Connect with us

Security

Cyber Threats: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps and More Security Stories

Published

on

Instead, it proceeded to redirect victims to a clone of their financial institution’s website, which further engaged them in a series of fraudulent transactions,” ZeroBEC said. “The attacker then proceeded to log into the victim’s account on a legitimate banking platform, initiate money transfers, and confirm the transactions with the victim’s phone.”

This model is believed to be part of a broader campaign that involves a series of phishing kits, including one that targets a prominent financial institution in Europe. “The kit, dubbed ‘BlueKit,’ is a sophisticated credential-stealing tool that leverages a combination of legitimate and malicious code to exfiltrate login credentials from users who fall for the scam,” ZeroBEC added.

into valid HTML code. “Following a BlueKit browser-in-the-middle flow, targeted individuals were transitioned into a counterfeit document-viewer process that distributed a genuine ScreenConnect client set up for use by an attacker on a ScreenConnect cloud instance. The service is priced at $250 for seven days, $480 for 14 days, and $940 for 30 days, positioning it as one of the more expensive options in the current PhaaS market compared to Tycoon 2FA, Greatness, and Forg365, which cost around $350, $289, and $400 per month, respectively.”

  • New IoT Botnet Targets MS-SQL

    Researchers have uncovered a new Internet of Things (IoT) botnet dubbed Dark Nexus that targets systems running Microsoft SQL Server (MS-SQL) databases. The botnet, first observed in December 2021, uses various attack vectors to compromise systems and recruit them into the botnet. It leverages a modular design, allowing operators to extend its capabilities by adding new plugins and updates. Dark Nexus has been linked to previous IoT botnets like Qbot and Mirai, with some code overlaps suggesting potential connections to these threats.

    See also  The Future of Cyber Defense: Insider Risk in the New Age

  • The Evolution of Delivery Methods in Malicious Scripts

    In the realm of cybersecurity, the delivery method of malicious scripts can vary significantly. Some observed examples involve the use of tools like curl or MSHTA to access additional content, while others utilize msiexec to install payloads from attacker-controlled servers. These scripts serve as a gateway for installing ScreenConnect, which creates an additional remote access point on compromised endpoints.

    ClickFix Expands to Multiple Platforms

    A new ransomware-as-a-service (RaaS) operation known as CRPx0, delivered through ClickFix, has emerged in the cybersecurity landscape. This operation employs tactics such as using Windows and macOS update prompts and reCAPTCHA checks to deceive victims into executing malicious commands. On Windows systems, it initiates a complex DLL chain, while on macOS, it directly downloads a Python payload. The final outcome is a cross-platform Python ransomware that exfiltrates data before encryption, utilizes AES-128-CBC for file encryption, employs an embedded RSA-4096 public key for key wrapping, attempts lateral movement, and demands Bitcoin or Monero payments within 48 hours through ransom notes. The RaaS program was first detected on June 7, 2026, and is currently being promoted on a clearnet site (“crpx0[.]su/v3.txt”) for managing compromised machines, extracting files and credentials, monitoring stolen cryptocurrency assets, executing remote commands, and manually launching ransomware.

    Enhancing Recovery and Security Measures

    When it comes to recovering from a security breach, changing passwords is essential but may not be sufficient to close all potential access points. Attackers could still exploit vulnerabilities like unauthorized app approvals or active remote sessions to gain entry without the need for passwords. It is crucial to end open sessions, revoke unknown app access, and inspect remote tools for any signs of compromise. While improved security settings are gradually becoming standard practice, vulnerabilities stemming from outdated account links, weak authentication methods, and trusted yet exploitable software still pose risks. To stay protected, it is advisable to review existing access permissions before granting new ones.

    See also  Critical Vulnerability Exposed: Oracle EBS Targeted in Recent Cyber Attacks by Cl0p Hackers

    Trending