Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
Gigabud 뱅킹 트로이목마가 안드로이드 작업 프로file을 생성하여 은행 앱 악성코드 검사를 우회합니다.
Gigabud banking trojan creates an Android work profile to bypass banking app malware checks.
AI가 선별한 아티클
Gigabud 뱅킹 트로이목마가 안드로이드 작업 프로file을 생성하여 은행 앱 악성코드 검사를 우회합니다.
Gigabud banking trojan creates an Android work profile to bypass banking app malware checks.
Google Ads에 광고를 게재한 개발자가 계정 정지에 처했다.
A developer faced account suspension on Google Ads for promoting software.
구글 광고를 통해 악성 소프트웨어를 광고하는 방법에 대한 기사
An article about advertising malicious software on Google Ads.
F5 BIG-IP APM 기기에서 PHP 웹 셸이 메모리에 주입되어 디스크 스캔을 회피하는 악성 코드가 발견됨.
Malware on F5 BIG-IP APM injects a PHP web shell into memory, evading disk scans.
BengalSEO 캠페인이 Bing 검색 결과를 오염시켜 악성코드와 기술 지원 사기를 유도하고 있다.
BengalSEO campaign poisons Bing search results leading to malware and tech support scams.
악성 VBScript를 새로운 시스템에 배포하는 ScreenConnect 악성 활동에 대한 연구 결과.
Details on worm-like activity using ScreenConnect to spread malicious VBScript payload to new systems.
JSCeal 악성코드는 세션 쿠키 도용으로 구글 인증을 우회할 수 있는 능력을 지닌다.
JSCeal malware can bypass Google authentication using stolen session cookies.
REVSTEALER와 연결된 네 가지 모듈이 윈도우 업데이트와 디펜더를 비활성화합니다.
Four modules linked to REVSTEALER disable Windows Update and Defender.
BraZetsu 악성코드는 감염된 윈도우 시스템을 범죄 시장의 재고로 전환합니다.
BraZetsu malware turns compromised Windows systems into inventory for criminal marketplaces.
공격자들이 신뢰받는 Node.js 런타임을 악성 코드 전파 도구로 활용하고 있다.
Attackers are using the trusted Node.js runtime as a tool for malware delivery.
가짜 소프트웨어 설치 프로그램이 윈도우 업데이트를 비활성화하고 Microsoft Defender를 약화시키고 있다.
Fake software installers disable Windows Update and weaken Microsoft Defender.
러시아 해커가 엑셀 악성코드로 8만 명 감염한 혐의로 기소됐다.
A Russian hacker faces charges for infecting 80,000 users with malware via Excel attachments.
위협 행위자들이 더 나은 공격을 원하지 않고 반복 가능한 공격을 원한다는 내용.
Threat actors prefer repeatable attacks over better ones, exemplified by the ClickFix technique.
러시아 연관 사이버 범죄 집단이 AI 분석 방해를 위해 새로운 기법을 사용하고 있음.
Russia-aligned threat actor uses a new technique to disrupt AI analysis.
ValleyRAT 백도어가 인증된 애드웨어에 숨겨져 배포되고 있다.
ValleyRAT backdoor is being distributed hidden in signed adware.
TerminalFix가 Cloudflare CAPTCHA를 이용해 악성 명령어를 실행하도록 유도하는 기법을 설명합니다.
TerminalFix uses fake Cloudflare CAPTCHAs to trick users into running malicious commands.
구글 크롬과 엣지 확장 중 암호화폐를 훔치는 악성 코드 발견.
Wallet-stealing malware found in 19 Chrome and Edge extensions.
IoT 봇넷과 다양한 사이버 위협에 대한 최신 소식.
Latest news on IoT botnets and various cyber threats.
캄보디아를 겨냥한 Spark RAT 리모트 액세스 트로잔이 보안 도구를 비활성화하는 캠페인에 사용되고 있다.
Spark RAT targets individuals in Cambodia, using diverse lures to disable security tools.
GoCaracal 악성코드는 이더리움 스마트 계약을 사용하여 C2 주소를 가져옵니다.
GoCaracal malware uses Ethereum smart contracts to retrieve C2 addresses.
이스라엘 혁명수비대와 연관된 해킹 그룹의 새로운 악성코드 발견.
New malware linked to Iranian hacking group Nimbus Manticore discovered.
SLEEPWALKER라는 새로운 백도어가 특정 패킷을 대기하며 독자적인 바이트코드를 실행합니다.
A new backdoor named SLEEPWALKER waits for a specific packet and then executes its own bytecode.
NVIDIA NemoClaw의 취약점이 발견되어 악성 웹페이지가 AI 모델을 조작할 수 있는 가능성이 보고되었다.
A vulnerability in NVIDIA NemoClaw allows a malicious webpage to take control of local AI models.
24개의 npm 패키지가 가짜 CAPTCHA 페이지를 호스팅하기 위해 악용되고 있다.
24 npm packages are abused to host fake CAPTCHA pages for phishing.
Fake Minecraft 클라이언트를 통해 유포되는 Weedhack 악성코드에 대한 보안 연구 결과.
Weedhack malware spreads to gamers via fake Minecraft clients and SEO poisoning, researchers found.
WordlistLoader와 SynkLoader라는 두 종류의 새로운 맬웨어가 발견되었습니다.
Two new malware families, WordlistLoader and SynkLoader, have been discovered.
Operation QUICSILVER은 미얀마 정부 및 IT를 타겟으로 하는 사이버 스파이 작전이다.
Operation QUICSILVER is a cyber espionage campaign targeting the Myanmar government and IT.
사이버 보안 연구자들이 악성 npm 패키지를 발견해 AI 기반 리눅스 백도어를 배포하고 있음을 확인했습니다.
Cybersecurity researchers have discovered malicious npm packages delivering an AI-based Linux backdoor, RedC2 4.0.
안드로이드 차량 시스템을 겨냥한 새로운 악성코드가 발견됐다.
A new malware targeting Android car systems has been discovered.
rust 크레이트 arrayref가 원격 페이로드를 실행하는 사례 발생.
The rust crate arrayref executed a remote payload during the build process.