CERT-UA warns of phishing campaign using GitHub and malware
The messages urge recipients to urgently update mobile applications used in widely deployed civilian and military systems.
The messages urge recipients to urgently update mobile applications used in widely deployed civilian and military systems.
The attackers deployed the BurrowShell backdoor, capable of taking screenshots, system manipulation, remote shell execution, and operating as SOCKS proxy.
The campaign distributes one of the most fully featured browser-based surveillance toolkits observed in the wild.
The malicious npm packages masquerade as legitimate developer utilities but contain hidden functionality designed to retrieve C&C infrastructure.
The agency revealed the recovery phrase to a seized cryptocurrency wallet on a photo of a confiscated device.
The activity originated from 4,305 unique IP addresses spanning 20 autonomous systems.
The campaign involves five key malicious components: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE.
The report provides deeper technical insight into the implant’s capabilities.
In brief: Cisco patches Catalyst SD-WAN zero-day, a China-linked cyber espionage campaign compromised over 50 organizations worldwide, and more.
As part of the campaign, 53 organizations across 42 countries were compromised, with suspected infections spanning at least 20 additional nations.
Showing elements 211 - 220