MalwareInfosecurity Magazine·1 week ago

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

The Lazarus threat group employed post-quantum cryptography in its key exchange mechanism while distributing a previously unknown Windows vulnerability, demonstrating sophisticated operational security practices. This approach suggests advanced threat actors are already integrating quantum-resistant encryption methods into their attack infrastructure ahead of mainstream adoption.

MalwareInfosecurity Magazine·1 week ago

Six npm Packages Read C2 Addresses From Ethereum Wallet

Six malicious npm packages were discovered exfiltrating command-and-control infrastructure addresses by querying an Ethereum wallet, demonstrating a novel evasion technique that leverages blockchain to host malware configuration. This approach obscures C2 locations within cryptocurrency transactions, making them harder to detect and block through traditional network monitoring methods.

MalwareKaspersky Securelist·1 week ago

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Kaspersky researchers have identified that the Head Mare APT group is exploiting unpatched vulnerabilities in TrueConf servers to distribute the PhantomCore and PhantomGraph backdoors to video conference participants. The attack leverages compromised TrueConf software installers to deliver these malicious payloads to target systems. This campaign highlights the risks posed by unpatched collaboration tools and their potential use as infection vectors by sophisticated threat actors.

MalwareUnit 42·1 week ago

Kimwolf v7: An Evolution of the Kimwolf Botnet

Kimwolf v7 represents an updated iteration of the Kimwolf botnet with enhanced capabilities targeting Android IoT devices, leveraging HTTP/2 DDoS fingerprinting for attacks. The malware employs Ethereum ENS for command-and-control resolution alongside Tor-based backup routing to maintain resilience against takedown efforts.

MalwareUnit 42·1 week ago

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Unit 42 has published an analysis of the Aeternum botnet loader, which uses Polygon blockchain smart contracts to establish decentralized command-and-control infrastructure and execute payloads. This approach represents an evolution in botnet evasion tactics, leveraging blockchain technology to distribute and maintain C2 operations outside traditional network chokepoints. The analysis examines how Aeternum's architecture enables resilient malware communications through on-chain smart contracts.

MalwareElastic Security Labs·2 weeks ago

Living off the coding agent: Two tales of tunnels and LaunchAgents

Elastic Security Labs documents a technique where coding agents create reverse tunnels and LaunchAgents to expose local admin applications to the internet, potentially providing remote access despite benign appearances. Security teams should treat this activity as high severity even when it resembles legitimate development operations rather than confirmed malware, as the outcome—exposing privileged services—represents significant risk regardless of intent.

MalwareMicrosoft Security Blog·2 weeks ago

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

A macOS ClickFix campaign has evolved its delivery method by concealing infostealer lures behind browser-fingerprinting checks, complicating detection efforts while simultaneously creating new forensic indicators for defenders to hunt on. This tactical shift reflects the threat actor's attempt to reduce exposure to security researchers and automated scanning while maintaining operational effectiveness. The change demonstrates how adversaries continuously refine evasion techniques in response to defensive capabilities.

MalwareKrebs on Security·3 weeks ago

Read This Before You Buy That TV Streaming Stick

Generic TV streaming sticks marketed with unlimited content for a one-time fee pose serious security risks beyond their known practice of renting out users' internet connections to third parties. Security researchers have discovered these devices actively spoof mobile phones to click ads on AI-generated websites, enabling fraud schemes targeting online merchants and advertising networks. The analysis reveals a coordinated operation that exploits both user devices and the broader digital advertising ecosystem.

MalwareKrebs on Security·1 month ago

FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI has seized hundreds of domains associated with NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies, following evidence linking the platform to the Popa botnet. The action was coordinated with industry partners and comes weeks after security researchers connected NetNut to Popa, which comprises at least two million compromised devices operated largely without victim consent.