East and Asia, the campaign also uses many social media that are strategically aligned with the political interests of the People's Republic of China. The HaiEnergy campaign uses 72 websites posing as independent news channels and publishing content in 11 languages. Mandiant analysts believe these websites are linked to Chinese PR firm Shanghai Haixun Technology Co. HaiEnergy:…

Read more

0ktapus phishing campaign: 130 victims like Cloudflare or MailChimp  
0ktapus phishing campaign: 130 victims like Cloudflare or MailChimp

Group-IB has discovered that the recently uncovered 0ktapus phishing campaign targeting Twilio and Cloudflare employees was part of the massive attack chain that resulted in 9.931.000 accounts from over 130 organizations being compromised. The campaign was codenamed 0ktapus by researchers at Group-IB because it posed as a popular identity and access management service. The vast majority of victims are located in the United States, and many of them use Okta's identity and access management services. Group-IB Threat Intelligence teamdiscovered and analyzed the attackers' phishing infrastructure, including phishing domains, the phishing kit, and the...

Read more

Cyber ​​war between Ukraine and Russia

Since mid-February 2022, NETSCOUT has been monitoring the threat landscape in Russia and Ukraine. The analysis revealed that DDoS attacks against Ukraine increased by 2022 percent in February 2021 compared to the same period in 134. On the other hand, since the conflict began, DDoS attacks against Russia have increased by around 236 percent compared to the previous month. While the frequency and volume of DDoS attacks against Russia and Ukraine have increased significantly, attacks against the EMEA region as a whole compared to the same period in 2021 decreased by…

Read more

Malware campaign: Kronos and GootKit
G Data News

Malware campaign: Kronos and GootKit target users from Germany. With "Kronos" and "Gootkit", two well-known malware programs are once again being used. The malware is spread via manipulated search engine results. The current wave started rolling on Thursday. Users from Germany in particular seem to be the focus of the attackers. Numerous compromised websites ensured widespread distribution. It installs one of two malicious programs: either Gootkit or Kronos. Both malicious programs are banking Trojans. "Banking Trojans are anything but yesterday's news," says Tim Berghoff, Security Evangelist at...

Read more