Remove 06
article thumbnail

Kraken fileless attack technique abuses Microsoft Windows Error Reporting (WER)

Security Affairs

” states the blog post published by Malwarebytes. The payload loaded is a.Net DLL internally named “Kraken.dll” and compiled on 2020-06-12. . “On September 17th, we discovered a new attack called Kraken that injected its payload into the Windows Error Reporting (WER) service as a defense evasion mechanism.”

Phishing 130
article thumbnail

Brazilian trojan banker is targeting Portuguese users using browser overlay

Security Affairs

Since the end of April 2020, a new trojan has been affecting Portuguese users from several bank organizations. Since the end of April 2020, a new Trojan variant is affecting users from several bank organizations in Portugal. In detail, the bitcoin wallet was used in recent transactions, last: 2020-01-14 00:22h.

article thumbnail

The hidden C2: Lampion trojan release 212 is on the rise and using a C2 server for two years

Security Affairs

Also, the C2 server is the same noticed on the past campaigns since 2020, suggesting, thus, that criminals are using the same server geolocated in Russia for two years to orchestrate all the malicious operations. Filename : Comprovativo de pagamento_2866-XRNM_15-02-2022 06-43-54_28.vbs FUD capabilities of the Lampions’ VBS loader.