Tag: Hacker Group

Chinese-Speaking Hacker Group Targets Human Rights Studies in Middle East
News

Chinese-Speaking Hacker Group Targets Human Rights Studies in Middle East

Since June 2023, a threat actor going by the name of Tropic Trooper has been conducting a sustained cyber campaign against unidentified government agencies in the Middle East and Malaysia. According to Sherif Magdy, a security researcher at Kaspersky, "this group's sighting of their [Tactics, Techniques, and Procedures] in important governmental entities in the Middle East, particularly those related to human rights studies, marks a new strategic move." The activity was discovered in June 2024, according to the Russian cybersecurity vendor, when a public web server running the open-source Umbraco content management system (CMS) discovered a new version of the China Chopper web Shell—a tool used by many Chinese-speaking threat actors for remote access to compromised servers read more...
FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT
News

FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT

The financially motivated threat actor known as FIN7 has been seen distributing MSIX installers that ultimately lead to the deployment of NetSupport RAT by using malicious Google advertising that mimic reputable firms. According to a report released earlier this week by cybersecurity firm eSentire, the threat actors impersonated well-known organizations, such as AnyDesk, WinSCP, BlackRock, Asana, Concur, The Wall Street Journal, Workable, and Google Meet, using malicious websites. A persistent e-crime outfit that has been operating since 2013, FIN7 (also known as Carbon Spider and Sangria Tempest) first dabbled in attacks aimed at point-of-sale (PoS) devices to steal payment data before refocusing on ransomware campaigns to penetrate large firms. The threat actor has improved its...
New Hacker Group ‘GambleForce’ Tageting APAC Firms Using SQL Injection Attacks
News

New Hacker Group ‘GambleForce’ Tageting APAC Firms Using SQL Injection Attacks

Since at least September 2023, a group of hackers known only as GambleForce have been linked to a number of SQL injection attacks against businesses, mostly in the Asia-Pacific (APAC) area. The Singapore-based Group-IB stated in a report shared with The Hacker News that "GambleForce uses a set of basic yet very effective techniques, including SQL injections and the exploitation of vulnerable website content management systems (CMS) to steal sensitive information, such as user credentials." 24 organizations in the gaming, government, retail, and travel sectors in Australia, Brazil, China, India, Indonesia, the Philippines, South Korea, and Thailand are thought to have been the group's targets read more New Hacker Group 'GambleForce' Tageting APAC Firms Using SQL Injection Attacks. ...