Výsledky hledání

téma: podvod× typ: rozbor× v celém archivu zrušit filtry

52 karet z 52 položek CZ · EN/orig

2

New Android malware uses AI to steal bank logins and PINs

Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script. The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan. It also abuses Android Debug Bridge (ADB), a legitimate tool…

Google finance US

tg: rozbor tg: propagace tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · New Android malware uses AI to steal bank logins and PINs

Fake parcel delivery messages steal your card and bank details

Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial…

doprava US

tg: varování tg: rozbor tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · Fake parcel delivery messages steal your card and bank details

1

T-Mobile rewards points expiry texts are a phishing scam

Since early May 2026, we’ve been monitoring a large phishing campaign based on T-Mobile rewards points. The messages falsely warn that a customer’s rewards points are about to expire. They aren’t legitimate account notices: They use urgency, invented point balances, and phishing links to push recipients into acting before they can verify the claim. A typical message says that a T-Mobile Rewards account holds 18,400 points, gives an imminent expiry date, and states that unused points will be…

T-Mobile telekomunikace US

tg: varování tg: rozbor tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · T-Mobile rewards points expiry texts are a phishing scam

1

AI helps scammers build convincing antivirus renewal pages

Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing…

Avast US

tg: rozbor tg: propagace tp: phishing tp: podvod tp: AI

· Malwarebytes Labs · AI helps scammers build convincing antivirus renewal pages

1

Search results are sending people to fake Bitrefill checkouts

Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency. The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what…

Bitrefill obchod US

tg: varování tg: rozbor tp: phishing tp: podvod

· Malwarebytes Labs · Search results are sending people to fake Bitrefill checkouts

2

Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket communications, multi-stage credential theft, AES-256-CTR implementation, infrastructure, and actionable indicators for defenders.

SG

tg: rozbor tp: phishing tp: podvod tp: identita

· Group-IB · Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Over 15 months and seven campaigns, they built a malicious browser extension that installs…

Google Microsoft finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

4

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal…

US

tg: rozbor tp: podvod tp: identita

· Rapid7 · The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Android malware creates a hidden copy of your banking app

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device. To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of…

finance US

tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod

· Malwarebytes Labs · Android malware creates a hidden copy of your banking app

3

Protecting organizations from AI-assisted executive impersonation and invoice fraud

In this article Attack chain overviewEmail DeliveryDomain registrationGenerative AI usageMitigation and protection guidanceMicrosoft Defender detectionsMicrosoft Security CopilotThreat intelligence reportsMITRE ATT&CK Techniques observedIndicators of compromise (IOC)Learn More Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive…

ServiceNow US

tg: varování tg: rozbor tp: phishing tp: podvod tp: AI

· Microsoft Security Blog · Protecting organizations from AI-assisted executive impersonation and invoice fraud

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod tp: identita

· Microsoft Security Blog · Detect and disrupt AI-themed attacks with Microsoft Defender

2

More than 100,000 fake stores are out to steal your card details

Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores. The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined. The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even…

obchod US

tg: varování tg: rozbor tp: phishing tp: podvod

· Malwarebytes Labs · More than 100,000 fake stores are out to steal your card details

2

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery…

Google Cloudflare NetSupport veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the…

Google Tampermonkey US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

2

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

This week on the Lock and Code podcast… Crooks are taking a holiday. They’re counting on you to fund it. For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate…

US

tg: rozbor tg: propagace tg: přehled tp: podvod tp: identita

· Malwarebytes Labs · Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Flirty OnlyFans promoters on X may be using AI to appear human

In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they promoted paid adult-content pages. At the time, one unanswered question was how much of those conversations was automated. Were people working from scripts behind the accounts? Were they conventional, rules-based chatbots following a limited decision tree? Or were they using generative AI to…

X OnlyFans US

tg: varování tg: rozbor tp: podvod tp: AI

· Malwarebytes Labs · Flirty OnlyFans promoters on X may be using AI to appear human

1

1

StreamRat Android malware spreads through Meta and TikTok ads

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections, but…

Meta TikTok US

tg: varování tg: rozbor tp: malware tp: podvod

· Malwarebytes Labs · StreamRat Android malware spreads through Meta and TikTok ads

3

Scammers are getting smarter about where they target you 

Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes from Malwarebytes’ own threat research systems and…

Google Microsoft Apple Amazon US

tg: rozbor tg: návod tg: propagace tp: phishing tp: podvod

· Malwarebytes Labs · Scammers are getting smarter about where they target you 

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Research by: Amit Yardeni Key Points A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. We dubbed this group Gambling Goblin: a Chinese-speaking cybercrime cluster connected to a previously documented group, Earth Berberoka, that targeted gambling sites across Asia. It marks a shift from Brazil’s usual home-grown banking-trojan threats to a…

Apache veřejná správa školství IL

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Check Point Research · Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months, with higher distribution volume, and has emerged as a formidable threat, featuring a comprehensive credential harvester, an embedded sandbox scoring system, and a Polygon blockchain-based dead drop for resilience. Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on…

US

tg: varování tg: rozbor tp: malware tp: podvod tp: identita

· Elastic Security · REVSTEALER ramps up: analysis of up-and-coming infostealer

2

Fake GTA 6 leaked copy drains your crypto wallet

We’ve seen scam sites built around Grand Theft Auto VI (GTA 6) targeting visitors in three different ways this year. In June, we looked at sites selling GTA 6 “early access” for hundreds of dollars in cryptocurrency. You paid, got nothing, and could not reverse the payment. In August, we found fake Extended Look and demo sites delivering an infostealer instead of a game. The site we examined this week looks like a GTA 6 fan countdown site but offers to sell a leaked copy of the game. It loads a…

