Threat actors use MS Teams vishing technique to deploy DarkGate malware
The attacker impersonated an employee of a known client during a Microsoft Teams call and convinced the victim to download the remote desktop app AnyDesk.
The attacker impersonated an employee of a known client during a Microsoft Teams call and convinced the victim to download the remote desktop app AnyDesk.
The EU sanctioned GRU Unit 29155 known for assassinations, bombings, and cyberattacks across Europe.
The threat actor registered more than 200 domain names to support the campaign.
If successfully exploited, the flaw could be used to execute malicious commands.
The campaign is believed to be a more sophisticated iteration of earlier “ClickFix” attacks.
Currently, its unclear, how the both flaws are being exploited.
The attacks mainly focus on Chinese-branded devices that are either awaiting critical security patches or have reached EoL status.
The threat actors employed phishing emails exploiting a known WinRAR flaw to deliver malware.
Glutton has some issues in its stealth and encryption mechanisms, which may indicate that it is still under development.
The attacks reportedly began in November and have increased through December.
Showing elements 1081 - 1090