MoonBounce: a step forward for UEFI threats

On January 20, 2022, researchers at Kaspersky discovered a hidden threat entrenched within the firmware of a computer: a rootkit. It’s called “MoonBounce” and is believed to be developed by government-backed Chinese hackers[6]. So what are rootkits? Generally, when talking about malware, rootkits are a type of malware designed to conceal itself or traces of …

How North Korea is targeting US Defense Corporations

Recently, the Malwarebytes Threat Intelligence Team discovered a new spear phishing and malware attack from a notorious hacker group, Lazarus Group, a North Korean state-sponsored APT, or Advanced Persistent Threat.[1] In a nutshell, an APT is an adversary with many resources and a high level of experience, which it leverages to infiltrate the IT system …

TrickBot’s New Defences and Improvements

Recently, security researchers from IBM have found out that TrickBot has implemented new improvements and defenses once again. To provide context, TrickBot is a Trojan that is capable of delivering malicious malware. It was originally created as a banking Trojan back in 2016 with the sole goal of stealing banking information.[1] Ever since then, TrickBot …

2FA is no longer secure enough.

It has been a recent uprising during the past couple of years that companies and services have encouraged to start rolling out two-factor authentication modalities to its users whether it be in the form of a text-message, email, through an authentication app or via other means. However, a recent security breach fell upon the hands …

SIM-Card Swapping scam

With the advent of technology, smartphones have changed the way we think, work, and socialize. They have started to provide numerous advantages, including accessibility and easier communication. People started saving all their personal information and some of their passwords in some security apps on their phones. In addition, many individuals rely on their phones for …

The Belarus Railway Hack

On Monday, January 24th, a group of hackers claimed to have launched a successful ransomware attack against Belarusian Railways, the state-run national train system of Belarus. In their posted screenshots, the group appears to have gotten access to the backend systems of the railway and has claimed to have encrypted the system with malware[1]. One …

How a Minecraft DDOS Attack Crippled a Whole Country’s Internet

Last weekend, a massive-scale tournament was hosted on the popular PC game Minecraft in which 150 competitors vied for the grand prize of $100,000.[2] The tournament in question was inspired by the hit Netflix show Squid Game and was set to take place on the mega streaming platform Twitch.[1] However, things quickly went awry when …

NFT Project Taken Over by Cyber Criminals

Ozzy Osbourne, a famous musician and TV personality from the 70’s decided to launch a new NFT project called CryptoBatz. “I’ve been trying to get in on the NFT action”[2] said Ozzy, after his wife Sharon didn’t allow him to buy a Bored Ape NFT for christmas, Ozzy decided to “Make his own”[2] . The …

Security threats in Google Chrome

Google Chrome, one of the most used browsers with an estimated 3.2 billion users, has recorded around 26 security breaches. Google stated that the one of these issues is rated as “critical”. Usually, chrome’s vulnerabilities are not often rated as “critical”, this is already the second one this year. This critical vulnerability is a use …

Malicious Attack Towards the Missing

The largest humanitarian network has had their information compromised and thousands of people will continue to suffer because of it. Although the hackers use of the sensitive information is yet to be discovered, countless troubles have come from the attack. What is the ICRC? The International Committee of the Red Cross (ICRC) is a neutral …