Tag: APAC

New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA
News

New Wave of JSOutProx Malware Targeting Financial Firms in APAC and MENA

The Middle East and North Africa (MENA) and Asia-Pacific (APAC) financial institutions are the target of JSOutProx, a new "evolving threat" variant. In a technical paper released this week, Resecurity stated that "JSOutProx is an advanced attack framework that leverages both JavaScript and.NET." It interacts with a core JavaScript module that is operating on the victim's computer by using the.NET (de)serialization functionality. Once it's run, the malware allows the framework to load further plugins, which in turn carry out more harmful operations on the target. Early attacks dispersing JSOutProx were first discovered by Yoroi in December 2019 and have been linked to a threat actor known as Solar Spider. The history of bank strikes and other large company actions in Europe and As...
New Hacker Group ‘GambleForce’ Tageting APAC Firms Using SQL Injection Attacks
News

New Hacker Group ‘GambleForce’ Tageting APAC Firms Using SQL Injection Attacks

Since at least September 2023, a group of hackers known only as GambleForce have been linked to a number of SQL injection attacks against businesses, mostly in the Asia-Pacific (APAC) area. The Singapore-based Group-IB stated in a report shared with The Hacker News that "GambleForce uses a set of basic yet very effective techniques, including SQL injections and the exploitation of vulnerable website content management systems (CMS) to steal sensitive information, such as user credentials." 24 organizations in the gaming, government, retail, and travel sectors in Australia, Brazil, China, India, Indonesia, the Philippines, South Korea, and Thailand are thought to have been the group's targets read more New Hacker Group 'GambleForce' Tageting APAC Firms Using SQL Injection Attacks. ...