ZeroHour

Search: “Windows Deployment Services”

116 stories

Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results

NCSC, FBI, and AIVD warn Iranian state-linked actors deliver CHOSEN BRICK Windows spyware via fake AI apps, antivirus installers, and MRI-result lures.

A joint advisory from the UK NCSC, FBI, and Dutch AIVD details CHOSEN BRICK (FBI tracking name: HEAVYGRAM), Iranian state-linked Windows spyware targeting dissidents, activists, and journalists worldwide since at least 2025. Lures impersonate Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player, and KeePass, and operators pivot conversations from corporate to personal devices to bypass enterprise controls. The spyware persists via Registry Run keys, adds Microsoft Defender exclusions, uses per-victim Telegram bots for command-and-control, and exfiltrates screenshots, audio, email, and chat data via Telegram and cloud services, with some victim data appearing on pro-Iranian leak sites.

GBHackersupdated · 10h agofirst · 1d agoMalware in the wild 6 sources

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

Unit 42 uncovers CL-CRI-1171, a two-year pay-per-install campaign distributing 10,000+ OfferLoader samples via YouTube and SEO poisoning.

Palo Alto Networks Unit 42 tracked a campaign as CL-CRI-1171, an infection-as-a-service platform operating for at least two years. It used 11 YouTube gaming channels with hundreds of thousands of subscribers and SEO-poisoned download pages for trojanized WinDirStat and Bluetooth driver installers to distribute OfferLoader, a disposable loader embedded in Inno Setup installers. Payloads delivered included Insomnia RAT (Node.js and Python backdoors), ARKTunnel (a WebSocket-based RAT using LSB steganography), and Docro Hijacker (Chrome browser hijacker), with later infections delivering GCleaner and Socks5Systemz. Over 200 rotating domains across .xyz, .cfd, .space, and .info TLDs were used, with gating filters that served broken links or decoy pages to scanners and researchers.

GBHackers · 5d agoMalware in the wild2

ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

Cisco Talos details ClearFake's fake-CAPTCHA chain deploying ZigCryptoStealer with a BYOVD attack that kills EDR processes, observed at a Ukrainian government organization in April 2026.

ClearFake compromises websites, injects JavaScript via a malicious Cloudflare Worker, retrieves instructions from BNB Smart Chain contracts (EtherHiding), and presents a fake Google CAPTCHA that tricks Windows users into pasting a command that loads a remote library over WebDAV via rundll32. The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which hijacks clipboard cryptocurrency addresses, alongside a signed but vulnerable Windows driver used in a BYOVD attack to terminate EDR processes. A parallel branch delivers Amatera secondary payloads that install a hidden remote-access client providing operator desktop control, with Cisco Talos tracking the remote-loader activity as UAT-10820. Talos observed unusual remote library execution at a Ukrainian government organization in April 2026 and assesses the attacks are part of a broader theft operation rather than a single targeted campaign.

Cyber Security News · 7d agoMalware in the wild1

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

Zimperium documents ToxicPanda 2.0, an Android banking trojan now targeting 349 financial institutions in 16 countries via ADB privilege escalation and overlay credential theft.

Zimperium's zLabs documented ToxicPanda 2.0, an Android banking trojan expanding from 16 targeted apps to 349 financial institutions across 16 countries, with 167 remote commands. It poses as a dropper, abuses VPN permissions to block Google Play Protect while installing a hidden payload, then uses the Accessibility Service for screen monitoring and overlay-based credential theft. It automates enabling Android Wireless Debugging and completes the pairing handshake to gain ADB shell access for privilege escalation, and overlays fake lock screens to steal device PINs. Previously unfinished commands are now operational and samples are served from AWS-hosted storage buckets.

Security Affairs · 25d agoMalware in the wild

HBO Max Reddit Account Hijacked to Spread PasteSwitch ClickFix Malware

Hijacked HBO Max verified Reddit account ran 108 ClickFix malvertising ads delivering AMOS and Amatera stealers plus crypto clippers to macOS and Windows users.

Threat actors hijacked HBO Max's verified Reddit account (u/hbomax) to run 108 malicious ClickFix ads over 48 hours in a campaign tracked as PasteSwitch, researched by Hudson Rock and ADAMnetworks. macOS victims were served curl | zsh chains deploying MacSync and Atomic macOS Stealer (AMOS), which harvest browser credentials, Telegram data, Apple Notes, and macOS passwords, while fake Ledger, Trezor, and Exodus apps targeted BIP39 seed phrases. Windows users received an InstallFix chain using an MP3/HTA polyglot with mshta and PowerShell, scheduled-task persistence, AMSI disabling, and in-memory Amatera Stealer that hid C2 traffic (77.91.65.13:443) behind a facebook.com TLS SNI. AnimateClipper and ZigClipper components swapped copied crypto wallet addresses and used Binance Smart Chain contracts as mutable C2 dead drops; Reddit paused the ads and the initial access path remains undisclosed.

GBHackersupdated · 1d agofirst · 2d agoMalware 7 sources

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Fake software-download sites distribute installers that disable Windows Update and weaken Defender, attributed to China-linked cluster Silver Fox.

Microsoft says an active campaign uses counterfeit vendor websites on .com.cn and .hl.cn infrastructure with Chinese-language lures to deliver server-side generated installers that establish scheduled-task persistence, add Defender exclusions, delete shadow copies, and stop services including wuauserv, UsoSvc, uhssvc and WaaSMedicSvc. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, primarily China-based operations of multinationals and Chinese-speaking users. Microsoft assesses with moderate confidence the activity matches the Silver Fox (Yinhu) cluster, historically tied to Gh0st RAT and ValleyRAT, with C2 over non-standard ports like 5090 and 7088-7090 via domains iualef[.]net and oijfwe[.]net. Kaspersky separately detailed a QN Wallpaper DLL-sideloading chain delivering ValleyRAT.

The Hacker News · 14d agoMalware in the wild1