Tag: campaign

Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets
News

Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets

After compromising over 830 packages in the npm registry, the second wave of the Shai-Hulud supply chain attack has spread to the Maven ecosystem. The Maven Central package org.mvnpm:posthog-node:4.18.1, according to the Socket Research Team, has the same two elements linked to Sha1-Hulud: the loader "setup_bun.js" and the primary payload "bun_environment.js." The Hacker News was informed by the company that the sole Java package found thus far was org.mvnpm:posthog-node:4.18.1. According to a Tuesday update from the cybersecurity firm, the PostHog project has compromised releases in both the JavaScript/npm and Java/Maven ecosystems, powered by the identical Shai Hulud v2 payload. It is important to note that PostHog does not publish the Maven Central package. Instead, an automat...
Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign
News

Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign

It is expected that a campaign exploiting the recently revealed security weaknesses that have been actively exploited in the field infected up to 2,000 Palo Alto Networks devices. The Shadowserver Foundation published figures showing that the U.S. (554) and India (461), followed by Thailand (80), Mexico (48), Indonesia (43), Turkey (41), the U.K. (39), Peru (36), and South Africa (35), have reported the most infections. Censys reported earlier this week that it had discovered 13,324 next-generation firewall (NGFW) administration interfaces that were openly accessible, with 34% of these exposures being in the United States. It's crucial to remember that not every one of these exposed hosts is inherently at risk read more about Over 2000 Palo Alto Networks Devices Hacked in Ongoing At...
DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign
News

DarkGate Malware Exploits Samba File Shares in Short-Lived Campaign

Researchers studying cybersecurity have provided insight into a brief campaign of DarkGate malware that spread by using Samba file shares. The activity, according to Palo Alto Networks Unit 42, took place between March and April of 2024. The infection chains used servers that were public-facing Samba file shares that hosted JavaScript and Visual Basic Script (VBS) files. North America, Europe, and portions of Asia were among the targets. This was a very short-lived campaign, according to security researchers Brad Duncan, Yijie Sui, Anmol Maurya, Uday Pratap Singh, and Vishwa Thothathri, that shows how threat actors can inventively misuse reputable tools and services to spread their malware. Since its inception in 2018, DarkGate has developed into a malware-as-a-service (MaaS) pro...
OpenSSH Trojan Campaign Targets IoT and Linux Systems
News

OpenSSH Trojan Campaign Targets IoT and Linux Systems

Security experts have identified a sophisticated assault operation that targets Linux-based systems and Internet of Things (IoT) devices by utilizing both open-source and bespoke tools. In a recent blog post, Microsoft claimed that the attackers used a modified version of OpenSSH to take over infected systems and install crypto mining software. An established criminal infrastructure is behind the attack campaign, and its command and control (C2) server is a Southeast Asian financial institution's subdomain read more OpenSSH Trojan Campaign Targets IoT and Linux Systems. Stay one step ahead of cyber threats with ReconBee.com. Explore our comprehensive coverage of recent cyber attacks, cybersecurity awareness, and the latest cybersecurity news to safeguard your digital world.
New Malware Campaign Leveraging Satacom Downloader to Steal Cryptocurrency
News

New Malware Campaign Leveraging Satacom Downloader to Steal Cryptocurrency

It has been discovered that a recent malware campaign used the Satacom downloader as a delivery mechanism to spread covert malware capable of stealing cryptocurrencies using a rogue extension for Chromium-based browsers. According to Kaspersky researchers Haim Zigel and Oleg Kupreev, the malware installed by the Satacom downloader is primarily designed to steal BTC from the victim's account by performing web injections into specific cryptocurrency websites. Users of Coinbase, Bybit, KuCoin, Huobi, and Binance who are mostly in Brazil, Algeria, Turkey, Vietnam, Indonesia, India, Egypt, and Mexico are the campaign's target audience. The Legion Loader, also known as the Satacom Downloader read more Malware Campaign Leveraging Satacom Downloader to Steal Cryptocurrency. Stay one s...