Skip to main content

TrendAI™
Blog de Seguridad

Blog de Seguridad de TrendAI

Blogs destacados

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More
Malware

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

TrendAI™ Research tracked three campaigns that ship completely different decoy applications and unrelated payloads, all riding one shared toolkit. This analysis covers the full chain, from the pixel data that hides the first stage, through a flexible shared loader to deliver multiple payloads, revealing how adversaries are standardizing their delivery mechanisms.

Read article
New Golang Ransomware Agenda Customizes Attacks

A new piece of ransomware written in the Go language has been targeting healthcare and education enterprises in Asia and Africa. This ransomware is called Agenda and is customized per victim.

Read Article
Ransomware & extortion
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus

We investigate mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game Genshin Impact. The driver is currently being abused by a ransomware actor to kill antivirus processes and services for mass-deploying ransomware.

Read Article
Analyzing The ForcedEntry Zero-Click iPhone Exploit Used By Pegasus

Citizen Lab has released a report on a new iPhone threat dubbed ForcedEntry. This zero-click exploit seems to be able to circumvent Apple's BlastDoor security, and allow attackers access to a device without user interaction.

Read Article
Phishing & BEC
APT-C-36 Updates Its Spam Campaign Against South American Entities With Commodity RATs

We have continued tracking APT-C-36, also known as Blind Eagle, since our research on this threat actor in 2019. We share new findings of APT-C-36’s ongoing spam campaign targeting South American entities.

Read Article
Cyber threats
#SinFiltro: Exponiendo las Tácticas de los Hackers de Cuentas de Instagram

¿Qué tácticas utilizan los hackers de cuentas de Instagram? ¿Qué hacen estos ciberdelincuentes con las cuentas robadas? ¿Cómo pueden los usuarios proteger sus cuentas? Analizamos los incidentes de hackeo de cuentas de Instagram desde la perspectiva de un investigador de seguridad y compartimos recomendaciones para los usuarios de Instagram y otras plataformas de redes sociales.

Read Article
SHAREit Flaw Could Lead to Remote Code Execution

We discovered vulnerabilities in the SHAREit application. These vulnerabilities can be abused to leak a user’s sensitive data, execute arbitrary code, and possibly lead to remote code execution. The app has over 1 billion downloads.

Read Article
XCSSET Mac Malware: Infects Xcode Projects, Uses 0Days

Further investigation led us to a developer’s Xcode project that contained XCSSET source malware, which leads to a rabbit hole of malicious payloads. Most notable in our investigation is the discovery of two zero-day exploits.

Read Article
Malware
Bashlite actualizado con comandos de minería y puerta trasera

Descubrimos un malware Bashlite actualizado diseñado para agregar dispositivos de internet de las cosas infectados a una botnet de denegación de servicio distribuido (DDoS). Basado en el módulo Metasploit que explota, el malware apunta a dispositivos con la API UPnP de WeMo.

Read Article
IoT & smart devicesMalware
Beauty Camera Apps Send Users Porn, Collects Pictures

We discovered several beauty camera apps (detected as AndroidOS_BadCamera.HRX) on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes. Some of these have been downloaded millions of times.

Read Article
Malware
Aplicación bancaria falsa encontrada en Google Play utilizada en SMiShing

A medida que los usuarios comienzan a buscar aplicaciones y otros servicios de sus bancos, también aumentan las oportunidades para los estafadores. Un ejemplo reciente de esto es la aplicación Movil Secure, parte de un esquema de SMiShing dirigido a usuarios de habla hispana.

Read Article