All posts tagged: Malware

Malicious Machine Learning Models Discovered on Hugging Face: Report

Malicious Machine Learning Models Discovered on Hugging Face: Report

Hugging Face, the artificial intelligence (AI) and machine learning (ML) hub, is said to contain malicious ML models. A cybersecurity research firm discovered two such models that contain code that can be used to package and distribute malware to those who download these files. As per the researchers, threat actors are using a hard-to-detect method, dubbed Pickle file serialisation, to insert malicious software. The researchers claimed to have reported the malicious ML models, and Hugging Face has removed them from the platform. Researchers Discover Malicious ML Models in Hugging Face ReversingLabs, a cybersecurity research firm, discovered the malicious ML models and detailed the new exploit being used by threat actors on Hugging Face. Notably, a large number of developers and companies host open-source AI models on the platform that can be downloaded and used by others. The firm discovered that the modus operandi of the exploit involves using Pickle file serialisation. For the unaware, ML models are stored in a variety of data serialisation formats, which can be shared and reused. Pickle is a Python …

New Chatbot for Malware Creation, Scams

New Chatbot for Malware Creation, Scams

Security researchers have discovered a new malicious chatbot advertised on cybercrime forums. GhostGPT generates malware, business email compromise scams, and more material for illegal activities. The chatbot likely uses a wrapper to connect to a jailbroken version of OpenAI’s ChatGPT or another large language model, the Abnormal Security experts suspect. Jailbroken chatbots have been instructed to ignore their safeguards to prove more useful to criminals. Must-read security coverage What is GhostGPT? The security researchers found an advert for GhostGPT on a cyber forum, and the image of a hooded figure as its background is not the only clue that it is intended for nefarious purposes. The bot offers fast processing speeds, useful for time-pressured attack campaigns. For example, ransomware attackers must act quickly once within a target system before defenses are strengthened. The official advertisement graphic for GhostGPT. Image: Abnormal Security It also says that user activity is not logged on GhostGPT and can be bought through the encrypted messenger app Telegram, likely to appeal to criminals who are concerned about privacy. The chatbot can …

Crypto Scammers Are Reportedly Posing as Job Recruiters to Circulate Malware 

Crypto Scammers Are Reportedly Posing as Job Recruiters to Circulate Malware 

Malicious crypto scammers have been found to be fishing for their victims posing as job recruiters online. Popular cyber investigator Taylor Monahan, who goes by the username @tayvano_, has posted an update to his 85,000 followers on X. As per the update, scammers are using recruiting platforms like LinkedIn to reach out to job seekers, asking them to fix issues with video-call software and subsequently injecting malicious malware to get access to the victims’ computers. Monahan works in the security division of crypto wallet MetaMask. The post, part of a thread on the threat, published by Monahan shared screenshots of the job listing circulated by the scammers. The post shows the fraudulent job opening of “Business Development Lead” at an entity named ‘Halliday’. To entice people to apply for this senior level position, the post boasts an annual salary bracket of $300,000 (roughly Rs. 2.56 lakh) to $350,000 (roughly Rs. 2.99 lakh) Once job seekers end up answering questions, the scammers ask them to record a video answering the last question. On clicking the ‘Request …

Law Enforcement Operation Targets Infostealers

Law Enforcement Operation Targets Infostealers

In a sweeping international effort, the U.S. Department of Justice, Federal Bureau of Investigation, and multiple global law enforcement agencies have exposed “Operation Magnus,” targeting two of the world’s most notorious information-stealing malware networks, RedLine Stealer and META. According to a press release published on Oct. 29, the operation led to the seizure of multiple servers, the unsealing of charges against a RedLine Stealer developer, and the arrest of two suspects in Belgium. RedLine and META information stealers RedLine Stealer and META are two distinct types of malware known as “information stealers,” or “infostealers,” designed to capture sensitive user data. The existence of RedLine Stealer was initially reported in 2020, while META first appeared in 2022. In an interview, a representative of the META malware revealed that its development initially relied on portions of RedLine Stealer’s source code, which had been acquired through a sale. Both malware are capable of stealing sensitive information from infected computers, such as: Usernames and passwords for online services, including e-mail boxes. Financial information such as credit card numbers or …

Get Advanced Ad Blocking and Superior Data Privacy Tools for

Get Advanced Ad Blocking and Superior Data Privacy Tools for $11

TL;DR: Get rid of annoying ads while protecting your privacy and confidential data with a lifetime subscription to AdGuard — new users can get it for just $11 at TechRepublic Academy. With so much business being transacted online and so much of our data being stored in the cloud, maintaining privacy and security are more important than ever. Plus, those irritating banner and popup ads can be more than just an annoyance. Some of them are actually just a front for seriously dangerous malware. Fortunately, you can now block ads and protect yourself online with a lifetime subscription to AdGuard. About AdGuard Not only will AdGuard banish annoying popups, video ads and banners with advanced ad blocking, but you will also get superior data privacy tools. The program is powered by advanced digital and computing technology to keep you shielded in cyberspace. AdGuard provides the ultimate privacy protection so you no longer need to fear the multitude of activity trackers and analyzers that are all over the web. Superior protection from malware is also included. …

