WannaCry & The Reality Of Patching

Credit to Author: Mark Nunnikhoven (Vice President, Cloud Research)| Date: Mon, 15 May 2017 00:46:55 +0000

[Editors note: For the latest WannaCry information as it relates to Trend Micro products, please read this support article.]  The WannaCry ransomware variant of 12-May-2017 has been engineered to take advantage of the most common security challenges facing large organizations today. Starting with a basic phish, this variant uses a recent vulnerability (CVE-2017-0144/MS17-010) to spread…

Read more

WanaCrypt0r ransomware hits it big just before the weekend

Credit to Author: Pieter Arntz| Date: Fri, 12 May 2017 18:07:55 +0000

Reports of two massive ransomware attacks by a ransomware that Malwarebytes detects as Ransom.WanaCrypt0r. attacks in Europe are dominating the news.

Categories:

Tags:

(Read more…)

The post WanaCrypt0r ransomware hits it big just before the weekend appeared first on Malwarebytes Labs.

Read more

New ‘Jaff’ ransomware via Necurs asks for 2 BTC

Credit to Author: Jérôme Segura| Date: Thu, 11 May 2017 17:11:12 +0000

The dreaded Necurs botnet delivers a new ransomware with a high ransom ask in this newest spam campaign.

Categories:

Tags:

(Read more…)

The post New ‘Jaff’ ransomware via Necurs asks for 2 BTC appeared first on Malwarebytes Labs.

Read more

Pawn Storm – A Look Into this Cyberespionage Actor Group

Credit to Author: Jon Clay| Date: Mon, 08 May 2017 18:13:50 +0000

In April 2017 my monthly threat webinar focused on a cyberespionage group our Forward-Looking Threat Researcher, Feike Hacquebord, has been following for many years and recently published a report into the most recent two years of activities. In this post I want to focus on their tools and tactics versus who they target since this…

Read more

OAuth Phishing On The Rise

Credit to Author: Mark Nunnikhoven (Vice President, Cloud Research)| Date: Wed, 03 May 2017 22:59:29 +0000

Recently there was a significant volume of new phishing emails aimed at capturing access to Google accounts…specifically your email and contacts. You can read more about it at The Verge, Quartz, and Ars Technica. This phish is a great—evil !?!—example of a sophisticated attempt to gain access to a large number of users accounts. In…

Read more

Google Docs App spam goes phishing

Credit to Author: Christopher Boyd| Date: Wed, 03 May 2017 19:51:53 +0000

There’s a very clever phishing scam going around at the moment involving Google Docs App. Originally thought to be targeting journalists given the sheer number of them mentioning it on their Twitter feeds, it’s also been slinging its way across unrelated mailboxes – from orgs to schools/campuses.

Categories:

Tags:

(Read more…)

The post Google Docs App spam goes phishing appeared first on Malwarebytes Labs.

Read more

System optimizers turning to Tech Support Scams

Credit to Author: Pieter Arntz| Date: Thu, 27 Apr 2017 15:00:25 +0000

PUPs and more specifically system optimizers have been found turning to tech support scams to increase the amount of money they can take from their unsuspecting customers.

Categories:

Tags:

(Read more…)

The post System optimizers turning to Tech Support Scams appeared first on Malwarebytes Labs.

Read more

A story of fonts by the EITest HoeflerText campaign

Credit to Author: Jérôme Segura| Date: Wed, 26 Apr 2017 19:45:58 +0000

The HoeflerText campaign is known for a fake font download that delivers the Spora ransomware. But did you know it also uses special characters in the dropper’s file name?

Categories:

Tags:

(Read more…)

The post A story of fonts by the EITest HoeflerText campaign appeared first on Malwarebytes Labs.

Read more