UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
Russian state-sponsored threat actors from the UAC-0145 sub-cluster, linked to Sandworm and GRU, are using fake CAPTCHA checks on compromised websites to…
Ethereum is a blockchain platform used in the EtherHiding technique to retrieve domain names from smart contracts for malicious CAPTCHA injection.
ACR Stealer, an infostealer active since 2024, is targeting enterprise networks by stealing saved browser passwords, live session tokens, PDFs, Microsoft 365…
Cybersecurity researchers have flagged an active browser extension campaign designed to steal cryptocurrency by stealthily replacing wallet addresses during transactions. The cryptocurrency…
Silent Swap is a cryptocurrency clipper campaign identified by McAfee Labs that uses unsigned installers to deploy a malicious Chromium extension masquerading…
HellsUchecker is a backdoor delivered via EtherHiding and ClickFix campaigns, capable of executing files retrieved from C2 and reporting results back.