Threat actors have been leveraging polyglot and malicious Java archive files to distribute the StrRAT and Ratty remote access trojans to evade detection by security solutions, The Hacker News reports. . Deep Instinct researchers discovered that the StrRAT payload has been deployed in a campaign leveraging both JAR and MSI file formats, indicating potential execution via Windows and Java Runtime Environments. Meanwhile, a separate campaign involved the deployment of StrRAT and Ratty using the CAB and JAR polyglots, with URL shortening services rebrand.ly and cutt.ly leveraged to spread the artifacts, according to the report. . Cyber analysts from Deep Instinct focus on StrRAT and Ratty's innovative distribution strategies utilizing polyglots to evade detection by security solutions.. StrRAT Techniques, Polyglot Threats, Remote Access Trojans, Malware Distribution. . LinuxSecurity.com Team
The bane of the computer security world is how long it takes to recognize and respond to new attack paradigms. Name a major threat -- the boot virus, macro virus, email attachment, or Web JavaScript redirect -- and it seems to take years to respond adequately.. So here's an early warning: Waterholes should be on your radar. The link for this article located at InfoWorld is no longer available. . Stay vigilant against evolving waterhole attacks as stealth tactics emerge—knowledge is your best defense.. Waterhole Attack, Cybersecurity Methods, Threat Awareness. . LinuxSecurity.com Team
Hackers seeking source code from Google, Adobe and dozens of other high-profile companies used unprecedented tactics that combined encryption, stealth programming and an unknown hole in Internet Explorer, according to new details released by the anti-virus firm McAfee.. The link for this article located at Wired is no longer available. . The link for this article located at Wired is no longer available.. hackers, seeking, source, google, adobe, dozens, other, high-profile, companies, unpre. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.