TrendAI™
Security Blog

Featured Blogs
The Boardroom Debate: How Cyber Risk Hits Your Bottom Line
You don’t need to be an expert to use cyber risk quantification. TrendAI™ automates data collection to deliver real-time financial risk insights and clear next steps for remediation.
TrendAI™ Brings OpenAI's GPT Cyber Models Into the Race to Shrink Exposure Time to Zero
OpenAI’s GPT cyber models help TrendAI™ close the exposure window, from vulnerability to fix, faster than ever.
ATF Reports Breach After Qilin Leak Site Appearance: Insights from TrendAI™
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has reportedly appeared on the Qilin ransomware group’s leak site. Explore how Qilin operates and what organizations can learn from its past tactics.
Search for research articles
Filter by:
Hacking Tools, Survey Scam Target Facebook Users
Digmine Miner Spreading via Facebook Messenger
A new cryptocurrency-mining bot is spreading through Facebook Messenger. We named this Digmine based on the moniker (비트코인 채굴기 bot) it was referred to in a report of recent related incidents in South Korea.
Google’s DoubleClick Abused to Deliver Miners
On January 24, 2018, we observed that the number of Coinhive web miner detections tripled due to a malvertising campaign. Attackers seem to have abused Google’s DoubleClick, which provides internet ad serving services, for traffic distribution.
New AndroRAT Exploits Allow for Permanent Rooting
A new variant of Android Remote Access Tool can inject root exploits to perform malicious tasks such as silent installation, shell command execution, WiFi password collection, and more. It targets CVE-2015-1805, a vulnerability disclosed in 2016.
Fake Banking App Found on Google Play Used in SMiShing
As users start to look for apps and other services from their banks, opportunities for scammers also increase. One recent example of this is the app Movil Secure, part of a SMiShing scheme targeting Spanish-speaking users.
Beauty Camera Apps Send Users Porn, Collects Pictures
We discovered several beauty camera apps (detected as AndroidOS_BadCamera.HRX) on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes. Some of these have been downloaded millions of times.
Bashlite Updated with Mining and Backdoor Commands
We uncovered an updated Bashlite malware designed to add infected internet-of-things devices to a distributed-denial-of-service (DDoS) botnet. Based on the Metasploit module it exploits, the malware targets devices with the WeMo UPnP API.
XCSSET Mac Malware: Infects Xcode Projects, Uses 0Days
Further investigation led us to a developer’s Xcode project that contained XCSSET source malware, which leads to a rabbit hole of malicious payloads. Most notable in our investigation is the discovery of two zero-day exploits.
SHAREit Flaw Could Lead to Remote Code Execution
We discovered vulnerabilities in the SHAREit application. These vulnerabilities can be abused to leak a user’s sensitive data, execute arbitrary code, and possibly lead to remote code execution. The app has over 1 billion downloads.
#NoFilter: Exposing the Tactics of Instagram Account Hackers
What tactics do Instagram account hackers use? What do these cybercriminals do with stolen accounts? How can users protect their accounts? We look into Instagram account hacking incidents from a security researcher’s perspective and share recommendations for users of Instagram and other social media platforms.