Agenda Ransomware Uses Rust to Target More Vital Industries

Agenda Ransomware Uses Rust to Target More Vital Industries

An emerging ransomware family, Agenda has recently been targeting critical sectors such as the healthcare and education industries. The threat actors behind this ransomware appear to be migrating their ransomware code to Rust as recent samples still lack some features seen in the original binaries written in the Golang variant of the ransomware. Rust language is becoming more popular among threat actors as it is more difficult to analyze and has a lower detection rate by antivirus engines.

Full article HERE

IoC can be downloaded HERE

Sophisticated DarkTortilla Malware Spreading Via Phishing Sites

Sophisticated DarkTortilla Malware Spreading Via Phishing Sites

Security researchers have identified a sophisticated campaign of DarkTortilla malware, which is spread via typosquatted phishing sites. DarkTortilla is a complex .NET-based malware that has been active since 2015. The malware is known to drop multiple stealers and Remote Access Trojans (RATs) such as AgentTesla, AsyncRAT, NanoCore, etc

Full article HERE

IOC can be download from HERE

Digital Security – How to take care of your digital life professional or private – Part I

Security start to take care of our personal digital security

This article wants to start a series of practical tips to reduce the risk of attacks.

Digital security is all that area in which we talk about personal safety.
Let’s remember that 91% of successful attacks in recent years have been thanks to phishing emails, therefore an attack on the person.
That same person who has a professional digital life, a private digital life and again: a real private and professional life (both employee and freelancer or entrepreneur).

It is logical to think that every computer security strategy must start by adopting the necessary measures to mitigate the risk that these “lives” could in some way be a risk to ourselves or to the profession we have chosen.

1) The first rule is: Take your own digital security as important and necessary, the famous mantra “whoever you want to come and attack me” is the stupidest thing you can say and think.
Thinking there are people out there trying to hack FBI or something you are wrong.
Most of the breaches that are exchanged on the net every second are 90% of people who say “who do you want to come and attack me”.
A joint account is useful for a thousand things, from committing serious crimes, misadvertising or simply hiding your tracks.

If someone uses your devices, your mailbox, etc., remember that they will come and ask you for explanations, which means proving your innocence despite having done nothing wrong!

2) Every device must be secured, there are many applications and tutorials on how to do it for every single existing device, so I think it’s worth using Google not only to search for: “big breasts free”
It is important to choose well, since cybercriminals can create applications hiding backdoors or something to steal your data (and here the big brands teach).

3) You must not think that someone spends huge budgets just to give you an email, an online space, etc.
Free always means allowing these “benefactors” to take our very useful data for them in terms of marketing and to better profile what to sell and much more.
That said, using a free email or a free service for our profession is questionable, do we really want to feed our customers’ data to third parties or people who trust us?

4) Just as you protect your home from ill-intentioned or intruders, you must take responsibility and the duty to do so in your digital life too, even more so on the latter!
The smartphone, the smart TV, the machine that yodels you, are all components of your digital life.

5) You are responsible for the most sensitive and at-risk people in your family.
Here we could talk for hours, we all have a duty to defend the people most at risk in our family entourage. Minors, for example, whether they are our children or sisters/brothers. If through us they hack into our home, steal information and use it for questionable purposes? What if we allow social media to be used without any safety for minors? Remember how many have committed suicide because of cyberbullying and such…

That’s all for this part, see you next time

Venom RAT expands its operations by adding a Stealer Module 

 RAT capable of stealing Credit Card Information

A RAT (Remote Access Trojan) is a tool used by Threat Actors (TAs) to gain full access and remote control of a victim’s machine, including mouse and keyboard control, file access, network resources access, etc.

Continue reading the orignal articles HERE

Ioc availabile here from Alienvault

venom rat

Mallox Ransomware showing signs of Increased Activity

Mallox Ransomware showing signs of Increased Activity

Ransomware potentially targeting organizations dealing in Critical Infrastructure

“TargetCompany” is a type of ransomware that was first identified in June 2021. The researchers named it TargetCompany ransomware because it adds the targeted company name as a file extension to the encrypted files. In September 2022, researchers identified a TargetCompany ransomware variant targeting Microsoft SQL servers and adding the “Fargo” extension to the encrypted files. TargetCompany ransomware is also known to add a “Mallox” extension after encrypting the files… continue on the original article on cyble website

  • IoC discovered by Alienvault downloadable on OTX
  • Download