Tag: Belarus

Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus
News

Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus

Sticky Werewolf, a threat actor, has been connected to targeted attacks, mostly in Russia and Belarus, with the intention of using an as-yet-unknown implant to spread the Lumma Stealer virus. Under the alias Angry Likho, cybersecurity firm Kaspersky is monitoring the behavior, claiming it has a "strong resemblance" to Awaken Likho (also known as Core Werewolf, GamaCopy, and PseudoGamaredon). With a more condensed infrastructure, a smaller selection of implants, and an emphasis on workers of big businesses, such as government agencies and their contractors, Angry Likho's attacks are more focused, the Russian company claimed read more about Sticky Werewolf Uses Undocumented Implant to Deploy Lumma Stealer in Russia and Belarus. Get up to date on the latest cybersecurity news and en...
Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus
News

Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus

Organizations in Belarus and Russia are the only ones targeted by cyberattacks connected to the hacktivist collective Head Mare. In a Monday study of the group's strategies and equipment, Kaspersky claimed that Head Mare obtains early access through more modern means. For example, the attackers exploited the relatively new WinRAR vulnerability CVE-2023-38831, which enables the attacker to run arbitrary code on the system using an archive that has been specially constructed. With this strategy, the gang is better able to conceal and deliver the harmful payload. One of the hacktivist groups targeting Russian organizations in the context of the Russo-Ukrainian conflict that started the previous year is Head Mare read more about Hacktivists Exploits WinRAR Vulnerability in Attacks Ag...
Sticky Werewolf Expands Cyber Attack Targets in Russia and Belarus
News

Sticky Werewolf Expands Cyber Attack Targets in Russia and Belarus

Researchers studying cybersecurity have revealed information on Sticky Werewolf, a threat actor connected to cyberattacks against targets in Belarus and Russia. In addition to government agencies, the phishing assaults also targeted a pharmaceutical company, a Russian research institute that specializes in microbiology and vaccine development, and the aviation industry, according to a study released by Morphisec last week. Security researcher Arnold Osipov stated, "In prior campaigns, the infection chain started with phishing emails containing a link to download a malicious file from platforms like gofile.io." The most recent campaign made use of archive files that pointed to a payload kept on WebDAV servers via LNK files. In October 2023, BI.ZONE first reported about Sticky Were...