Ukrainian government, military targeted with DarkCrystal RAT
The malware is being distributed via Signal messaging service.
The malware is being distributed via Signal messaging service.
The suspects are accused of being key players in the distribution and administration of malware loaders.
The attack chain involves the use of a MS Excel file with a VBA macro to initiate the infection process.
The Russian influence actors Storm-1679 and Storm-1099 have shifted their focus to the Olympics since June 2023.
The list of the most deployed, attributed malware families includes RATs, stealers, and ransomware.
Alongside the Dora RAT backdoor, the attacks involved a keylogger, infostealer, and proxy tools.
The threat actors have already split the stolen Bitcoin into multiple new wallets.
The sophistication of the attack suggests involvement of highly skilled actors.
The attackers gained access to authentication tokens.
In brief: Police hit malware droppers, the US dismantles a massive proxy botnet, five covert influence ops disrupted, and more.
Showing elements 1461 - 1470