Tag: malware botnet

Volt Typhoon rebuilds malware botnet following FBI disruption
News

Volt Typhoon rebuilds malware botnet following FBI disruption

According to SecurityScorecard researchers, the Chinese state-sponsored hacker collective Volt Typhoon has started to reconstruct its "KV-Botnet" malware botnet following its disruption by law authorities in January. Since at least five years ago, the Chinese state-sponsored cyberespionage threat group Volt Typhoon is thought to have gained access to vital U.S. infrastructure as well as other networks across the globe. To install custom malware that creates secret communication and proxy channels and sustains ongoing access to targeted networks, they primarily hack SOHO routers and networking devices, including Netgear ProSAFE firewalls, Cisco RV320s, DrayTek Vigor routers read more about Volt Typhoon rebuilds malware botnet following FBI disruption. Get up to date on the latest ...
FBI: Androxgh0st malware botnet steals AWS and Microsoft credentials
News

FBI: Androxgh0st malware botnet steals AWS and Microsoft credentials

Threat actors utilizing the Androxgh0st virus are constructing a botnet aimed at stealing cloud credentials and exploiting the obtained data to distribute further malicious payloads, according to a warning issued today by CISA and the FBI. The botnet, which was first discovered by Lacework Labs in 2022, searches for websites and servers that have remote code execution (RCE) vulnerabilities by utilizing versions of the PHPUnit unit testing framework, PHP web framework, and Apache web server. CVE-2017-9841 (PHPUnit), CVE-2021-41773 (Apache HTTP Server), and CVE-2018-15133 (Laravel) are among the RCE weaknesses targeted by these attacks. The two agencies warned that Androxgh0st is a Python-scripted malware that is mainly used to target.env files that contain sensitive data read more...