Lumma infostealer returns after May police crackdown
Lumma has shifted away from previous use of Cloudflare and is now leveraging alternative cloud services, particularly the Russian provider Selectel.
Lumma has shifted away from previous use of Cloudflare and is now leveraging alternative cloud services, particularly the Russian provider Selectel.
The impacted products include Cisco ISE and ISE-PIC versions 3.3 and 3.4.
Authorities estimate the suspect earned over EUR 7 million through advertising revenues and facilitation fees.
No classified or sensitive data appears to have been compromised.
Recent DCHSpy samples have been disguised as VPN and banking apps and promoted on Telegram channels in both English and Farsi.
The exploit chain, dubbed ‘ToolShell’, has enabled the compromise of dozens of organizations worldwide.
The tool is designed to gather extensive information, including GPS data, SMS messages, photos, contacts, and audio.
The decryptor aims to help victims recover locked files without paying ransom demands.
According to Shadowserver, nearly 1,040 CrushFTP servers are still unpatched and exposed online.
Additionally, UK’s NCSC has publicly attributed the deployment of a sophisticated new malware dubbed ‘AUTHENTIC ANTICS’ to the APT28 threat actor long thought to be a unit of the GRU (Military Unit 26165).
Showing elements 601 - 610