Tag: powershell
-
Fake Google Chrome errors trick you into running malicious PowerShell scripts
A new malware distribution campaign uses fake Google Chrome, Word, and OneDrive errors to trick users into running malicious PowerShell fixes that ins… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-google-chrome-errors-trick-you-into-running-malicious-powershell-scripts/
-
FlyingYeti targets Ukraine using WinRAR exploit to deliver COOKBOX Malware
Russia-linked threat actor FlyingYeti is targeting Ukraine with a phishing campaign to deliver the PowerShell malware COOKBOX. Cloudflare researchers … First seen on securityaffairs.com Jump to article: securityaffairs.com/164017/hacking/flyingyeti-targets-ukraine.html
-
The End of an Era: Microsoft Phases Out VBScript for JavaScript and PowerShell
Microsoft on Wednesday outlined its plans to deprecate Visual Basic Script (VBScript) in the second half of 2024 in favor of more advanced alternative… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/the-end-of-era-microsoft-phases-out.html
-
Microsoft Replacing VBScript With JavaScript PowerShell
Microsoft has shifted its scripting options for web development and task automation. The company is replacing VBScript with more advanced alternatives… First seen on gbhackers.com Jump to article: gbhackers.com/microsoft-replacing-vbscript/
-
Suspected CoralRaider continues to expand victimology using three information stealers
Talos also discovered a new PowerShell command-line argument embedded in the LNK file to bypass anti-virus products and download the final payload int… First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/suspected-coralraider-continues-to-expand-victimology-using-three-information-stealers/
-
Hackers Use Custom Backdoor Powershell Scripts to Attack Windows Machines
The Damselfly Advanced Persistent Threat (APT) group, also known as APT42, has been actively utilizing custom backdoor variants, NiceCurl and TameCat,… First seen on gbhackers.com Jump to article: gbhackers.com/hackers-use-custom-backdoor/
-
Analyze Malicious Powershell Scripts by Running Malware in ANY.RUN Sandbox
Hackers exploit PowerShell, a built-in scripting tool on Windows (and sometimes Linux), to launch various attacks. PowerShell scripts can download mal… First seen on gbhackers.com Jump to article: gbhackers.com/powershell-script-tracer_-analyze-powershell-execution/
-
Rhadamanthys infostealer deployed via AI-based PowerShell
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/rhadamanthys-infostealer-deployed-via-ai-based-powershell
-
Malicious PowerShell script pushing malware looks AI-written
A threat actor is using a PowerShell script that was likely created with the help of an artificial intelligence system such as OpenAI’s ChatGPT, Googl… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-powershell-script-pushing-malware-looks-ai-written/
-
New DEEP#GOSU Malware Campaign Targets Windows Users with Advanced Tactics
A new elaborate attack campaign has been observed employing PowerShell and VBScript malware to infect Windows systems and harvest sensitive informatio… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/new-deepgosu-malware-campaign-targets.html
-
Novel Script-Based Attack That Leverages PowerShell And VBScript
A new campaign has been identified as DEEP#GOSU is likely linked to the Kimsuky group, and it employs a new script-based attack chain t… First seen on gbhackers.com Jump to article: gbhackers.com/power-vbscript-attack/
-
Remote Trojaner Agent Tesla wird über Quantum Builder verbreitet
Tags: powershellDer Builder verwendet außerdem Techniken wie Decoys, UAC Prompts und In-Memory PowerShell, um die endgültige Payload auszuführen. Sie alle werden imme… First seen on infopoint-security.de Jump to article: www.infopoint-security.de/remote-trojaner-agent-tesla-wird-ueber-quantum-builder-verbreitet/a32345/
-
Qualys kündigt bahnbrechende Lösung für First-Party-Software-Risikomanagement an
Mit der neuen Lösung von Qualys können die Teams ihre eigenen, mit gängigen Sprachen wie PowerShell und Python erstellten Skripte als Qualys ID (QIDs)… First seen on infopoint-security.de Jump to article: www.infopoint-security.de/qualys-kuendigt-bahnbrechende-loesung-fuer-first-party-software-risikomanagement-an/a35024/
-
Ukraine Military Targeted With Russian APT PowerShell Attack
First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ukraine-military-targeted-with-russian-apt-powershell-attack

