SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraud operation tracked as REF6045 by Elastic Security Labs is targeting customers of Mexican banks, fintech platforms, payment processors,…
A new banking fraud operation tracked as REF6045 by Elastic Security Labs is targeting customers of Mexican banks, fintech platforms, payment processors,…
A previously undocumented threat actor, Armored Likho, has been attributed to cyber attacks targeting government agencies and the electric power sector across…
Unknown threat actors are leveraging the ScreenConnect remote access tool to deploy and execute AsyncRAT as part of a massive, multi-domain, multi-language…
Cybersecurity researchers have identified a new multi-stage malware delivery attack chain, dubbed VEIL#DROP, that leverages social engineering and Google's Blogger platform to…
Security researcher Bert-Jan Pals analyzed roughly 3,000 live ClickFix payloads and presented findings at OrangeCon in early June, publishing details on June…
Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services.…
PteroPaste is used by Gamaredon to weaponize USB drives and download additional PowerShell payloads via an encrypted channel.
PteroDee is a PowerShell tool used by Gamaredon to fetch and execute PowerShell payloads in memory.
PteroCache is a PowerShell tool used by Gamaredon to fetch and execute PowerShell payloads in memory.
PteroOdd is a PowerShell tool used by Gamaredon to fetch a single PowerShell payload using the Telegra.ph API, likely in collaboration with…