Massive credential theft campaign exploits React2Shell flaw in Next.js apps
At least 766 systems spanning multiple cloud providers and geographic regions have already been compromised.
At least 766 systems spanning multiple cloud providers and geographic regions have already been compromised.
In brief: Google patches Chrome zero-day, Chinese hackers exploit zero-day flaw in TrueConf, and more.
While some of TA416’s techniques, tactics and procedures remained unchanged, Proofpoint observed the group modifying its infection chains.
The campaign combines social engineering with “living-off-the-land” techniques.
Google didn’t disclose any additional details regarding the nature of exploitation.
As part of the breach, multiple AWS access keys were stolen and later used for unauthorized activity across a limited number of Cisco cloud accounts.
Attackers leveraged the update channel of TrueConf to deliver malware, more specifically a payload linked to the Havoc C&C framework.
The hackers hijacked the npm account of the library's developer and inserted a malicious dependency into the package configuration.
He now faces up to 10 years in prison on a computer fraud charge and up to 20 years if convicted of money laundering.
The investigation began when the researchers examined activity linked to the Stately Taurus group that leveraged USB-based malware called USBFect, aka HIUPAN.
Showing elements 231 - 240