Researchers from Trend Micro’s Threat Hunting team have uncovered a new technique employed by the advanced persistent threat (APT) group dubbed Mustang Panda or Earth Preta. The cyberespionage group has been abusing the Microsoft Application Virtualization Injector (MAVInject.exe) to stealthily inject malicious payloads into waitfor.exe when it detects an ESET antivirus application running. This discovery is a sign of the group’s evolving tactics to bypass security defenses and maintain a foothold in compromised systems. Sophisticated Evasion Tactics Earth Preta’s latest campaign uses Setup Factory, an installer builder, to drop and execute malicious payloads while evading detection. The attack chain starts…
Kirsten Doyle
The Qualys Threat Research Unit (TRU) has uncovered two significant vulnerabilities in OpenSSH, a widely used open-source implementation of the Secure Shell (SSH) protocol. These flaws, tracked as CVE-2025-26465 and CVE-2025-26466, pose substantial security risks to enterprise infrastructure and encrypted communications. Details of the Vulnerabilities CVE-2025-26465: The researhers said the OpenSSH client is vulnerable to an active machine-in-the-middle (MITM) attack if the VerifyHostKeyDNS option is enabled (it is disabled by default): when a vulnerable client connects to a server, an active machine-in-the-middle can mimic the server by fully bypassing the client’s checks of the server’s identity. The issue was introduced…
South Korea has formally suspended new downloads of the Chinese AI chatbot DeepSeek, citing concerns over data privacy and compliance with domestic regulations. The suspension took effect on 15 February, according to the Personal Information Protection Commission (PIPC). While downloads are currently restricted in domestic app marketplaces, the web-based service remains accessible. The decision follows PIPC’s analysis of DeepSeek’s data handling practices, which revealed deficiencies in communication functions and personal information processing procedures with third-party service providers. Shortly after its launch, DeepSeek was found to have inadequately addressed South Korea’s data protection laws, which saw regulators issue a formal order…
Microsoft Threat Intelligence has uncovered a new variant of XCSSET, a sophisticated modular macOS malware that targets users by infecting Xcode projects. While the latest variant has only been observed in limited attacks, security researchers warn that its enhanced capabilities make it a significant threat to macOS users and developers. A Persistent Threat Since 2020 First identified by Trend Micro in 2020, XCSSET initially gained infamy as it was able to compromise Xcode projects, which allowed it to execute malicious code whenever a developer built an infected project. The malware leveraged zero-day vulnerabilities to slip past macOS security protections, steal…
As entities of every sector move more apps and workloads to the cloud, security is becoming a top priority. Microsoft Azure, one of the world’s most popular cloud platforms, provides a range of security tools and best practices to help businesses protect their assets stored in their environments. However, securing an Azure environment is about more than just enabling default protections—it’s about helping users maintain compliance, too. This takes a forward-thinking approach to identity management, network security, logging, and monitoring. To strengthen security, Microsoft has made several key changes, including mandatory Multi-Factor Authentication, new AI-driven security integrations, and enhancements to…
Jeremiah Fowler, an experienced cybersecurity researcher at vpnMentor and co-founder of Security Discovery, has uncovered a massive data exposure involving nearly 2.7 billion records linked to Mars Hydro, a China-based manufacturer of IoT-enabled grow lights. The breach, which included sensitive Wi-Fi credentials, IP addresses, and device details, underscores ongoing concerns about IoT security and data privacy. Fowler discovered the unprotected database and reported it to vpnMentor. The publicly accessible trove contained 2,734,819,501 records totaling 1.17 terabytes of data, exposing logging, monitoring, and error records for IoT devices sold globally. The records included: The database appeared to belong to LG-LED SOLUTIONS…
eSentire’s Threat Response Unit (TRU) has uncovered a new cyber espionage campaign leveraging a legitimate Adobe executable to sideload the EarthKapre/RedCurl loader. The attack specifically targeted a firm in the Legal Services industry, highlighting the group’s persistent focus on corporate espionage. A Sophisticated Attack Chain The TRU team said the initial foothold was gained through a phishing campaign, where targets received a PDF file masquerading as an Indeed job application. The PDF contained links to a ZIP archive with an ISO image. Once the victim opened the image file, they encountered what appeared to be a CV file (“CV Applicant…
Espionage actors linked to China may be diversifying their operations, as new evidence points to the use of espionage tools in a recent ransomware attack against a South Asian software and services company. Symantec Threat Intelligence reports that the attack, involving the RA World ransomware, stands out due to the distinct toolset typically associated with China-based espionage groups, raising questions about the motivations behind this cross-over from traditional espionage to financially driven cybercrime. Espionage Toolsets Deployed In late 2024, a cyberattack targeting an Asian software company saw the deployment of tools historically used by China-linked espionage actors. These tools, usually…
As people celebrate Valentine’s Day today, malicious actors are jumping on the love bandwagon in an opportunity to exploit heightened emotions and consumer spending with a wave of scam emails. According to the latest findings from Bitdefender Antispam Lab, a whopping 50% of all Valentine’s Day-themed spam emails between 13 January 13 and 7 February this year, were classified as scams—a steep rise from 25% in 2024. Similarly, new data from KnowBe4 revealed a 34.8% spike in Valentine’s Day-related phishing attacks compared to February 2024. Love Is in the Air—and So Are Phishing Scams Bitdefender’s research highlights a growing trend…
The Russia-linked threat actor known as Seashell Blizzard has assigned one of its subgroups to gain initial access to internet-facing infrastructure and establish long-term persistence within targeted entity, a Microsoft report has revealed. Also dubbed APT44, BlackEnergy Lite, Sandworm, Telebots, and Voodoo Bear, Seashell Blizzard has been active since at least 2009 and is believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU) military unit 74455. Targeting Critical Sectors Observed activities following initial access suggest that this campaign allowed Seashell Blizzard to infiltrate global targets across critical sectors, including energy, oil and gas, telecommunications, shipping, arms manufacturing,…
