An Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report
Cyber Security Blogs Q2-2023 Ransomeware Report ATLANTA, July 20, 2023: Cyble, the Y Combinator-backed leader in AI-powered global cyber threat intelligence, today announced the release of its much-awaited Q2-2023 Ransomware Report, an exhaustive resource offering critical insights into the ever-evolving global ransomware landscape Within the 38-page report, organizations will gain valuable insights into critical aspects, including the
- Published in RSS blog posts
Kanti: A NIM-Based Ransomware Unleashed in the Wild
Cyber Security BlogsNew Ransomware Strain Sets Sights on Cryptocurrency Users New programming languages often have fewer security measures and less mature detection mechanisms than well-established ones. Threat Actors (TAs) often attempt to bypass traditional security defenses and avoid detection by using a less-known programming language. NIM, a programming language specifically created for efficient execution
- Published in RSS blog posts
Legion Stealer targeting PUBG players
Cyber Security BlogsStealer impersonating Solution File (.sln) via a fake GitHub repo GitHub is a web platform that facilitates version control and collaboration for software development projects. This enables users to store and manage their source code repositories, track code modifications, and collaborate with others on the same project. While GitHub serves as a hosting
- Published in RSS blog posts
Security Gaps in Green Energy Sector: Unveiling the Hidden Dangers of Public-Facing PV Measuring and Diagnostics Solutions
Cyber Security BlogsOver 130K PV Measuring and Diagnostics Solutions exposed over the Internet With its increasing prominence and global adoption, green energy has emerged as a potential target for attackers, posing concerns for both State and Private entities in the near future. With the increasing adoption of renewable energy sources such as solar, wind, and
- Published in RSS blog posts
LummaC Stealer Leveraging Amadey Bot to Deploy SectopRAT
Cyber Security BlogsKey Takeaways The blog delves into a new infection approach to disseminating the SectopRAT final payload. Providing insight into LummaC stealer and its method of procuring the Amadey bot malware. The Amadey bot replicates itself to ensure persistence, generating an LNK file within the startup folder directory. Upon being started, this LNK file
- Published in RSS blog posts
AgentTesla Malware Targets Users with Malicious Control Panel File
Cyber Security BlogsKey Takeaways The blog highlights a new infection chain for distributing AgenTesla RAT. It involves a spam email with a CPL file that, when executed, downloads a PowerShell script that injects AgentTesla malware in exe and MSbuild.exe. The PowerShell scripts use obfuscated binary strings to hide malicious code. For persistence, malicious VB Scripts
- Published in RSS blog posts
Utilization of Leaked Ransomware Builders in Tech-Related Scams
Cyber Security Blogs Key Takeaways This blog sheds light on a new Tech Scam wherein scammers employ deceptive tactics to lure users into paying for non-existent antivirus solutions. Uncovering Tech Scammers possible involvement in different ransomware attacks. The IP address of a domain used in this scam is associated with both the TORZON MARKETPLACE, a
- Published in RSS blog posts
STRRAT’s Latest Version Incorporates Dual Obfuscation Layers
Cyber Security Blogs Key Takeaways • The blog highlights a new infection technique for distributing STRRAT version 1.6. It involves a spam email with a PDF attachment that, when opened, downloads a zip file containing the malicious JavaScript, which drops STRRAT. • STRRAT version 1.6 employs two string obfuscation techniques: “Zelix KlassMaster (ZKM)”
- Published in RSS blog posts
Sophisticated SiMay RAT Spreads Via Telegram Phishing Site
Cyber Security Blogs Keylogger and Gh0st RAT Variant deployed to spy on Users Threat actors (TAs) have been relentlessly employing diverse techniques to propagate malware by leveraging counterfeit websites of renowned applications. Cyble Research and Intelligence Labs (CRIL) reported on a trojanized version of Telegram specifically aimed at Chinese users. Telegram is a
- Published in RSS blog posts
Sneaky XWorm Uses MultiStaged Attack
Cyber Security BlogsThreat Actors Leveraging WebDAV Servers for Covert Operations Threat Actors (TAs) frequently utilize multistage attacks to increase the likelihood of successfully delivering malicious payload by evading detection from antivirus products and creating a complex and intricate attack structure that poses challenges for analysis. The TAs commonly employ LOLBin (Living Off the Land
- Published in RSS blog posts










