BadRabbit: a closer look at the new version of Petya/NotPetya

Credit to Author: Malwarebytes Labs| Date: Tue, 24 Oct 2017 23:08:18 +0000

BadRabbit, a new version of NotPetya, also has an infector allowing for lateral movements. However, unlike NotPetya, it does not use EternalBlue and uses a website to drop its payload. We take a closer look at this new ransomware variant.

Categories:

Tags:

(Read more…)

The post BadRabbit: a closer look at the new version of Petya/NotPetya appeared first on Malwarebytes Labs.

Read more

Magniber ransomware: exclusively for South Koreans

Credit to Author: hasherezade| Date: Thu, 19 Oct 2017 00:29:23 +0000

A few days ago, Magnitude EK resurfaced, this time with a new payload that targets only the country of South Korea. It’s called Magniber ransomware.

Categories:

Tags:

(Read more…)

The post Magniber ransomware: exclusively for South Koreans appeared first on Malwarebytes Labs.

Read more

Old MS Office feature weaponized in malspam attacks

Credit to Author: Jérôme Segura| Date: Tue, 17 Oct 2017 15:00:16 +0000

An old Microsoft Office feature has been brought back to the forefront as way to distribute malware without relying on macros or exploits.

Categories:

Tags:

(Read more…)

The post Old MS Office feature weaponized in malspam attacks appeared first on Malwarebytes Labs.

Read more

Malvertising on Equifax, TransUnion tied to third party script (updated)

Credit to Author: Jérôme Segura| Date: Thu, 12 Oct 2017 21:42:28 +0000

We take a look at the the recent malvertising incident that happened on Equifax’s site and show how it also affected TransUnion.

Categories:

Tags:

(Read more…)

The post Malvertising on Equifax, TransUnion tied to third party script (updated) appeared first on Malwarebytes Labs.

Read more

Decoy Microsoft Word document delivers malware through a RAT

Credit to Author: Jérôme Segura| Date: Fri, 13 Oct 2017 15:00:41 +0000

A Remote Administration Tool (RAT) is delivered via an unusual route: a benign-looking Microsoft Word document with an ulterior motive.

Categories:

Tags:

(Read more…)

The post Decoy Microsoft Word document delivers malware through a RAT appeared first on Malwarebytes Labs.

Read more

Malvertising on Equifax, TransUnion tied to third party script

Credit to Author: Jérôme Segura| Date: Thu, 12 Oct 2017 21:42:28 +0000

Equifax’s website is once again infected, this time with malvertising that redirects to a fake Flash player. Further investigation reveals TransUnion was also targeted.

Categories:

Tags:

(Read more…)

The post Malvertising on Equifax, TransUnion tied to third party script appeared first on Malwarebytes Labs.

Read more

Malvertising on Equifax, TransUnion tied to 3rd party library

Credit to Author: Jérôme Segura| Date: Thu, 12 Oct 2017 21:42:28 +0000

Equifax’s website is once again infected, this time with malvertising that redirects to a fake Flash player. Further investigation reveals TransUnion was also targeted.

Categories:

Tags:

(Read more…)

The post Malvertising on Equifax, TransUnion tied to 3rd party library appeared first on Malwarebytes Labs.

Read more

Equifax, TransUnion websites push fake Flash Player in malvertising campaign

Credit to Author: Jérôme Segura| Date: Thu, 12 Oct 2017 21:42:28 +0000

Equifax’s website is once again infected, this time with malvertising that redirects to a fake Flash player. Further investigation reveals TransUnion was also targeted.

Categories:

Tags:

(Read more…)

The post Equifax, TransUnion websites push fake Flash Player in malvertising campaign appeared first on Malwarebytes Labs.

Read more