Weekly Malware & Threats Roundup | 24 Feb - 02 Mar 2025
1ī¸âŖ đĄđŧđŋđđĩ đđŧđŋđ˛đŽđģ đđŽđ°đ¸đ˛đŋđ đđļđģđ¸đ˛đą đđŧ $đ.đą đđļđšđšđļđŧđģ đđđđļđ đđŋđđŊđđŧ đđ˛đļđđ
North Korea's Lazarus hacking group has been identified as responsible for the largest cryptocurrency heist in history, stealing over $1.5 billion from ByBit.
Source: https://www.bleepingcomputer.com/news/security/north-korean-hackers-linked-to-15-billion-bybit-crypto-heist/
2ī¸âŖ đđļđđŠđ˛đģđŧđē đđŽđēđŊđŽđļđ´đģ đđļđđđŋđļđ¯đđđ˛đ đ đŽđšđđŽđŋđ˛ đđļđŽ đđŽđ¸đ˛ đđļđđđđ¯ đĨđ˛đŊđŧđđļđđŧđŋđļđ˛đ
Attackers are using fake GitHub projects to distribute stealers, backdoors, and cryptocurrency wallet clippers, targeting developers globally.
Source: https://securelist.com/gitvenom-campaign/115694/
3ī¸âŖ đŽ,đąđŦđŦ+ đ§đŋđđ˛đđļđ´đĩđ.đđđ đđŋđļđđ˛đŋ đŠđŽđŋđļđŽđģđđ đđ
đŊđšđŧđļđđ˛đą đđŧ đđ˛đŊđšđŧđ đđļđąđąđ˛đģđđĩđŦđđ đĨđđ§
A large-scale campaign abuses a vulnerable Windows driver to evade EDR systems and deploy remote access trojans.
Source: https://research.checkpoint.com/2025/large-scale-exploitation-of-legacy-driver/
4ī¸âŖ đĄđ˛đ đ đŽđšđđŽđŋđ˛ đđŽđēđŊđŽđļđ´đģ đ¨đđ˛đ đđŋđŽđ°đ¸đ˛đą đĻđŧđŗđđđŽđŋđ˛ đđŧ đĻđŊđŋđ˛đŽđą đđđēđēđŽ đŽđģđą đđđĨ đĻđđ˛đŽđšđ˛đŋ
Cybercriminals are distributing malware via cracked software downloads, leveraging Dead Drop Resolver techniques to avoid detection.
Source: https://asec.ahnlab.com/en/86390/
5ī¸âŖ đđŋđŽđđđđŽđšđš đ đŽđšđđŽđŋđ˛ đđŋđŽđļđģđ đđŋđđŊđđŧ đĒđŽđšđšđ˛đđ đđļđŽ đđŽđ¸đ˛ đđŧđ¯ đđģđđ˛đŋđđļđ˛đđ
A Russian cybercrime group deceived Web3 job seekers into downloading malware through a fraudulent interview platform.
Source: https://www.bleepingcomputer.com/news/security/grasscall-malware-campaign-drains-crypto-wallets-via-fake-job-interviews/
Additional Cybersecurity News:
đĸ đŽđŦđŽđą đ¨đģđļđ đ°đŽ đđģđ°đļđąđ˛đģđ đĨđ˛đđŊđŧđģđđ˛ đĨđ˛đŊđŧđŋđ: đđđ¯đ˛đŋ đđđđŽđ°đ¸đ đĻđĩđļđŗđ đđŧ đđļđđŋđđŊđđļđŧđģ
86% of major cyber incidents in 2024 resulted in downtime or financial loss, with attackers increasingly focusing on sabotage and data exfiltration.
Source: https://www.paloaltonetworks.com/blog/2025/02/incident-response-report-attacks-shift-disruption/
đ đđĩđļđģđ˛đđ˛ đđđ¯đ˛đŋ đđđŊđļđŧđģđŽđ´đ˛ đđđēđŊđ đđąđŦ%, đđŋđŧđđąđĻđđŋđļđ¸đ˛ đĨđ˛đŊđŧđŋđđ
Chinese state-backed cyber espionage activities surged in 2024, targeting finance, media, and manufacturing sectors.
Source: https://www.crowdstrike.com/en-us/global-threat-report/
đ´ đ˛đ% đŧđŗ đđŽđ°đ¸đ˛đŋđ đ¨đđ˛ đĄđ˛đ đđ
đŊđšđŧđļđ đđŧđąđ˛ đĒđļđđĩđļđģ đ°đ´ đđŧđđŋđ đŧđŗ đđļđđ°đšđŧđđđŋđ˛
Cybercriminals are exploiting newly released vulnerabilities faster than ever, with ransomware attacks targeting healthcare at record levels.
Source: https://www.sonicwall.com/threat-report