Remove advanced-persistent-threats-apts
article thumbnail

New PowerDrop malware targets U.S. aerospace defense industry

Security Affairs

A previously unknown threat actor has been observed targeting the U.S. Researchers from the Adlumin Threat Research discovered a new malicious PowerShell script, dubbed PowerDrop, that was employed in attacks aimed at organizations in the U.S. aerospace defense sector with a new PowerShell malware dubbed PowerDrop. aerospace sector.

article thumbnail

APT hacked a US municipal government via an unpatched Fortinet VPN

Security Affairs

The Federal Bureau of Investigation (FBI) reported that an APT group had breached the network of a local US municipal government by exploiting vulnerabilities in an unpatched Fortinet VPN. “The FBI is continuing to warn about Advanced Persistent Threat (APT) actors exploiting Fortinet vulnerabilities.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Nation-state actors exploit Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus, CISA warns

Security Affairs

“Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. ” continues the alert.

article thumbnail

Microsoft Patch Tuesday, January 2023 Edition

Krebs on Security

Dustin Childs , head of threat awareness at Trend Micro’s Zero Day Initiative , said sysadmins need to take additional measures to be fully protected from this vulnerability. “Vulnerabilities like CVE-2023-21674 are typically the work of advanced persistent threat (APT) groups as part of targeted attacks,” Narang said.

article thumbnail

SideWinder carried out over 1,000 attacks since April 2020

Security Affairs

SideWinder, an aggressive APT group, is believed to have carried out over 1,000 attacks since April 2020, Kaspersky reported. Researchers from Kaspersky have analyzed the activity of an aggressive threat actor tracked as SideWinder (aka RattleSnake and T-APT-04). ” states Kaspersky. ” states Kaspersky.

article thumbnail

GwisinLocker ransomware exclusively targets South Korea

Security Affairs

Researchers spotted a new family of ransomware, named GwisinLocker, that encrypts Windows and Linux ESXi servers. Researchers warn of a new ransomware called GwisinLocker which is able to encrypt Windows and Linux ESXi servers. “It is similar to Magniber in that it operates in the MSI installer form. Pierluigi Paganini.

article thumbnail

BackdoorDiplomacy APT targets diplomats from Africa and the Middle East

Security Affairs

ESET researchers discovered an advanced persistent threat (APT) group, tracked as BackdoorDiplomacy, that is targeting diplomats across Africa and the Middle East. According to the experts, the BackdoorDiplomacy APT group has been active since at least 2017. SecurityAffairs – hacking, APT).