Tag: Israeli

Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations
News

Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations

A novel remote access trojan and information stealer that Iranian state-sponsored attackers employ to survey compromised endpoints and carry out malicious orders has been made public by cybersecurity experts. The malware has been identified in the wild since at least September 1, 2023, according to artifacts published to the VirusTotal database, and the cybersecurity firm Check Point has dubbed it WezRat. According to a technical report, WezRat has the ability to carry out keylogging, upload files, capture screenshots, execute commands, and steal cookie files and clipboard items. The primary component of the backdoor is less suspicious because distinct modules carry out some tasks read more about Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations. Ge...
Israeli Entities Targeted by Cyberattack Using Donut and Sliver Frameworks
News

Israeli Entities Targeted by Cyberattack Using Donut and Sliver Frameworks

Researchers studying cybersecurity have uncovered an assault operation that targets several Israeli organizations using frameworks like Donut and Sliver that are available to the public. "Leverage target-specific infrastructure and custom WordPress websites as a payload delivery mechanism, but affect a variety of entities across unrelated verticals, and rely on well-known open-source malware," according to a report released by HarfangLab last week, indicating that the campaign is thought to be highly targeted. The activity is being monitored by the French business using the moniker "Supposed Grasshopper." It is a pointer to a server under the control of the attacker ("auth.economy-gov-il[.]com/SUPPOSED_GRASSHOPPER.bin"), which is connected to by a first-stage downloader. This is ...
Iranian Tortoiseshell Hackers Targeting Israeli Logistics Industry
News

Iranian Tortoiseshell Hackers Targeting Israeli Logistics Industry

At least eight websites associated with shipping, logistics, and financial services companies in Israel were targeted as part of a watering hole attack. Tel Aviv-based cybersecurity company ClearSky attributed the attacks with low confidence to an Iranian threat actor tracked as Tortoiseshell, which is also called Crimson Sandstorm (previously Curium), Imperial Kitten, and TA456. "The infected sites collect preliminary user information through a script," ClearSky said in a technical report published Tuesday read more Iranian Tortoiseshell Hackers Targeting Israeli Logistics Industry. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, and the latest cybersecurity news.