Cyfirma

Python-based RAT Abuses Discord API to Execute Data Theft Attacks

The Python-based Discord Remote Access Trojan (RAT) leverages Discord’s API as a C2 server to execute arbitrary system commands, steal sensitive information, capture screenshots, and manipulate both local machines and Discord servers.

Flesh Stealer Snoops on Web Browsers and Cryptocurrency Wallets

Flesh Stealer has been actively promoted on Discord, Telegram channels, and underground forums like Pyrex Guru. Employing Base64 obfuscation techniques to conceal its functions and strings, the stealer first emerged in August 2024.

NonEuclid RAT Combines Advanced Stealth, Anti-Detection, and Ransomware Capabilities

Developed in C# for the .NET Framework 4.8, NonEuclid is built to evade detection and offers a suite of advanced capabilities, including ransomware encryption, privilege escalation, and anti-detection mechanisms.

New FireScam Information Stealer Comes with Spyware Capabilities

FireScam monitors device activities such as screen state changes, e-commerce transactions, clipboard activity, and user engagement to gather valuable information covertly.

New Node.js-based Wish Stealer Targets Discord, Browsers, and Cryptocurrency Wallets

CYFIRMA recently discovered a new malware called “Wish Stealer” that targets Windows users by stealing sensitive information from various sources like Discord, web browsers, cryptocurrency wallets, and social media accounts.

Android Malware SpyNote Disguised as Fake Antivirus in New Campaign

Disguised as legitimate antivirus software, SpyNote exploits Android app permissions to gain extensive control, intercept credentials, and steal data from applications, including cryptocurrency wallets.

Pakistan-based Threat Actor Targets Indians with Fake Loan Android Application

These actors create fake loan apps, obtain personal details through a KYC process, and then extort money by threatening to distribute manipulated photos. The apps exploit minimal permissions to avoid detection.
December 20, 2023

Decrypting the Sidewinder Cyber Intrusion Tactics

The Sidewinder group, a sophisticated APT group originating from South Asia, is behind a highly targeted cyber threat campaign involving a malicious Word document with an embedded macro, potentially targeting Nepalese government officials.

WISE REMOTE Stealer Unleashed : Unveiling Its Multifaceted Malicious Arsenal

The WISE REMOTE Stealer is an advanced information stealer and Remote Access Trojan (RAT) that is coded in the Go programming language and utilizes code manipulation techniques to evade antivirus detection, making it difficult to detect and mitigate.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags