SentinelOne

LABScon25 Replay | LLM-Enabled Malware In the Wild

Over 500 GitHub repositories were found distributing infostealers disguised as Minecraft mods. The Fractureiser malware was spread via popular modding platforms like Bukkit and CurseForge, targeting both Windows and Linux users.

The Good, the Bad and the Ugly in Cybersecurity – Week 36

Three Russian FSB officers are accused of orchestrating cyberattacks on U.S. critical infrastructure. Two malicious npm packages were using Ethereum smart contracts to conceal URLs for second-stage payload delivery.

The Good, the Bad and the Ugly in Cybersecurity – Week 34

Key incidents include the sentencing of high-profile cybercriminals, enhanced supply chain protections by PyPI, the evolution of the Noodlophile infostealer, and a sophisticated DPRK-linked espionage campaign using the MoonPeak RAT.

Smart Contract Scams | Ethereum Drainers Pose as Trading Bots to Steal Crypto

A widespread cryptocurrency scam campaign has been uncovered, where threat actors distribute malicious Ethereum smart contracts disguised as trading bots. These contracts have collectively stolen over $900,000 USD from unsuspecting users.

Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem

A sophisticated infostealer campaign leveraging the Python-based PXA Stealer has compromised over 4,000 systems across 62 countries. The campaign exfiltrates credentials, cookies, and financial data via Telegram bots and Cloudflare Workers.

macOS.ZuRu Resurfaces | Modified Khepri C2 Hides Inside Doctored Termius App

A new variant of the macOS.ZuRu malware has resurfaced, targeting macOS users through a trojanized version of the Termius SSH client. This version incorporates a modified Khepri C2 beacon and introduces new techniques for persistence.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags