Cyber Security

LookBack Malware

LookBack malware is a remote access Trojan written in C++ that relies on a proxy communication tool to relay data from the infected host to a command and control IP. When this function is executed, the Sodom Normal communications module begins running within Libcurl.dll. In addition to loading the communications module, the initial macro described above configures a persistence mechanism for this […]

LookBack Malware Read More »

GermanWiper

For the past week, a new ransomware strain has been wreaking havoc across Germany. Named GermanWiper, this ransomware doesn’t encrypt files but instead, it rewrites its content with zeroes, permanently destroying users’ data. According to German security researcher Marius Genheimer and CERT-Bund, Germany’s Computer Emergency Response Team, the GermanWiper ransomware is currently being distributed via

GermanWiper Read More »

Android Ransomware

A new ransomware family targeting Android devices spreads to other victims by sending text messages containing malicious links to the entire contact list found on already infected targets. The malware dubbed Android/Filecoder.C (FileCoder) by the ESET research team which discovered it is currently targeting devices running Android 5.1 or later.”Due to narrow targeting and flaws in both execution

Android Ransomware Read More »

Chinese hackers launching zegost malware to attack Government Networks

The malware developed to steal the targeted victim’s information that resides in the compromised network with the ability to leverage multiple exploits. Researchers believe that the malware only focuses on the Chinese government network, but it was unclear why threat actors targeting only government agencies. Most of the exploits are often used by Italian offensive

Chinese hackers launching zegost malware to attack Government Networks Read More »