Cyware Feed
russian-nodaria-apt-adds-advanced-information-stealing-functionality

Russian Nodaria APT Adds Advanced Information Stealing Functionality

Researchers from Broadcom Symantec took the wraps off of an information-stealing malware known as Graphiron. Russia-affiliated ATP group Nodaria is using it in operations against Ukraine. Written in the Go programming language, the malware enables operators to gather a variety of data from the infected systems, including screenshots, files, system information, and login passwords.

Cyware Feed
dota-2-under-attack:-threat-actors-exploit-a-chrome-flaw-to-infect-gamers

Dota 2 Under Attack: Threat Actors Exploit a Chrome Flaw to Infect Gamers

Security experts at Avast Threat Labs uncovered four malicious Dota 2 game mods that cyber adversaries are using to backdoor players’ systems. The game mods were named Overdog no annoying heroes (id 2776998052), Custom Hero Brawl (id 2780728794), and Overthrow RTZ Edition X10 XP (id 2780559339). These programs could be used for logging, creating coroutines, […]

Cyware Feed
remcos-rat-used-to-spy-on-ukrainian-government-–-says-cert-ua

Remcos RAT Used to Spy on Ukrainian Government – Says CERT-UA

An alert from the CERT-UA revealed that threat actors conducted a phishing campaign against Ukrainian government agencies to deploy the Remcos RAT on their computers. The email contained a file reminding recipients to pay for services availed from Ukrtelecom. This latest Remcos version leverages the Dynamic Imports technique to evade detection by static analysis tools.