Proof Point

Threat Actors Deliver Malware via YouTube Video Game Cracks

Many types of video games appear to be targeted to younger users including games popular with children, a group that is less likely to be able to identify malicious content and risky online behaviors.

TA4903 Threat Actor Spoofs U.S. Government, Small Businesses in Phishing, BEC Bids

The actor uses tactics such as spoofing government agencies, incorporating QR codes in phishing campaigns, and adopting new themes to lure victims into credential phishing and BEC activities.

‘Tis the Season for Tax Hax

TA576, a cybercriminal threat actor, has returned with tax-themed lures targeting accounting and finance organizations during the U.S. tax season, using unique attack chains and delivering Parallax RAT.

TA866 Returns with a Large Email Campaign

The new campaign by TA866 involved a large volume of emails with attached PDFs containing OneDrive URLs that initiated a multi-step infection chain leading to malware payload.

BattleRoyal Threat Cluster Spread DarkGate RAT via Email and Fake Browser Updates

The BattleRoyal cluster, using DarkGate and NetSupport malware, demonstrates the use of multiple attack chains and social engineering techniques to deliver payloads via email and fake update lures.

TA422’s Dedicated Exploitation Loop—the Same Week After Week

Russian APT group TA422 has been actively exploiting patched vulnerabilities to target government, aerospace, education, finance, manufacturing, and technology sectors in Europe and North America.

TA402 Uses Complex IronWind Infection Chains to Target Middle East-Based Government Entities

TA402 has recently employed a new initial access downloader called IronWind, using various infection chains and delivery methods such as Dropbox links, XLL and RAR file attachments, in order to evade detection.

TA571 Delivers Forked IcedID Loader Variant

The use of the Forked IcedID variant, which removes banking functionality and focuses on payload delivery, highlights a shift in malware tactics toward prioritizing ransomware delivery.

From Copacabana to Barcelona: The Cross-Continental Threat of Brazilian Banking Malware

Proofpoint researchers have discovered a new version of the Grandoreiro malware that is targeting victims in both Mexico and Spain. This is unusual as the malware has historically only targeted Portuguese and Spanish speakers in Brazil and Mexico.

ZenRAT Malware Brings More Chaos Than Calm

ZenRAT is a new malware targeting Windows users and being distributed via fake Bitwarden installation packages. The malware redirects non-Windows users to a benign webpage while stealing information from Windows users.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags