Tag: InfoStealer Malware

Hackers poison arrayref Rust crate to push infostealer malware
News

Hackers poison arrayref Rust crate to push infostealer malware

Malware that ran on developers' systems during compilation was introduced by hackers who gained access to the maintainer account for the popular Rust crate arrayref. In the same supply-chain attack, the attacker additionally poisoned two further crates, append-only-vec and internment, within a 23-minute span. With over 53 million downloads in the last 90 days, the arrayref crate is a well-liked Rust library that is utilized by blockchain, graphics, and cryptography tools. The malicious Rust crate releases were arrayref 0.3.10, append-only-vec 0.1.9, and internment 0.8.7, all of which were maintained by the same account, according to a report from application security firm StepSecurity. While leaving the remaining upstream source code entirely unaltered, the hacker added a depende...
Rhadamanthys infostealer disrupted as cybercriminals lose server access
News

Rhadamanthys infostealer disrupted as cybercriminals lose server access

The operation of the Rhadamanthys infostealer has been interrupted, and many “customers” using the malware-as-a-service are reporting that they can no longer access their servers. Rhadamanthys is a type of infostealer malware that pilfers credentials and authentication cookies from browsers, email clients, and various other applications. It is widely disseminated via campaigns disguised as software cracks, YouTube videos, or harmful search ads. The malware is provided on a subscription basis, with cybercriminals paying the developer monthly for access to the malware, assistance, and a web panel for collecting stolen data. Cybersecurity researchers g0njxa and Gi7w0rm, who monitor malware operations such as Rhadamanthys, report that cybercriminals involved in the operation assert t...
Botnet targets Basic Auth in Microsoft 365 password spray attacks
News

Botnet targets Basic Auth in Microsoft 365 password spray attacks

Password-spray assaults against Microsoft 365 (M365) accounts globally are being carried out by a vast botnet of more than 130,000 infected machines, which targets basic authentication in order to circumvent multi-factor authentication. According to a SecurityScorecard assessment, the attackers are targeting the accounts on a broad scale by using credentials that were acquired by infostealer malware. To get beyond Multi-Factor Authentication (MFA) safeguards and obtain unauthorized access without setting off security alerts, the assaults rely on non-interactive sign-ins using Basic Authentication (Basic Auth). Businesses that only use interactive sign-in monitoring are unaware of these threats read more about Botnet targets Basic Auth in Microsoft 365 password spray attacks. G...
Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines
News

Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines

Researchers studying cybersecurity have discovered harmful packages on the public Python Package Index (PyPI) repository that infect Windows computers with the information-stealing malware known as WhiteSnake Stealer. The packages nigpal, figflix, telerer, seGMM, fbdebug, sGMM, myGens, NewGends, and TestLibs111 are infected with malware. "WS" is the threat actor who uploaded them. These packages incorporate Base64-encoded source code of PE or other Python scripts within their setup.py files," Fortinet FortiGuard Labs noted in a research published last week. The last malicious payload is dumped and executed when these Python packages are installed read more Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines. Get up to date on the latest cybersecu...