Weekly Malware & Threats Roundup | 24 Feb - 02 Mar 2025
1๏ธโฃ ๐ก๐ผ๐ฟ๐๐ต ๐๐ผ๐ฟ๐ฒ๐ฎ๐ป ๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐ ๐๐ถ๐ป๐ธ๐ฒ๐ฑ ๐๐ผ $๐ญ.๐ฑ ๐๐ถ๐น๐น๐ถ๐ผ๐ป ๐๐๐๐ถ๐ ๐๐ฟ๐๐ฝ๐๐ผ ๐๐ฒ๐ถ๐๐
North Korea's Lazarus hacking group has been identified as responsible for the largest cryptocurrency heist in history, stealing over $1.5 billion from ByBit.
Source: https://www.bleepingcomputer.com/news/security/north-korean-hackers-linked-to-15-billion-bybit-crypto-heist/
2๏ธโฃ ๐๐ถ๐๐ฉ๐ฒ๐ป๐ผ๐บ ๐๐ฎ๐บ๐ฝ๐ฎ๐ถ๐ด๐ป ๐๐ถ๐๐๐ฟ๐ถ๐ฏ๐๐๐ฒ๐ ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ ๐๐ถ๐ฎ ๐๐ฎ๐ธ๐ฒ ๐๐ถ๐๐๐๐ฏ ๐ฅ๐ฒ๐ฝ๐ผ๐๐ถ๐๐ผ๐ฟ๐ถ๐ฒ๐
Attackers are using fake GitHub projects to distribute stealers, backdoors, and cryptocurrency wallet clippers, targeting developers globally.
Source: https://securelist.com/gitvenom-campaign/115694/
3๏ธโฃ ๐ฎ,๐ฑ๐ฌ๐ฌ+ ๐ง๐ฟ๐๐ฒ๐๐ถ๐ด๐ต๐.๐๐๐ ๐๐ฟ๐ถ๐๐ฒ๐ฟ ๐ฉ๐ฎ๐ฟ๐ถ๐ฎ๐ป๐๐ ๐๐
๐ฝ๐น๐ผ๐ถ๐๐ฒ๐ฑ ๐๐ผ ๐๐ฒ๐ฝ๐น๐ผ๐ ๐๐ถ๐ฑ๐ฑ๐ฒ๐ป๐๐ต๐ฌ๐๐ ๐ฅ๐๐ง
A large-scale campaign abuses a vulnerable Windows driver to evade EDR systems and deploy remote access trojans.
Source: https://research.checkpoint.com/2025/large-scale-exploitation-of-legacy-driver/
4๏ธโฃ ๐ก๐ฒ๐ ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ ๐๐ฎ๐บ๐ฝ๐ฎ๐ถ๐ด๐ป ๐จ๐๐ฒ๐ ๐๐ฟ๐ฎ๐ฐ๐ธ๐ฒ๐ฑ ๐ฆ๐ผ๐ณ๐๐๐ฎ๐ฟ๐ฒ ๐๐ผ ๐ฆ๐ฝ๐ฟ๐ฒ๐ฎ๐ฑ ๐๐๐บ๐บ๐ฎ ๐ฎ๐ป๐ฑ ๐๐๐ฅ ๐ฆ๐๐ฒ๐ฎ๐น๐ฒ๐ฟ
Cybercriminals are distributing malware via cracked software downloads, leveraging Dead Drop Resolver techniques to avoid detection.
Source: https://asec.ahnlab.com/en/86390/
5๏ธโฃ ๐๐ฟ๐ฎ๐๐๐๐ฎ๐น๐น ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ ๐๐ฟ๐ฎ๐ถ๐ป๐ ๐๐ฟ๐๐ฝ๐๐ผ ๐ช๐ฎ๐น๐น๐ฒ๐๐ ๐๐ถ๐ฎ ๐๐ฎ๐ธ๐ฒ ๐๐ผ๐ฏ ๐๐ป๐๐ฒ๐ฟ๐๐ถ๐ฒ๐๐
A Russian cybercrime group deceived Web3 job seekers into downloading malware through a fraudulent interview platform.
Source: https://www.bleepingcomputer.com/news/security/grasscall-malware-campaign-drains-crypto-wallets-via-fake-job-interviews/
Additional Cybersecurity News:
๐ข ๐ฎ๐ฌ๐ฎ๐ฑ ๐จ๐ป๐ถ๐ ๐ฐ๐ฎ ๐๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐ ๐ฅ๐ฒ๐๐ฝ๐ผ๐ป๐๐ฒ ๐ฅ๐ฒ๐ฝ๐ผ๐ฟ๐: ๐๐๐ฏ๐ฒ๐ฟ ๐๐๐๐ฎ๐ฐ๐ธ๐ ๐ฆ๐ต๐ถ๐ณ๐ ๐๐ผ ๐๐ถ๐๐ฟ๐๐ฝ๐๐ถ๐ผ๐ป
86% of major cyber incidents in 2024 resulted in downtime or financial loss, with attackers increasingly focusing on sabotage and data exfiltration.
Source: https://www.paloaltonetworks.com/blog/2025/02/incident-response-report-attacks-shift-disruption/
๐ ๐๐ต๐ถ๐ป๐ฒ๐๐ฒ ๐๐๐ฏ๐ฒ๐ฟ ๐๐๐ฝ๐ถ๐ผ๐ป๐ฎ๐ด๐ฒ ๐๐๐บ๐ฝ๐ ๐ญ๐ฑ๐ฌ%, ๐๐ฟ๐ผ๐๐ฑ๐ฆ๐๐ฟ๐ถ๐ธ๐ฒ ๐ฅ๐ฒ๐ฝ๐ผ๐ฟ๐๐
Chinese state-backed cyber espionage activities surged in 2024, targeting finance, media, and manufacturing sectors.
Source: https://www.crowdstrike.com/en-us/global-threat-report/
๐ด ๐ฒ๐ญ% ๐ผ๐ณ ๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ๐ ๐จ๐๐ฒ ๐ก๐ฒ๐ ๐๐
๐ฝ๐น๐ผ๐ถ๐ ๐๐ผ๐ฑ๐ฒ ๐ช๐ถ๐๐ต๐ถ๐ป ๐ฐ๐ด ๐๐ผ๐๐ฟ๐ ๐ผ๐ณ ๐๐ถ๐๐ฐ๐น๐ผ๐๐๐ฟ๐ฒ
Cybercriminals are exploiting newly released vulnerabilities faster than ever, with ransomware attacks targeting healthcare at record levels.
Source: https://www.sonicwall.com/threat-report