article thumbnail

T95 Android TV Box sold on Amazon hides sophisticated malware

Security Affairs

“By doing this, the C&C server ends up hitting the Pi-hole webserver instead of sending my logins, passwords, and other PII to a Linode in Singapore (currently 139.162.57.135 at time of writing).” and a file named. ” continues the expert. data/system/shared_prefs/open_preference.xml ?

Cleanup 96
article thumbnail

A new trojan Lampion targets Portugal

Security Affairs

Looking at the file, it is obfuscated, but in this case, the technique used by criminals was simple: just add commentaries (junk blocks) between the lines of the malicious code to make it confused. After a few rounds of code cleanup (deobfuscation), the final code comes up. zip file is now accessed by Lampion and its content is loaded.

article thumbnail

I've Just Added 2,844 New Data Breaches With 80M Records To Have I Been Pwned

Troy Hunt

In total, there were 2,889 text files in the archive but it's what's inside them which I found particularly interesting. Almost all the files are just email addresses and plain text passwords (the occasional file has a username that's not an email address and a password). But there's 18.6M