Tag: backdoor

New EAGERBEE Variant Targets ISPs and Governments with Advanced Backdoor Capabilities
News

New EAGERBEE Variant Targets ISPs and Governments with Advanced Backdoor Capabilities

An improved version of the EAGERBEE malware framework has been used to attack Middle Eastern governments and Internet service providers (ISPs). The latest EAGERBEE variant, also known as Thumtais, exhibits a notable progression by including a number of components that enable the backdoor to execute command shells, enumerate file systems, and deliver additional payloads. According to an analysis by Kaspersky researchers Saurabh Sharma and Vasily Berdnikov, the main plugins can be divided into the following groups based on their functionalities: Plugin Orchestrator, File System Manipulation, Remote Access Manager, Process Exploration, Network Connection Listing, and Service Management. The Russian cybersecurity firm has given the backdoor read more about New EAGERBEE Variant Target...
JAVS courtroom recording software backdoored in supply chain attack
News

JAVS courtroom recording software backdoored in supply chain attack

Malware has been used to backdoor the installation of Justice AV Solutions (JAVS), a popular courtroom video recording program, allowing attackers to gain control of affected PCs. The digital recording technology, commonly referred to as JAVS, is presently installed in over 10,000 courtrooms, law offices, penal facilities, and other entities globally, according to the company that created it. Since then, JAVS has taken down the compromised version from its official website, claiming that the malicious fffmpeg.exe component that was part of the trojanized program "did not come from JAVS or any 3rd party related to JAVS." To make sure that, in the unlikely event that they were stolen, the organization reset all passwords and performed a thorough examination of all systems read more...
New Backdoor Created Using Leaked CIA’s Hive Malware Discovered in the Wild
Risk, Security

New Backdoor Created Using Leaked CIA’s Hive Malware Discovered in the Wild

Unknown threat actors have launched a new backdoor that copies features from the multi-platform Hive malware suite developed by the U.S. Central Intelligence Agency (CIA), whose source code was made public by WikiLeaks in November 2017. Alex Turing and Hui Wang of Qihoo Netlab 360 wrote in a technical write-up released last week: "This is the first time we captured a variant of the CIA Hive attack kit in the field, and we dubbed it xdr33 based on its embedded Bot-side certificate CN=xdr33." According to reports, xdr33 spreads by taking advantage of a security flaw in the F5 appliance and connecting to a command-and-control (C2) server over SSL while utilizing counterfeit Kaspersky certificates read the complete article New Backdoor Created Using Leaked CIA's Hive Malware Discovered ...