Tag

Unc4990

All articles tagged with #unc4990

cybersecurity1 year ago

"Rising Threat: USB Malware Exploits News and Media Platforms"

Hackers linked to UNC4990 are using USB devices to initiate attacks, with payloads hosted on legitimate platforms like GitHub, Vimeo, and Ars Technica. These payloads, disguised as harmless text strings, are crucial in downloading and executing malware. The attackers have targeted users in Italy and have made over $55,000 in profit through a backdoor named QUIETBOARD, which also mines cryptocurrencies and has various capabilities. Despite being removed from the impacted platforms, the use of trusted sites and covert hosting makes it difficult to detect and remove the malicious code, highlighting the ongoing threat of USB-based malware and the challenge it poses to conventional security measures.

cybersecurity1 year ago

"Ars Technica Targeted in Unprecedented Malware Campaign with Advanced Obfuscation"

Security firm Mandiant reported a never-before-seen malware campaign that used Ars Technica and Vimeo to serve second-stage malware, employing obfuscation techniques to cover its tracks. The campaign, attributed to threat actor UNC4990, involved embedding malicious strings in benign content on the websites, which were automatically retrieved by devices infected with the first-stage malware. This novel approach, along with previous techniques used by UNC4990, demonstrates a sophisticated and evolving threat landscape in cybersecurity.