Known group of malicious actors has refreshed its banking trojan campaign by using new websites. The actors have created clone websites of NordVPN and other products, infecting systems with Bolik. The websites look very convincing, have similar URLs with the original ones, and carry valid SSL certificates. According to a report by Dr. Web Antivirus researchers, the same … [Read more...] about Fake NordVPN Website Infects Victims With Banking Trojan
Victims
Troldesh Ransomware Infecting Victims via Compromised Websites
Malicious actors are leveraging compromised URLs to infect victims with Troldesh ransomware. The particular software is most likely to be detected by AV tools, but not always. The actors are using TOR for data exfiltration and communication, and two infected URLs for redundancy. According to a report by Sucuri researchers, the Troldesh ransomware is seeing a rise in the past … [Read more...] about Troldesh Ransomware Infecting Victims via Compromised Websites
