GandCrab ransomware distributed by RIG and GrandSoft exploit kits

Credit to Author: Malwarebytes Labs| Date: Tue, 30 Jan 2018 23:43:52 +0000

Ransomware may have slowed its growth but is still a go-to payload for threat actors looking to monetize drive-by download attacks. The latest attempt: GandCrab ransomware.

Categories:

Tags:

(Read more…)

The post GandCrab ransomware distributed by RIG and GrandSoft exploit kits appeared first on Malwarebytes Labs.

Read more

New Chrome and Firefox extensions block their removal to hijack browsers

Credit to Author: Pieter Arntz| Date: Thu, 18 Jan 2018 16:00:00 +0000

Two new extensions in Firefox and Chrome force install then hide from the user. Learn how you can protect yourself against them and remove them manually.

Categories:

Tags:

(Read more…)

The post New Chrome and Firefox extensions block their removal to hijack browsers appeared first on Malwarebytes Labs.

Read more

A coin miner with a “Heaven’s Gate”

Credit to Author: hasherezade| Date: Wed, 17 Jan 2018 16:00:00 +0000

The Heaven’s Gate technique has been around since 2009. But now coin miners are using it to maximize their performance in the target architecture.

Categories:

Tags:

(Read more…)

The post A coin miner with a “Heaven’s Gate” appeared first on Malwarebytes Labs.

Read more

RIG exploit kit campaign gets deep into crypto craze

Credit to Author: Jérôme Segura| Date: Tue, 09 Jan 2018 17:11:16 +0000

We take a look at a prolific campaign that is focused on the distribution of coin miners via drive-by download attacks. We started to notice larger-than-usual payloads from the RIG exploit kit around November 2017, a trend that has continued more recently via a campaign dubbed Ngay.

Categories:

Tags:

(Read more…)

The post RIG exploit kit campaign gets deep into crypto craze appeared first on Malwarebytes Labs.

Read more

Napoleon: a new version of Blind ransomware

Credit to Author: Malwarebytes Labs| Date: Fri, 08 Dec 2017 17:00:15 +0000

The ransomware previously known as Blind has been spotted recently with a .napoleon extension and a bug fix that means files can no longer be decrypted by victims. In this post, we’ll analyze the sample for its structure, behavior, and distribution method.

Categories:

Tags:

(Read more…)

The post Napoleon: a new version of Blind ransomware appeared first on Malwarebytes Labs.

Read more

Interesting disguise employed by new Mac malware HiddenLotus

Credit to Author: Thomas Reed| Date: Fri, 08 Dec 2017 16:00:22 +0000

A new piece of Mac malware called HiddenLotus is using a clever new trick to fool users into opening it.

Categories:

Tags:

(Read more…)

The post Interesting disguise employed by new Mac malware HiddenLotus appeared first on Malwarebytes Labs.

Read more

Seamless campaign serves RIG EK via Punycode (updated)

Credit to Author: Jérôme Segura| Date: Mon, 04 Dec 2017 22:48:49 +0000

The most prolific gate to the RIG exploit kit is coming in a different flavor. The Seamless campaign is now using a domain name with foreign characters translated by Punycode.

Categories:

Tags:

(Read more…)

The post Seamless campaign serves RIG EK via Punycode (updated) appeared first on Malwarebytes Labs.

Read more

Seamless campaign serves RIG EK via Punycode

Credit to Author: Jérôme Segura| Date: Mon, 04 Dec 2017 22:48:49 +0000

The most prolific gate to the RIG exploit kit is coming in a different flavor. The Seamless campaign is now using a domain name with foreign characters translated by Punycode.

Categories:

Tags:

(Read more…)

The post Seamless campaign serves RIG EK via Punycode appeared first on Malwarebytes Labs.

Read more