Topic: process hollowing
-
MaaS Attack Chain Merges ClickFix, ErrTraffic, Cruciferra
A new malware-as-a-service campaign combines ClickFix social engineering, the ErrTraffic delivery service, and the Cruciferra loader to push malware while disabling endpoint defenses, as detailed by eSentire's Threat Response Unit. The attack chain starts on hijacked WordPress sites, uses Ethereu...
Read More » -
Fake AI Guides Spread AsyncRAT Malware via Dev Tools
Threat actors are distributing malware disguised as AI study guides and developer tools, targeting Windows users with a multi-stage attack that deploys the AsyncRAT trojan through trusted system tools to evade detection. The attack chain uses deceptive files like "AI-Ready PostgreSQL 18" and fake...
Read More » -
AI Chatbot Prompts Lead Users to Cryptojacking Malware Sites
Cybercriminals are using AI chatbot responses and poisoned search results to direct users to fake download sites for popular system utilities like CrystalDiskInfo and HWMonitor, as part of a cryptojacking campaign targeting high-performance GPUs. The attack chain involves DLL sideloading via mali...
Read More » -
HR and Recruiters Hit by Year-Long Malware Attack
A long-running malware campaign is specifically targeting HR and recruitment professionals to steal sensitive organizational data using sophisticated, stealthy techniques. The attack begins with a deceptive resume-themed file that triggers a multi-stage infection, employing tactics like DLL sidel...
Read More » -
Fake Windows BSOD Screens Deliver ClickFix Malware
A sophisticated phishing campaign targets the European hospitality industry by impersonating Booking.com, using a fake website and a fabricated Windows Blue Screen of Death error to trick users into manually installing malware. The attack deploys the DCRAT remote access trojan, which gains persis...
Read More » -
DeadLock Ransomware Evades Security with BYOVD Attack
The DeadLock ransomware campaign uses a BYOVD technique, exploiting a known vulnerability (CVE-2024-51324) in a Baidu Antivirus driver to disable security software and delete recovery options before deploying its payload. The ransomware itself, written in C++, uses process hollowing and a custom ...
Read More » -
Inside the PureRAT Attack: From Info Stealer to Full Control
A sophisticated cyberattack begins with phishing emails using sideloading techniques to deploy malware, escalating from credential theft to deploying the full-featured PureRAT remote access trojan for complete system control. The campaign employs multiple layers of obfuscation, including custom c...
Read More »