Poland’s government institutions targeted in Russian cyberespionage campaign
The incident marks the latest in a string of Russian cyberattacks aimed at NATO-allied nations supporting Ukraine.
The incident marks the latest in a string of Russian cyberattacks aimed at NATO-allied nations supporting Ukraine.
The latest version of HijackLoader incorporates as many as seven new modules, expanding its capabilities further.
The attack maintains the appearance of a secure VPN connection, evading detection by VPN control mechanisms such as kill switches.
Censys identified 90,310 hosts exposing Tinyproxy services to the public internet.
Once installed, the malware grants cybercriminals unauthorized access to the victim's online banking info.
A Russian threat actor behind the alias 'LockBitSupp' has been identified as Dmitry Khoroshev.
The China-linked UNC5221 cluster appears to be behind the hack.
An analysis of the attacker-controlled IP addresses suggests potential involvement of a China-based threat actor.
Initial investigations suggest that no operational data was obtained.
Graph API is often used for discreet communications to cloud-based C&C servers.
Showing elements 1431 - 1440