Tag: Credential Theft

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate
News

Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate

As part of an ongoing campaign, threat actors continue to target Mexican organizations in order to distribute a modified version of SystemBC and AllaKore RAT. The activity has been attributed by Arctic Wolf Labs to a financially motivated hacking group called Greedy Sponge. Targeting a broad range of industries, including retail, manufacturing, transportation, capital goods, entertainment, agriculture, the public sector, and commercial services, it is thought to have been operational since early 2021. According to a cybersecurity firm's analysis released last week, the AllaKore RAT payload has been significantly altered to allow threat actors to transmit specific banking credentials and one-of-a-kind authentication data back to their command-and-control (C2) server in order to perpe...
HubPhish Exploits HubSpot Tools to Target 20000 European Users for Credential Theft
News

HubPhish Exploits HubSpot Tools to Target 20000 European Users for Credential Theft

A new phishing attempt that targeted European firms with the intention of obtaining account credentials and taking over the victims' Microsoft Azure cloud infrastructure has been revealed by cybersecurity researchers. Palo Alto Networks Unit 42 has given the campaign the codename HubPhish because of the misuse of HubSpot products in the attack chain. At least 20,000 European consumers who manufacture industrial, chemical, and automotive compounds are among the targets. In a study posted with The Hacker News, security experts Shachar Roitman, Ohad Benyamin Maimon, and William Gamazo stated that the campaign's phishing attempts peaked in June 2024, utilizing phony forms made with the HubSpot Free Form Builder tool read more about HubPhish Exploits HubSpot Tools to Target 20000 Europea...
Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft
News

Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft

Microsoft has disclosed that Storm-0940, a Chinese threat actor it monitors, is using a botnet known as Quad7 to plan extremely evasive password spray attacks. The IT giant claims that the password spray operations are used to steal credentials from numerous Microsoft customers, and has named the botnet CovertNetwork-1658. According to the Microsoft Threat Intelligence team, Storm-0940 has been active since at least 2021 and gains initial access through brute-force and password-spraying attacks, as well as by abusing or taking advantage of network edge apps and services read more about Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverag...