Web threats

Incidents

Bagle botnet being updated

A few minutes ago the people who are maintaining the Bagle botnet started updating it. We’ve intercepted two new modifications of the Bagle family, Trojan-Downloader.Win32.Bagle.d and Trojan-Downloader.Win32.Bagle.e.

Reports

ToddyCat: your hidden email assistant. Part 2

An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.