Topic: system persistence
-
Bank of America Phishing Scam Deploys Remote Access Malware
Phishing emails posing as Bank of America lure victims to fake login pages that steal credentials and trigger a malicious script installing ScreenConnect, a legitimate remote access tool abused for unauthorized control and persistence. The attack grants attackers full remote control, enabling dat...
Read More » -
ClickFix: The Silent Security Threat in Your Home
A new cyberattack called ClickFix is targeting both Mac and Windows users by bypassing standard security measures and spreading through deceptive emails, messages, or search results. The attack tricks users into copying and executing a single command in the terminal, which silently downloads malw...
Read More » -
Cyber-Espionage Attack Mimics Sandworm Hits Russian, Belarusian Forces
A sophisticated spear-phishing campaign targets Russian and Belarusian military personnel using weaponized documents disguised as legitimate military correspondence to deliver malware. The attack deploys a malicious LNK file that executes PowerShell scripts, establishes persistence, and sets up O...
Read More » -
New Phishing Attack Deploys RATs Using UpCrypter Evasion
A global phishing campaign uses personalized emails and fake websites to distribute malicious downloads, employing the UpCrypter loader to deploy remote access trojans for prolonged unauthorized access. The attack involves HTML attachments redirecting to deceptive sites, with variations like voic...
Read More » -
Critical Git RCE Flaw (CVE-2025-48384) Actively Exploited by Attackers
A critical Git vulnerability (CVE-2025-48384) allows arbitrary code execution via maliciously crafted submodules, affecting macOS and Linux systems. CISA has confirmed active exploitation and mandated federal agencies to patch by September 15, 2025, with fixed Git versions released on July 8, 202...
Read More »