Cybersecurity

OfflRouter Malware Evades Detection in Ukraine for Almost a Decade

Apr 18, 2024NewsroomIncident Response / Cyber Espionage Select Ukrainian government networks have remained infected with a malware called OfflRouter since 2015. Cisco Talos said its findings are based on an analysis of over 100 confidential documents that were infected with the VBA macro virus and uploaded to the VirusTotal malware scanning platform. “The documents contained […]

Cybersecurity

Threat actors leverage document publishing sites for ongoing credential and session token theft

Cisco Talos Incident Response (Talos IR) has observed the ongoing use of legitimate digital document publishing (DDP) sites for phishing, credential theft and session token theft during recent incident response and threat intelligence engagements. Hosting phishing lures on DDP sites increases the likelihood of a successful phishing attack, since these sites often have a favorable […]

Cybersecurity

EU Agrees ‘Cyber Solidarity Act’ to Bolster Incident Response and Reco

The European Union (EU) has agreed new rules to strengthen cyber incident response and recovery across member states, which has been dubbed the ‘cyber solidarity act.’ The provisional regulation aims to make the EU more resilient and reactive to cyber threats via new cooperation mechanisms. This includes the establishment of an EU-wide cybersecurity alert system, […]

Cybersecurity

More Signs of a Qakbot Resurgence

Cybercrime , Endpoint Detection & Response (EDR) , Fraud Management & Cybercrime Qakbot Wouldn’t Be the First Trojan to Come Back After a Takedown Akshaya Asokan (asokan_akshaya) • February 13, 2024     Security researchers are seeing new examples of Qakbot malware. (Image: Shutterstock) Takedowns aren’t always forever in cyberspace. Months after a U.S. law […]

Cybersecurity

DirtyMoe Malware Infects 2,000+ Ukrainian Computers for DDoS and Cryptojacking

Feb 02, 2024NewsroomCryptojacking / Malware The Computer Emergency Response Team of Ukraine (CERT-UA) has warned that more than 2,000 computers in the country have been infected by a strain of malware called DirtyMoe. The agency attributed the campaign to a threat actor it calls UAC-0027. DirtyMoe, active since at least 2016, is capable of carrying […]