A newly identified advanced threat group, referred to as Armored Likho (also known as Eagle Werewolf), has been conducting targeted phishing campaigns against government organizations and critical infrastructure, particularly within the electric power sector. Researchers have identified the group's operations in Russia, Brazil, and Kazakhstan, highlighting a mix of espionage-focused missions and profit-oriented cybercrime. The attackers rely heavily on carefully crafted spear-phishing emails containing malicious archive attachments that trick recipients into executing malware. The campaign primarily uses two infection methods. One involves self-extracting executable files created with the Nullsoft Scriptable Install System (NSIS), which display harmless-looking documents or surveys while secretly launching a concealed malware loader. The second method abuses Windows shortcut (LNK) files with hidden execution parameters that initiate obfuscated PowerShell commands. Both techniques ultimately download additional payloads from frequently changing GitHub repositories, allowing the attackers to update malware quickly and reduce the effectiveness of static detection methods. A key component of the campaign is BusySnake Stealer, a Python-based information stealer protected with PyArmor to make reverse engineering more difficult. The malware achieves persistence by creating scheduled tasks and scripts that allow it to execute automatically at regular intervals. It communicates continuously with a command-and-control (C2) server, waiting for instructions and enabling attackers to perform a wide range of malicious activities. Its capabilities include harvesting browser credentials and cookies, monitoring clipboard contents for sensitive data, collecting screenshots, searching for cryptocurrency wallet files, extracting Telegram session information, and scanning documents for potentially valuable keys or credentials. It also supports remote access features such as reverse SSH tunneling and manipulation of remote desktop software to capture user credentials. Researchers found evidence suggesting that artificial intelligence was used to develop parts of the malware's initial loader, enabling faster development and greater diversity among malware samples. Organizations can reduce the risk posed by this threat by strengthening email security, restricting execution of suspicious LNK files, monitoring Python runtime activity, detecting unusual scheduled tasks, and watching for unexpected downloads from GitHub repositories.
Russian state-sponsored cyber actors are actively targeting vulnerable and poorly secured network routers to gain unauthorized access to organizations, particularly those operating...
A recent wire-level analysis conducted on Grok Build CLI version reported that the tool automatically transmitted complete Git repositories, including unread files and commit histo...
A new software supply chain campaign has compromised several AsyncAPI npm packages to distribute a remote access trojan called Miasma v3. The affected packages include @asyncapi/ge...