US

tg: varování tg: rozbor tp: malware tp: podvod

· Malwarebytes Labs · Fake GTA 6 leaked copy drains your crypto wallet

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In…

finance obchod US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod tp: AI

· Mandiant / Google TI · Financially Motivated Threat Actor BREEZE COMET Targets Brazil

1

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Research by: hasherezade Key Points Since early 2025, Check Point Research has been tracking JSCeal, a sophisticated cryptocurrency-focused stealer with broader credential-theft, surveillance, and traffic-interception capabilities, delivered as compiled V8 bytecode (JSC files). The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers. Our goal was to recover the code to a…

IL

tg: rozbor tp: malware tp: podvod tp: identita

· Check Point Research · Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

1

1

SPOJENO PŘES CVE Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995)

CISA added CVE-2022-0995 to the Known Exploited Vulnerabilities catalog. Affected product: Linux Kernel. Remediation due date: 2026-09-09.

KEV ✓ EPSS 0.10 CVE-2022-0995 Linux Microsoft veřejná správa školství média US

tg: varování tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

· CISA KEV · Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995) · Cisco Talos · UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

1

1

ToxicPanda 2.0 can take over your Android phone and banking apps

Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account…

Google finance US

tg: rozbor tg: návod tg: propagace tp: malware tp: podvod tp: identita

· Malwarebytes Labs · ToxicPanda 2.0 can take over your Android phone and banking apps

1

UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques. The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis…

US

tg: varování tg: rozbor tp: malware tp: podvod tp: AI

· Cisco Talos · UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

3

41 deceptive download sites show a real link, then send you somewhere else

We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see…

Microsoft US

tg: varování tg: rozbor tp: podvod

· Malwarebytes Labs · 41 deceptive download sites show a real link, then send you somewhere else

Scammers are using fake crypto AML checkers to drain your wallet

Scammers are creating fake crypto wallet-checking sites that promise to tell you whether a wallet is linked to suspicious activity. Instead, they try to trick you into giving them access to your crypto. What real AML checking looks like AML stands for anti-money laundering. These are rules that require banks and other regulated businesses to screen customers for ties to crime. It’s designed to prevent cybercriminals from hiding or moving illegally obtained money. In the crypto world, this…

finance US

tg: varování tg: rozbor tp: phishing tp: podvod

· Malwarebytes Labs · Scammers are using fake crypto AML checkers to drain your wallet

Your polite reply to that text is worth $2 on the dark web 

Most wrong-number texts are harmless. Some are the first step in a carefully planned scam. By replying, you may be confirming that your number is active and that you’re willing to engage with strangers, making you a more valuable target for future fraud. Here’s why a polite response can be worth money to cybercriminals. The politeness trap Sunday night. You’re on the couch, half-watching Netflix, when your phone buzzes. “Hey! Are we still on for dinner tomorrow? Don’t forget the wine ” You…

US

tg: varování tg: rozbor tp: phishing tp: podvod

· Malwarebytes Labs · Your polite reply to that text is worth $2 on the dark web 

2

New Android malware lets criminals use your bank card in real time

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in…

Google finance US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Malwarebytes Labs · New Android malware lets criminals use your bank card in real time

Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live.…

Shopify PayPal Apple Klarna US

tg: varování tg: rozbor tp: phishing tp: podvod tp: identita

· Cisco Talos · Dissecting the JWR phishing framework

1

1

The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers treated the environment as a connected system, using existing permissions and relationships to expand their reach. Reconnaissance increasingly focuses on understanding access and capability rather than discovering vulnerable assets. AI is compressing the gap between discovery, decision-making, and execution for cloud attackers. The interval…

Amazon Web Services US

tg: incident tg: rozbor tg: propagace tp: podvod tp: AI tp: identita

· Qualys · The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

1

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” The WLDR agent is a sophisticated PowerShell-based C2 memory implant that…

US

tg: varování tg: rozbor tp: malware tp: podvod

· Cisco Talos · UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

2

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…

finance telekomunikace US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Elastic Security · ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…

finance telekomunikace US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Elastic Security · ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

1

1

The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament

With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.

SG

tg: varování tg: rozbor tp: phishing tp: podvod

· Group-IB · The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament

1

3

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

Executive Summary SentinelLABS has identified PCPJack, a credential theft framework that worms across exposed cloud infrastructure and removes artifacts associated with TeamPCP, a threat actor persona who claimed several high-profile supply chain intrusions throughout early 2026. The toolset harvests credentials from cloud, container, developer, productivity, and financial services, then exfiltrates the data through attacker-controlled infrastructure while attempting to spread to additional…

Docker Kubernetes Redis MongoDB US

tg: varování tg: rozbor tp: malware tp: podvod tp: identita

· SentinelLabs · PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Elastic Security Labs identified a new Brazilian banking trojan that we are tracking as TCLBANKER, a malware family we assess is a major update of the MAVERICK/SORVEPOTEL family. The campaign, tracked as REF3076, features a loader with robust anti-analysis capabilities that deploys two embedded .NET Reactor-protected modules: a full-featured banking trojan and a worm module for self-propagation. The banking trojan monitors the victim's browser address bar via UI Automation, targeting 59…

Logitech finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

1

1

Fake Installers to Monero: A Multi-Tool Mining Operation

Introduction Elastic Security Labs has been tracking a financially motivated operation, designated REF1695, that has been active since at least late 2023. The operator deploys a combination of RATs, cryptominers, and custom XMRig loaders through fake installer packages. Across all observed campaigns, the infection chains share a consistent packing technique, overlapping C2 infrastructure, and common social engineering patterns, linking them to a single operator. Beyond cryptomining, the threat…

US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · Fake Installers to Monero: A Multi-Tool Mining Operation

1