Mobile, IoT, and OT Cyber Threats Surge in 2024

Mobile, IoT, and OT Cyber Threats Surge in 2024

A new report from cloud security company ZScaler sheds light on the growing mobile threats on Android operating systems, as well as IoT and OT devices threats. The findings come as more than 60% of the global Internet traffic is now generated by mobile devices and financially-oriented mobile threats have grown by 111% over the last year. A list of mobile malware threats ZScaler’s ThreatLabz witnessed a 29% rise in banking mobile malware over the previous year, with banking malware representing 20% of the total Android threat landscape. Most active banking malware families to date include: Vultur, which is primarily distributed through the Google Play Store. Hydra, distributed via phishing messages, websites, and malicious Google Play Store applications. Ermac, designed to steal financial data from banking and wallet apps. Anatsa, also known as TeaBot Coper, also known as Octo Nexus, primarily targets cryptocurrency accounts Most of these banking malware record keystrokes, hijack credentials, and intercept SMS messages in order to bypass Multi-Factor Authentication. SEE: How to Create an Effective Cybersecurity Awareness Program (TechRepublic Premium) Spyware …

15 Notable Cyberattacks and Data Breaches

Cyberattacks, whether accidental or purposeful, have been a threat long before the invention of the World Wide Web. These attacks aim to steal money, data, or resources — and sometimes serve as tools for gaining an edge over rival nations. Each incident is a stark reminder for businesses to fortify their digital defenses while also underscoring the crucial role of security teams that work tirelessly to identify and neutralize these threats. The following attacks had a significant impact on U.S. businesses, organizations, and individuals. Although each was eventually resolved, their consequences left lasting effects. 1988: The Morris Worm What happened? The Morris Worm’s code fundamentally shifted the nascent computing industry’s understanding of what was possible. In 1988, Cornell University graduate student Robert Tappan Morris unleashed the experimental worm from MIT’s networks, causing widespread disruption throughout about 6,000 of the then 60,000 internet-connected computers. Emails were blocked for days, and military computer systems experienced significant slowdowns. How was it resolved? Some facilities hit by the Morris Worm were forced to completely replace their computer systems, while …

Clipper Malware Poses Threat to Crypto Transactions: Binance Urges Users to Triple-Check Withdrawal Addresses

The crypto sector, that is presently valued at over $2 trillion (roughly Rs. 1,70,32,400 crore), is under constant threat from malicious actors who are increasing in number at a rapid pace globally. In a recent blog, Binance sounded an alert about the ‘clipper malware’, that is being used by cyber criminals to manipulate transaction details and steal tokens. This information from Binance comes just days after the FBI disclosed that crypto users lost over $5.6 billion (roughly Rs. 47,029 crore) last year through scams and frauds. Understanding Clipper Malware You may have noticed that when you copy something on your phone, the information is saved to the ‘clipboard’ for easy pasting into another app. This clipboard is precisely where cybercriminals are targeting with Clipper malware. Crypto wallet addresses are usually made of random combination of numbers and alphabets, that are hard to remember. People frequently copy wallet addresses during transactions. As per Binance, the clipper malware intercepts this data on the clipboard. “When a user copies and pastes a wallet address to transfer cryptocurrency, the …

VMWare ESXi Servers Targeted by New Ransomware Variant

A new double-extortion ransomware variant targets VMWare ESXi servers, security researchers have found. The group behind it, named Cicada3301, has been promoting its ransomware-as-a-service operation since June. Once an attacker has initial access to a corporate network, they can copy and encrypt its private data using the Cicada3301 ransomware. They can then withhold the decryption key and threaten to expose the data on Cicada3310’s dedicated leak site to force the victim into paying a ransom. Cicada3301’s leak site has listed at least 20 victims, predominantly in North America and England, according to Morphisec. Businesses were of all sizes and came from a number of industries, including manufacturing, healthcare, retail, and hospitality. Sweden-based security company Truesec first became aware of the group when it posted on the cybercrime forum RAMP on June 29 in an attempt to recruit some new affiliates. However, BleepingComputer says it has been made aware of Cicada attacks as early as June 6. How the ransomware works Attackers gain entry by brute-forcing or stealing valid credentials and logging in remotely via ScreenConnect …

Grandoreiro Malware Targets More Than 1,500 Banks in 60 Countries

A new report from IBM X-Force exposes changes in the Grandoreiro malware landscape. The banking trojan is now capable of targeting more than 1,500 global banks in more than 60 countries, and it has been updated with new features. Also, Grandoreiro’s targeting has become wider, as it initially only targeted Spanish-speaking countries, while recent attack campaigns targeted countries in Europe, Asia and Africa. In addition, the malware is now sending phishing emails directly from the victim’s Microsoft Outlook local client to recipients’ email addresses found in the local system. What is Grandoreiro? According to Interpol, the Grandoreiro banking trojan has been a major threat across Spanish-speaking countries since 2017. The malware’s main functionalities allow cybercriminals to control devices on the infected computer, enable keylogging, handle windows and processes, open a browser and execute JavaScript inside it, upload or download files, and send emails, in addition to its banking trojan capabilities. Analysis of different attack campaigns reveals that many operators are involved in Grandoreiro attacks, as stated by cybersecurity company Kaspersky, which wrote in July 2020, …