SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
20 articles
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,”...
I have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much.
SparkKitty is a cross‑platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrati...
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing ki...
Defined as the practice of protecting software applications from threats throughout their lifecycle
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptom...
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attack...
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing...
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, impro...
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.
There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an ac...
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditi...
A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of t...
A large-scale supply chain attack has flooded RubyGems with 136 trojanized packages that deploy an XMRig Monero miner and self-propagate via SSH, underscorin...
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major suppl...
A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to...
A banking Trojan known as Lampion, believed to have originated in Brazil, is still actively used in ongoing attacks targeting Portuguese organizations.
Understanding what defines a nation-state actor — and what does not — changes how defenders evaluate threat intelligence relevance