← Back
MalwareThe Register·1 hour ago

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

23-year-old botnet down

Read full article at The Register

Related Articles

MalwareThe Hacker News·8 hours ago

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

A financially motivated threat actor tracked as Breeze Comet (previously UNC5669) has been targeting Brazilian financial services, retail, and e-commerce organizations since 2024 by exploiting payment systems and banking software to execute fraudulent transactions. According to Google's Threat Intelligence Group and Mandiant, the group specializes in manipulating payment infrastructure to conduct unauthorized transfers across Brazilian financial networks. This campaign represents a sustained effort against Brazil's critical financial ecosystem with a focus on direct financial fraud rather than data theft.

MalwareMalwarebytes Labs·9 hours ago

Fake GTA 6 leaked copy drains your crypto wallet

Cybercriminals are distributing a fraudulent GTA 6 leak that contains malware designed to drain cryptocurrency wallets, steal tokens, and pilfer NFTs from unsuspecting users seeking early access to the game. The scam exploits the high anticipation around the upcoming title to lure victims into downloading malicious files.

MalwareThe Hacker News·11 hours ago

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect

MalwareDark Reading·11 hours ago

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

The ClickFix campaign has compromised 31 organizations by leveraging the Polygon blockchain as an infrastructure tool, specifically using EtherHiding to dynamically update command-and-control servers. By abusing the blockchain as an attacker-controlled address book, the threat actors can maintain persistent communication channels that are difficult to disrupt through traditional takedown methods.