Skip to main content

TrendAI™
Security Blog

TrendAI Security Blog

Ausgewählte Blogs

XCSSET Mac Malware: Infects Xcode Projects, Uses 0Days

Further investigation led us to a developer’s Xcode project that contained XCSSET source malware, which leads to a rabbit hole of malicious payloads. Most notable in our investigation is the discovery of two zero-day exploits.

Read Article
Malware
Bashlite Updated with Mining and Backdoor Commands

We uncovered an updated Bashlite malware designed to add infected internet-of-things devices to a distributed-denial-of-service (DDoS) botnet. Based on the Metasploit module it exploits, the malware targets devices with the WeMo UPnP API.

Read Article
IoT & smart devices Malware
Beauty Camera Apps Send Users Porn, Collects Pictures

We discovered several beauty camera apps (detected as AndroidOS_BadCamera.HRX) on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes. Some of these have been downloaded millions of times.

Read Article
Malware
Fake Banking App Found on Google Play Used in SMiShing

As users start to look for apps and other services from their banks, opportunities for scammers also increase. One recent example of this is the app Movil Secure, part of a SMiShing scheme targeting Spanish-speaking users.

Read Article
Google’s DoubleClick Abused to Deliver Miners

On January 24, 2018, we observed that the number of Coinhive web miner detections tripled due to a malvertising campaign. Attackers seem to have abused Google’s DoubleClick, which provides internet ad serving services, for traffic distribution.

Read Article
Cyber threats
Digmine Miner Spreading via Facebook Messenger

A new cryptocurrency-mining bot is spreading through Facebook Messenger. We named this Digmine based on the moniker (비트코인 채굴기 bot) it was referred to in a report of recent related incidents in South Korea.

Read Article
Cyber threats
Hacking Tools, Survey Scam Target Facebook Users
Read Article