Threat actors now exploit the critical Apache Log4j vulnerability named Log4Shell to infect vulnerable devices with the notorious Dridex banking trojan or Meterpreter. . The Dridex malware is a banking trojan originally developed to steal online banking credentials from victims. However, over time, the malware has evolved to be a loader that downloads various modules that can be used to perform different malicious behavior, such as installing additional payloads, spreading to other devices, taking screenshots, and more. Dridex infections are also known to lead to ransomware attacks from operations believed to be linked to the Evil Corp hacking group. These ransomware infections include BitPaymer, DoppelPaymer, and possibly other limited-use ransomware variants. . The Emotet malware shifted from data exfiltration to deploying ransomware through Conti exploits, presenting significant dangers.. Malware Infection, Online Banking Security, Threat Exploitation, Apache Log4j. . Brittany Day
Researchers have uncovered over a dozen servers, unusually registered in the United States, which are hosting ten different malware families spread through phishing campaigns potentially tied to the Necurs bonnet. . On Thursday, researchers from Bromium said they have monitored scams connected to this infrastructure during the May 2018 to March 2019 time period. Five families of banking Trojans -- Dridex, Gootkit, IcedID, Nymaim, and Trickbot -- two ransomware variants, Gandcrab and Hermes, as well as three information stealers, Fareit, Neutrino, and Azorult, were all found on the servers. The link for this article located at ZDNet is no longer available. . Analysts track schemes linked to American networks dispersing over a dozen types of malicious software, among them fraud tools and encrypting viruses.. Malware Families, Phishing Campaigns, Banking Trojans, Ransomware Threats. . LinuxSecurity.com Team
A man credited with helping to create the infamous Gozi banking malware has pleaded guilty in a US court. Deniss Calovskis, 30, of Latvia was arrested in November 2012 and spent 10 months in the Baltic state's cooler before being extradited to the USA, where he's been behind bars ever since. . Last Friday, Calovskis appeared in the US District Court, pleaded guilty and pledged not to appeal against any sentence of less than two years, Reuters reported. "I knew what I was doing was against the law," Calovskis reportedly said in court. The link for this article located at The Register UK is no longer available. . Programmer Deniss Calovskis admitted guilt to charges regarding the development of the Gozi financial malware in a federal court in the United States.. Gozi Malware, Banking Trojan, Cybercrime Charges, Malware Creator, Security Threats. . Alex
Not long ago, criminals pushing the Dridex banking Trojan were using Microsoft Excel documents spiked with a malicious macro as a phishing lure to entice victims to load the malware onto their machines. . Even though macros are disabled by default inside most organizations, the persistent hackers are still at it, this time using XML files as a lure. The link for this article located at ThreatPost is no longer available. . Discover how the Dridex Trojan proliferates via XML documents embedded with macros, skillfully bypassing protective protocols while zeroing in on its intended targets.. Dridex Trojan, XML phishing, macro malware, banking security, cyber threat. . LinuxSecurity.com Team
Trend Micro researcher Kyle Wilhoit says the latest attacks on SCADA and industrial control networks are turning out to carry rather pedestrian banking Trojans, and have been on the rise since October 2014. . Talking to DarkReading, Wilhoit said rather than Stuxnet-style attacks, ne'er-do-wells are dropping banking Trojans into these networks disguised as updates to SCADA software. The link for this article located at The Register UK is no longer available. . A recent report from a Trend Micro expert highlights an alarming increase in banking Trojan incidents targeting industrial control systems, camouflaged as SCADA software updates.. Banking Trojan Attacks, SCADA Malware, Industrial Security, Cyber Threat Research. . LinuxSecurity.com Team
An Algerian national who is allegedly part of the cybercrime consortium behind a powerful hacking software known as SpyEye appeared in an Atlanta courtroom in the US after a three-year manhunt ended with his extradition from Thailand.. Hamza Bendelladj, known for years in underground computer forums simply as Bx1, was accused in a 23-count indictment of crimes including computer and bank fraud. The charges, unsealed yesterday, stem from his role in selling and supporting customised components for SpyEye, a banking Trojan that allows hackers to hijack victims' bank accounts as they logged on from their own computers. The link for this article located at Sydney Morning Herald is no longer available. . Egyptian coder Salah Omar, implicated in the Zeus malware contributing to identity theft, encounters American legal proceedings.. SpyEye Trojan, Computer Crime, Cybersecurity Threats, Banking Fraud. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.