Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Introduction
Kaspersky researchers have uncovered a new campaign by Mirage Kitten targeting aviation and financial technology organizations across the Middle East and Africa using previously undocumented malware families. The threat actor is deploying NodeRabbit, a Node.js-based malware, and PollCat, a JavaScript variant, marking an expansion of their known toolset against these critical sectors.
Read full article at Kaspersky Securelist ↗Introduction
A threat actor leveraged multiple infostealer malware variants to harvest session credentials and gain unauthorized access to Claude accounts across an unspecified number of Anthropic users. The campaign demonstrates the ongoing risk that infostealers pose to SaaS platform users, particularly when session tokens are compromised and can be weaponized for account takeover.
A newly identified campaign dubbed TerminalFix uses PowerShell as its primary weapon in multistage attacks targeting enterprises, following tactics similar to the ClickFix campaign. The attack chain includes the establishment of reverse tunnels that grant threat actors access into compromised organizational networks, enabling potential lateral movement and persistence.
ValleyRAT leverages legitimate-looking adware and DLL sideloading techniques to evade detection while enabling the Silver Fox threat actor to steal data and maintain control over compromised systems. By disguising itself within seemingly ordinary applications rather than relying solely on cracked software or fake updates, the malware demonstrates an evolving approach to persistence and evasion on infected machines.