« Reports in 2024 »

657 reports

2024-05-17
Rekt
#AlexLab
2024-05-21 • Securonix

CLOUD#REVERSER uses phishing-delivered ZIP archives and an executable disguised as an Excel file to install a multi-stage VBScript and PowerShell infection chain. The malware persists through scheduled tasks that mimic Google update jobs, repeatedly execu…

#Phishing #T1082 #T1059.003 #T1070.004 #T1041 #T1560 #T1555.003 #T1547.001 #T1059.001 #T1027.010 #CloudReverser
2024-05-20 • Vertex

Vertex demonstrated a Synapse investigation beginning with a suspicious SHA256 file and enriching it through VirusTotal, MalwareBazaar, and MITRE ATT&CK data. The workflow connected the sample to Konni-tagged files, Korean tax-themed HWP and LNK lures, tt…

#Konni #LNK
2024-05-17 • Quill Audits

The report analyzes the Radiant Capital exploit on Arbitrum, where a smart-contract rounding and token-quantity calculation flaw enabled theft of roughly $4.5 million in ETH. It records attacker, attack-contract, vulnerable-contract, and transaction ident…

#RadiantCapital
2024-05-17 • Rekt

AlexLab’s XLink bridge on BNB was exploited after a compromised private key let the attacker take over an ALEX liquidity-pool vault and make malicious proxy-contract upgrades. The incident drained about $4.3 million in assets, including roughly 13.7 milli…

#AlexLab
2024-05-14 • Rain

Rain disclosed and contained a security incident while stating that customer fiat and crypto assets remained fully accounted for and held one-to-one under custody. The update says Rain isolated the issue, added security controls, and covered potential los…

#News #Rain
2024-05-14 • Avast

Avast reported that Lazarus exploited CVE-2024-21338, an admin-to-kernel zero-day patched by Microsoft in February 2024, to load an updated FudModule data-only rootkit. The exploit replaced the group's earlier BYOVD approach with abuse of a built-in Windo…

#Trend #BYOVD #CVE-2024-21338