Tag: RAT malware

Silver Fox APT Targets Taiwan with Complex Gh0stCringe and HoldingHands RAT Malware
News

Silver Fox APT Targets Taiwan with Complex Gh0stCringe and HoldingHands RAT Malware

Researchers studying cybersecurity are alerting people in Taiwan to a new phishing effort that uses malware families including Gh0stCringe and HoldingHands RAT. According to a report provided to The Hacker News by Fortinet FortiGuard Labs, the action is a part of a larger effort that sent phishing communications posing as Taiwan's National Taxation Bureau early this January in order to distribute the Winos 4.0 malware framework. The cybersecurity firm claimed to have discovered more malware samples through ongoing surveillance and to have seen the same threat actor, known as Silver Fox APT, distribute Gh0stCringe and a malware strain based on HoldingHands RAT via phishing emails using malware-infected PDF documents or ZIP files. It is important to note that Gh0stCringe and Holdin...
Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims
News

Fake Kling AI Facebook Ads Deliver RAT Malware to Over 22 Million Potential Victims

Fraudulent Facebook pages and paid advertisements on the social media network are being used to deceive victims into downloading malware by directing them to phony websites impersonating Kling AI. Using text and image cues, Kling AI is a platform that uses artificial intelligence (AI) to create graphics and movies. The Beijing, China-based Kuaishou Technology is the company behind it, and it was introduced in June 2024. According to business figures, the service had over 22 million users as of April 2025. According to Check Point, the assault used phony Facebook pages and advertisements to spread a malicious file that eventually caused a remote access Trojan (RAT) to run, giving the attackers remote control over the victim's PC and the opportunity to collect confidential information...
Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails
News

Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails

A suspected actor with ties to Russia used a recently patched security hole in Windows NT LAN Manager (NTLM) as a zero-day exploit in cyberattacks against Ukraine. CVE-2024-43451 (CVSS score: 6.5) is a vulnerability that might be used to obtain a user's NTLMv2 hash. It is an NTLM hash disclosure spoofing vulnerability. Microsoft corrected it early this week. According to Microsoft's advisory, this vulnerability could be activated by a user choosing (single-clicking), inspecting (right-clicking), or doing an action other than opening or running a malicious file read more about Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the ...
Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware
News

Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware

Researchers studying cybersecurity have uncovered a new phishing effort that disseminates Remcos RAT, a fileless version of well-known commercial malware. Researchers Xiaopeng Zhang and Remcos RAT "provide purchases with a wide range of advanced features to remotely control computers belonging to the buyer," according to a report released last week by Fortinet FortiGuard Labs. Threat actors have, however, misused Remcos to obtain private data from victims and take over their computers remotely to carry out additional nefarious deeds read more about Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions. ...
Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware
News

Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware

The cybersecurity company CrowdStrike has issued a warning that threat actors are taking advantage of the situation to spread Remcos RAT to its clients in Latin America under the pretense of offering a hotfix. CrowdStrike is currently under fire for causing widespread IT disruptions by pushing out a faulty update to Windows devices. The attack chains entail the distribution of a ZIP archive file called "crowdstrike-hotfix.zip," which is the payload for the Remcos RAT malware loader Hijack Loader (also known as DOILoader or IDAT Loader). To be more precise, the archive file also contains a text file called "instrucciones.txt" that contains instructions in Spanish urging users to run an executable file called "setup.exe" to fix the problem read more about Cybercriminals Exploit CrowdS...
Russian Government Software Backdoored to Deploy Konni RAT Malware
News

Russian Government Software Backdoored to Deploy Konni RAT Malware

A backdoor has been included in an installer for a utility that is probably used by the Ministry of Foreign Affairs (MID)'s Russian Consular Department to distribute the remote access trojan Konni RAT (also known as UpDog). The investigation was conducted by German cybersecurity firm DCSO, which concluded that actors with ties to the Democratic People's Republic of Korea (DPRK) were behind the action, which was directed towards Russia. The Konni activity cluster, also known as Opal Sleet, Osmium, or TA406, has a documented history of using Konni RAT against Russian organizations. Since October 2021, at least, the threat actor has also been connected to assaults on MID. In November 2023, Fortinet FortiGuard Labs made public the use of Microsoft Word documents written in Russian as...
Lazarus hackers drop new RAT malware using 2-year-old Log4j bug
News

Lazarus hackers drop new RAT malware using 2-year-old Log4j bug

Lazarus, the infamous North Korean hacker group, is back at it again, using CVE-2021-44228, also known as "Log4Shell," to unleash three families of malware written in DLang that have never been seen before. Two remote access trojans (RATs) called NineRAT and DLRAT as well as a malware downloader called BottomLoader make up the new malware. Lazarus most likely selected the D programming language for new malware development in order to avoid detection because it is not frequently used in cybercrime operations. Code-named "Operation Blacksmith," the campaign began in March 2023 and targets physical security, manufacturing, and agricultural companies globally, according to Cisco read more Lazarus hackers drop new RAT malware using 2-year-old Log4j bug. Get up to date on the lates...