Tag: Windows Systems

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems
News

NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems

Cybersecurity researchers have revealed information about NANOREMOTE, a brand-new, fully functional Windows backdoor that employs the Google Drive API for command-and-control (C2) functions. A report from Elastic Security Labs claims that the malware's code is comparable to that of another implant called FINALDRAFT (also known as Squidoor), which uses the Microsoft Graph API for C2. FINALDRAFT is linked to the REF7707 threat cluster (also known as CL-STA-0049, Earth Alux, and Jewelbug). According to Daniel Stepanic, chief security researcher at Elastic Security Labs, one of the main characteristics of the malware is its ability to transfer data back and forth from the victim endpoint via the Google Drive API. In the end, this feature creates a difficult-to-detect conduit for payl...
EncryptHub linked to MMC zero-day attacks on Windows systems
News

EncryptHub linked to MMC zero-day attacks on Windows systems

EncryptHub is a threat actor that has been connected to Windows zero-day attacks that take use of a Microsoft Management Console vulnerability that was fixed this month. The 'MSC EvilTwin' security feature bypass, which Trend Micro staff researcher Aliakbar Zahravi discovered, is located in the way MSC files are handled on susceptible systems and is now being tracked as CVE-2025-26633. Because the user is not alerted before loading unusual MSC files on unpatched devices, attackers can utilize the vulnerability to circumvent Windows file reputation protections and run code. According to a Microsoft advisory released during this month's Patch Tuesday, an attacker might take advantage of the vulnerability in an email attack scenario read more about EncryptHub linked to MMC zero-day ...
Critical ‘BatBadBut’ Rust Vulnerability Exposes Windows Systems to Attacks
News

Critical ‘BatBadBut’ Rust Vulnerability Exposes Windows Systems to Attacks

A serious security vulnerability in the Rust standard library might be used to launch command injection attacks against Windows users. The vulnerability, identified by the tracking number CVE-2024-24576, has a maximum severity of 10.0 on the CVSS. That being stated, it only affects situations in which Windows batch files are called with untrusted parameters. According to a working group advisory published on April 9, 2024, the Rust standard library does not appropriately escape arguments when calling batch files (with the bat and cmd extensions) on Windows using the Command API. Bypassing the escaping, an attacker with control over the inputs given to the generated process might execute any shell command read more Critical 'BatBadBut' Rust Vulnerability Exposes Windows Systems to...