Incidents

Fake CNN Emails Claim US Have Started Bombing Syria

We’re currently seeing a spam run which involves a (fake) report from CNN saying that the US have started bombing Syria.

208214061

Clicking the shortened link will lead to an exploit kit which targets older, vulnerable versions of Adobe Reader and Java. The attackers favor using the Java exploit over the Reader exploit, as Java exploits are generally more reliable.

208214057

The exploit will download a Trojan-Downloader onto the system, which will subsequently download various other malware.

We’ve seen these actors use various methods of getting people to click on links in emails, including fake Facebook and PayPal emails. They also tend to use various URL shortening services.

It’s not surprising to see cyber-criminals jump on actualities. If the US do decide in favor of military action against Syria we can expect a lot more Syria-themed malicious emails.

Fake CNN Emails Claim US Have Started Bombing Syria

Your email address will not be published. Required fields are marked *

 

Reports

Operation TunnelSnake

A newly discovered rootkit that we dub ‘Moriya’ is used by an unknown actor to deploy passive backdoors on public facing servers, facilitating the creation of a covert C&C communication channel through which they can be silently controlled. The victims are located in Africa, South and South-East Asia.

APT trends report Q1 2021

This report highlights significant events related to advanced persistent threat (APT) activity observed in Q1 2021. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports.

The leap of a Cycldek-related threat actor

The investigation described in this article started with one such file which caught our attention due to the various improvements it brought to this well-known infection vector.

Subscribe to our weekly e-mails

The hottest research right in your inbox