Mexican financial institutions are facing a new spear-phishing campaign employing a modified version of the AllaKore RAT, an open-source remote access trojan. The BlackBerry Research and Intelligence Team identified the campaign, attributing it to an unknown Latin America-based financially motivated threat actor that has been active since at least 2021. The attacks specifically target large companies with gross revenues exceeding $100 million in various sectors such as retail, agriculture, public sector, manufacturing, transportation, commercial services, capital goods, and banking. The infection chain initiates with a ZIP file distributed via phishing or drive-by compromise, containing an MSI installer file. This installer drops a .NET downloader confirming the Mexican geolocation of the victim and retrieving the modified AllaKore RAT. The trojan, first observed in 2015, is capable of keylogging, screen capture, file upload/download, and remote control. The threat actor has tailored the malware to support commands related to banking fraud, specifically targeting Mexican banks and crypto trading platforms. Additional functionalities include launching a reverse shell, extracting clipboard content, and fetching/ executing additional payloads. The campaign utilizes Mexico Starlink IPs, Spanish-language instructions, and lures referencing the Mexican Social Security Institute (IMSS), making them applicable only to larger companies reporting directly to IMSS. BlackBerry noted that this financially motivated threat actor has persistently targeted Mexican entities for over two years, demonstrating a sustained interest in financial gain through cyber activities. Meanwhile, in a separate development, IOActive identified vulnerabilities in Lamassu Douro bitcoin ATMs, allowing an attacker with physical access to take control and steal user assets.
Microsoft is working on a well-documented problem that makes the classic Outlook mail client crash when it launches for Microsoft 365 customers running Windows. The problem does no...
A newly described attack dubbed CometJacking abuses URL parameters to inject hidden instructions into Perplexity’s Comet AI browser, causing the agent to access and leak sensitiv...
Detour Dog is a long-running campaign that hacks websites and has turned into a system for spreading malware using DNS. At first, it quietly sent visitors to tech-support and ad-fr...