Remove 06
article thumbnail

The hidden C2: Lampion trojan release 212 is on the rise and using a C2 server for two years

Security Affairs

Lampion trojan is one of the most active banking trojans impacting Portuguese Internet end users since 2019. The malware TTP and their capabilities remain the same observed in 2019 , but the trojan loader – the VBS files – propagated along with the new campaign has significant differences. FUD capabilities of the Lampions’ VBS loader.

article thumbnail

Lazarus BTC Changer. Back in action with JS sniffers redesigned to steal crypto

Security Affairs

In July 2020, Sansec published an article about the attacks on US and European online shops with the use of JavaScript sniffers (JS-sniffers). Initial discovery The clientToken= campaign conducted by Lazarus and identified by Sansec started in May 2019. com technokain[.]com com darvishkhan[.]net net areac-agr[.]com