HelloNet campaign: new malicious modules launched through the ViPNet update system
posted
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
Expert-led service offering round-the-clock monitoring, detection, investigation and rapid response to sophisticated cyberattacks, augmenting companies’ existing security controls with human-led detection and global threat intelligence.
posted
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
posted
updated UPD
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.
posted
Over the past two months, the anonymous researcher Nightmare Eclipse has publicly released six Windows vulnerabilities complete with ready-to-use exploits, without prior coordination with Microsoft. The most critical of these is MiniPlasma.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.
Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud.
Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.