Remove 2022 Remove Libraries Remove Manufacturing
article thumbnail

Microsoft experts linked the Raspberry Robin malware to Evil Corp operation

Security Affairs

On July 26, 2022, Microsoft researchers discovered that the FakeUpdates malware was being distributed via Raspberry Robin malware. The malware was first spotted in September 2021, the experts observed Raspberry Robin targeting organizations in the technology and manufacturing industries. exe to execute a malicious command.

article thumbnail

Raspberry Robin operators are selling initial access to compromised enterprise networks to ransomware gangs

Security Affairs

In October 2022, the malware was used in post-compromise activity attributed to another actor, DEV-0950 (which overlaps with FIN11 / TA505 cybercrime gang). Beginning on September 19, 2022, experts observed the worm infections deploying IcedID , Bumblebee and TrueBot payloads. The final-stage malware was the Clop ransomware.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

FritzFrog P2P Botnet is back and targets Healthcare, Education and Government Sectors

Security Affairs

In December the botnet registered a 10x growth in its infection rate peaking at 500 incidents per day in January 2022. Experts discovered infected machines in a European television channel network, a Russian manufacturer of healthcare equipment, and multiple universities in East Asia. ” continues the report.

Education 256
article thumbnail

GoDaddy discloses a new data breach

Security Affairs

The security breach was discovered in December 2022 after customer reported that their sites were being used to redirect to random domains. “In December 2022, an unauthorized third party gained access to and installed malware on our cPanel hosting servers. ” reads a FORM- 10-K filed with SEC. ” concludes the company.

article thumbnail

3CX voice and video conferencing software victim of a supply chain attack

Security Affairs

The software is used by organizations in olmost every industry, including automotive, food & beverage, hospitality, Managed Information Technology Service Provider (MSP), and manufacturing. “Unfortunately this happened because of an upstream library we use became infected.” “Unfortunately the rumors are true.

article thumbnail

Raspberry Robin malware used in attacks against Telecom and Governments

Security Affairs

The campaign has been active since at least September 2022, most of the infections have been observed in Argentina (34,8%), followed by Australia (23,2%). The malware was first spotted in September 2021, the experts observed it targeting organizations in the technology and manufacturing industries.

article thumbnail

Raspberry Robin spreads via removable USB devices

Security Affairs

The malware was first spotted in September 2021, the experts observed Raspberry Robin targeting organizations in the technology and manufacturing industries. The malware uses TOR exit nodes as a backup C2 infrastructure. Initial access is typically through infected removable drives, often USB devices. exe to execute a malicious command.