Russia-linked UAC-0184 targeting Ukraine with XWorm RAT
The infection process involves DLL sideloading and the use of the Shadowloader tool.
The infection process involves DLL sideloading and the use of the Shadowloader tool.
Together with GRU Stigal orchestrated a destructive WhisperGate campaign targeting Ukrainian government systems ahead of Russia’s invasion in 2022.
Any.Run said that no data or system integrity was impacted during the attack.
The researchers have observed botnet operators exploiting multiple flaws to target various devices.
Users are recommended to upgrade to the latest fixed MOVEit Transfer version.
The Polyfill.io domain and service, which was purchased by a Chinese company, has reportedly been modified to introduce malicious code.
GrimResource allows attackers to execute arbitrary code in MMC with minimal security warnings.
These attacks come just weeks after three high-severity Zyxel NAS vulnerabilities were publicly disclosed.
The group used phishing campaigns and supply chain attacks to breach their victims’ computer networks.
RedJuliett’s tactics involve exploiting flaws in internet-facing devices and using techniques such as SQL-injection and directory traversal exploits.
Showing elements 1331 - 1340