Showing posts with label Jérôme Segura. Show all posts
Showing posts with label Jérôme Segura. Show all posts

Thursday, February 22, 2018

Friday, January 12, 2018

Tuesday, December 5, 2017

Seamless campaign serves RIG EK via Punycode

The most prolific gate to the RIG exploit kit is coming in a different flavor. The Seamless campaign is now using a domain name with foreign characters translated by Punycode.

Categories:

Tags:

(Read more...)

The post Seamless campaign serves RIG EK via Punycode appeared first on Malwarebytes Labs.

The post Seamless campaign serves RIG EK via Punycode appeared first on Security Boulevard.



from Seamless campaign serves RIG EK via Punycode

Wednesday, November 29, 2017

Persistent drive-by cryptomining coming to a browser near you

If you think closing your browser window to leave a site that runs a cryptominer will stop the mining process, think again. Persistent drive-by cryptomining has arrived.

Categories:

Tags:

(Read more...)

The post Persistent drive-by cryptomining coming to a browser near you appeared first on Malwarebytes Labs.

The post Persistent drive-by cryptomining coming to a browser near you appeared first on Security Boulevard.



from Persistent drive-by cryptomining coming to a browser near you

Thursday, November 9, 2017

Disdain exploit kit served with a side of social engineering

Exploits may not be enough as threat actors combine them with social engineering in a new Disdain exploit kit attack method.

Categories:

Tags:

(Read more...)

The post Disdain exploit kit served with a side of social engineering appeared first on Malwarebytes Labs.

The post Disdain exploit kit served with a side of social engineering appeared first on Security Boulevard.



from Disdain exploit kit served with a side of social engineering

Tuesday, November 7, 2017

A look into the global drive-by cryptocurrency mining phenomenon

As drive-by downloads slow down, drive-by cryptocurrency mining emerges as the latest annoyance that hijacks our PCs' CPU.

Categories:

Tags:

(Read more...)

The post A look into the global drive-by cryptocurrency mining phenomenon appeared first on Malwarebytes Labs.

The post A look into the global drive-by cryptocurrency mining phenomenon appeared first on Security Boulevard.



from A look into the global drive-by cryptocurrency mining phenomenon

Tuesday, September 12, 2017

Compromised LinkedIn accounts used to send phishing links via private message and InMail

A recent attack uses existing LinkedIn user accounts to send phishing links to their contacts via private message but also to external members via email.

Categories:

Tags:

(Read more...)

The post Compromised LinkedIn accounts used to send phishing links via private message and InMail appeared first on Malwarebytes Labs.



from Compromised LinkedIn accounts used to send phishing links via private message and InMail

Wednesday, August 9, 2017

Thursday, May 11, 2017

New ‘Jaff’ ransomware via Necurs asks for 2 BTC

The dreaded Necurs botnet delivers a new ransomware with a high ransom ask in this newest spam campaign.

Categories:

Tags:

(Read more...)

The post New ‘Jaff’ ransomware via Necurs asks for 2 BTC appeared first on Malwarebytes Labs.



from New ‘Jaff’ ransomware via Necurs asks for 2 BTC

Wednesday, April 26, 2017

A story of fonts by the EITest HoeflerText campaign

The HoeflerText campaign is known for a fake font download that delivers the Spora ransomware. But did you know it also uses special characters in the dropper's file name?

Categories:

Tags:

(Read more...)

The post A story of fonts by the EITest HoeflerText campaign appeared first on Malwarebytes Labs.



from A story of fonts by the EITest HoeflerText campaign

Wednesday, April 12, 2017

Sundown EK gone missing, Terror EK flavours seen in active drive-by campaigns

With another player out at the moment, we take a look at a rebranded exploit kit in current malware campaigns.

Categories:

Tags:

(Read more...)

The post Sundown EK gone missing, Terror EK flavours seen in active drive-by campaigns appeared first on Malwarebytes Labs.



from Sundown EK gone missing, Terror EK flavours seen in active drive-by campaigns

Thursday, April 6, 2017

Malvertising on iOS pushes eyebrow-raising VPN app

A malvertising campaign on iOS is pushing a scareware page tricking Apple users into installing a free VPN app that comes with serious privacy implications.

Categories:

Tags:

(Read more...)

The post Malvertising on iOS pushes eyebrow-raising VPN app appeared first on Malwarebytes Labs.



from Malvertising on iOS pushes eyebrow-raising VPN app

Thursday, March 30, 2017

Websites compromised in ‘Decimal IP’ campaign

This URL is quite probably unlike anything you've ever seen before and yet still works and redirects to malware.

Categories:

Tags:

(Read more...)

The post Websites compromised in ‘Decimal IP’ campaign appeared first on Malwarebytes Labs.



from Websites compromised in ‘Decimal IP’ campaign

Wednesday, March 22, 2017

SMS phishing for the masses

This post looks at a recent SMS phishing scam for the RBC bank and a tool the attackers may have used to bulk send fraudulent SMS messages.

Categories:

Tags:

(Read more...)

The post SMS phishing for the masses appeared first on Malwarebytes Labs.



from SMS phishing for the masses

Tuesday, March 21, 2017

Canada and the U.K. hit by Ramnit Trojan in new malvertising campaign

This new malvertising campaign on adult websites was pushing the Ramnit information stealer.

Categories:

Tags:

(Read more...)

The post Canada and the U.K. hit by Ramnit Trojan in new malvertising campaign appeared first on Malwarebytes Labs.



from Canada and the U.K. hit by Ramnit Trojan in new malvertising campaign

Thursday, March 9, 2017

Exploit kits: Winter 2017 review

We take a look at the current exploit kit scene (Winter 2017) according to our telemetry and honeypots.

Categories:

Tags:

(Read more...)

The post Exploit kits: Winter 2017 review appeared first on Malwarebytes Labs.



from Exploit kits: Winter 2017 review

Tuesday, February 21, 2017

Rogue Chrome extension pushes tech support scam

Google Chrome may be one of the more secure browsers but an increasing number of malicious extensions are being forced onto users. The one we analyze can hide itself and receive commands from a remote server in order to hijack the browser with incessant offers, fraud and even tech support scams.

Categories:

Tags:

(Read more...)



from Rogue Chrome extension pushes tech support scam

Friday, February 3, 2017

2016 State of Malware Report

2016 was the year that reminded us how important prevention is, no matter what type of user you may be. Indeed ransomware dominated the threat landscape and was heavily distributed via phishing emails, compromised websites, or malicious ads. With such a threat that encrypts your valuable data, there is often times very little you can do...

Categories:

Tags:

(Read more...)



from 2016 State of Malware Report

Thursday, January 5, 2017

Tech support scam page triggers denial-of-service attack on Macs

Tech support scammers are up to dirty tricks again, trying to cause your computer to freeze by simply visiting a webpage.

Categories:

Tags:

(Read more...)



from Tech support scam page triggers denial-of-service attack on Macs

Tuesday, November 22, 2016

An overview of malvertising on the Mac

Mac users may face less malware attacks than their Windows counterparts, but it doesn't mean they are safe from online crooks. In this post we review the top malvertising attacks that target the OS X platform and how to stay safe.

Categories:

Tags:

(Read more...)



from An overview of malvertising on the Mac