Výsledky hledání

téma: malware× v celém archivu zrušit filtry

189 karet z 192 položek · strana 4 z 4 CZ · EN/orig

1

Fake Installers to Monero: A Multi-Tool Mining Operation

Introduction Elastic Security Labs has been tracking a financially motivated operation, designated REF1695, that has been active since at least late 2023. The operator deploys a combination of RATs, cryptominers, and custom XMRig loaders through fake installer packages. Across all observed campaigns, the infection chains share a consistent packing technique, overlapping C2 infrastructure, and common social engineering patterns, linking them to a single operator. Beyond cryptomining, the threat…

US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · Fake Installers to Monero: A Multi-Tool Mining Operation

1

Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

Key takeaways A South Asian financial institution was targeted with two custom malware components: a modular backdoor (BRUSHWORM) and a keylogger (BRUSHLOGGER) BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code The keylogger masquerades as libcurl via DLL side-loading, capturing system-wide keystrokes…

finance US

tg: incident tg: rozbor tp: malware tp: AI

· Elastic Security · Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

2

Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

Introduction During a recent investigation, we came across a data dump containing source code, compiled binaries, and deployment scripts for the kernel rootkit components of VoidLink, a cloud-native Linux malware framework first documented by Check Point Research in January 2026. Check Point's analysis revealed VoidLink to be a sophisticated, modular command-and-control framework written in Zig, featuring cloud-environment detection, a plugin ecosystem of over 30 modules, and multiple rootkit…

US

tg: rozbor tp: malware tp: AI tp: špionáž

· Elastic Security · Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

This blog discusses the steganography, cloud abuse, and email-based backdoors used against the Ukrainian defense supply chain in the latest Pawn Storm campaign that TrendAI™ Research observed and analyzed.

obrana veřejná správa JP

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: špionáž

· Trend Micro · Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

1

2

From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect

Introduction Elastic Security Labs is observing malicious campaigns delivering a multi-stage infection involving a previously undocumented loader. The infection begins when users are diverted to a Cloudflare Turnstile CAPTCHA page under the guise of a digital invitation. After the link is clicked, a VBScript file is downloaded to the machine. Upon execution, the script retrieves C# source code, which is then compiled and executed in memory using PowerShell. The final payload observed in these…

ConnectWise US

tg: varování tg: rozbor tp: malware tp: phishing

· Elastic Security · From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect

1

1