Keylogger masquerading as bank

Mar 28 2024

Gone Phishing Banner

Today's hottest cybersecurity news stories:

Today's hottest cybersecurity news stories:

  • 💻 Keylogger distributed as bank payment notice in phishing attack 🎣

  • 🤖 Ray AI flaw left unpatched is exploited for cryptocurrency mining ⛏️

  • 📱 Android users beware! Google Play apps make Androids = proxies 🎭

🚨 New Phishing Alert! Keylogger masquerading as bank payment notice 🏧

🚨 New Phishing Alert! Keylogger masquerading as bank payment notice 🏧

A cutting-edge phishing campaign has emerged, deploying a sophisticated loader malware to deliver the notorious Agent Tesla information stealer and keylogger. 😱💻

📧 Trustwave SpiderLabs uncovered this malicious operation on March 8, 2024, disguised as a bank payment notification email. Recipients are tricked into opening an archive file attachment containing a devious loader that unleashes Agent Tesla onto the victim's system. 🕵️‍♂️📤

💣 "This loader exhibits advanced evasion techniques, including obfuscation and polymorphic behaviour, to dodge detection," explained security researcher Bernard Bautista. "It even bypasses antivirus defences and leverages proxies to obscure traffic." 🛡️🕵️‍♂️

🔒 Once activated, the loader bypasses Windows Antimalware Scan Interface (AMSI) to execute Agent Tesla in memory, enabling cybercriminals to covertly siphon sensitive data via SMTP from a compromised email account linked to a legitimate Turkish security system supplier. 📧🔓

🌐 This sophisticated attack not only evades detection but also provides an added layer of anonymity, making it challenging to trace back to the perpetrators. "[The loader] marks a notable evolution in the deployment tactics of Agent Tesla," noted Bautista. 📈🕵️‍♂️

🚨 In parallel, cybersecurity firm BlueVoyant has uncovered another phishing campaign orchestrated by cybercrime group TA544, using PDFs disguised as legal invoices to distribute WikiLoader and establish connections with hacked WordPress sites for command-and-control (C2) purposes. 💼📄

💻 Moreover, the surge in Tycoon phishing kit activity highlights the ongoing sophistication of cyber threats. Targeting Microsoft 365 users with deceptive login pages, Tycoon employs intricate traffic filtering methods to bypass detection and steal credentials. 🎣🔐

🔍 Stay vigilant against these evolving cyber threats! Remember to scrutinise emails, avoid opening suspicious attachments, and keep your cybersecurity defences up-to-date. 💻🛡️

Raided 💀💀💀

🚨 Urgent Security Alert! All those afraid say Ray AI 🤖

Cybersecurity experts have uncovered a grave threat targeting the Anyscale Ray AI platform, leaving organisations vulnerable to malicious exploitation. 🛡️💻

Oligo Security researchers Avi Lumelsky, Guy Kaplan, and Gal Elbaz have disclosed an ongoing campaign dubbed ShadowRay, which has been active since September 2023. 😱🔒

This sophisticated attack leverages a critical vulnerability (CVE-2023-48022) in Ray's job submission API, allowing attackers to execute arbitrary code remotely without authentication. 🛠️🔓

Ray, a widely-used open-source AI compute framework trusted by major companies like OpenAI, Uber, Spotify, and Netflix, is now under siege, with threat actors infiltrating GPU clusters to mine cryptocurrencies and gain unauthorised access to sensitive credentials. 💰🔑

Despite the severity of the flaw, Anyscale has no immediate plans to address the issue, leaving countless organisations at risk of data breaches and system compromise. 😨🔍

The attackers behind ShadowRay have demonstrated a cunning ability to evade detection, utilising tools like Interactsh to maintain anonymity while exploiting compromised clusters for financial gain. 💼🕵️‍♂️

This alarming development underscores the urgent need for organisations to fortify their cybersecurity defences and remain vigilant against evolving threats in the AI landscape. 🌐🔒

Stay informed and take proactive measures to safeguard your systems against exploitation. Your security is paramount! 💻🛡️

🎣 Catch of the Day!! 🌊🐟🦞

Google don’t Play 😬😬😬

🚨 Critical Security Alert: Beware of Rogue VPN Apps on Google Play! 🔒

Attention Android users! Cybersecurity experts have uncovered a dangerous threat lurking within seemingly innocent free VPN apps on Google Play. 😱💻

Over 15 VPN applications have been identified as carriers of a malicious software development kit (SDK) that transforms Android devices into unwitting residential proxies. 🚫📱

These proxies reroute internet traffic through residential devices, making it appear legitimate and evading detection, but in reality, they're hijacking your device's bandwidth for illicit activities like cybercrime and shopping bot schemes. 🕵️‍♂️🔍

While residential proxies have legitimate uses, such as market research and ad verification, threat actors exploit them for nefarious purposes like ad fraud, spamming, and phishing, putting unsuspecting users at risk of legal trouble. ⚠️💸

The offending VPN apps, masquerading as tools for online privacy, include names like Lite VPN, Fast Fly VPN, and Oko VPN, among others. These apps, once installed, secretly deploy the malicious SDK to convert your device into a proxy server without your knowledge. 🕵️‍♂️🔓

The SDK, developed by LumiApps, has been utilised to orchestrate a sophisticated campaign dubbed ShadowRay, allowing attackers to compromise hundreds of Android devices and syphon sensitive credentials and data. 😨🔑

Despite efforts to address the issue, some of these apps have resurfaced on Google Play under different developer accounts, potentially exposing users to continued risks. 🔄📲

🛡️ Top Tips:

Update or Uninstall: If you've installed any of the listed apps, update to the latest version that does not use the malicious SDK. If no safe version exists, uninstall the app immediately.

Stay Informed: Be wary of free VPN apps and consider using paid services that prioritise user privacy and security.

Enable Play Protect: Google Play Protect can help detect and remove harmful apps from your device.

Your online safety is paramount. Don't let rogue apps compromise your security. Stay vigilant and take proactive measures to safeguard your digital life! 🔒🛡️

Let us know what you think!

Let us know what you think!

So long and thanks for reading all the phish!


Recent articles