UPDATES
3
4
3 4
threat
UPDATES
3
CHINA
The FBI has sent out a warning about an on-going
‘ smishing scam ’ potentially from Chinese cybercriminals , asking for payments of unpaid tolls .
Mike Britton , CIO at Abnormal Security , said : “ Cybercriminals will always favour leveraging trusted brands and urgent messaging to deceive unsuspecting victims . By impersonating legitimate transportation agencies , attackers increase the likelihood of success . This latest toll payment scam is particularly effective because it mimics legitimate government and transportation agencies to prompt users to act quickly out of fear of fines .
“ The cost to execute these smishing attacks is negligible – attackers only need to craft convincing text messages and set up fraudulent payment sites . With mass distribution , even a small percentage of victims falling for the scam can generate significant returns for cybercriminals .”
4
NORTH KOREA
SecurityScorecard ’ s STRIKE Team , has identified a new
Lazarus Group campaign affecting software developers and cryptocurrency users . The group is embedding advanced malware into GitHub repositories and NPM packages , making it easy for unsuspecting developers to download and integrate malicious code into their projects . The malware targets cryptocurrency wallets and browser extensions , with confirmed infections spreading across multiple regions .
SecurityScorecard ’ s SVP of Threat Research & Intelligence , Ryan Sherstobitoff , said : “ Operation Marstech Mayhem exposes a critical evolution in the Lazarus Group ’ s supply chain attacks , demonstrating not only their commitment to operational stealth but also significant adaptability in implant development .
“ The introduction of the Marstech1 implant , with its layered obfuscation techniques – from control flow flattening and dynamic variable renaming in JavaScript to multi-stage XOR decryption in Python – underscores the threat actor ’ s sophisticated approach to avoiding both static and dynamic analysis .”
3 4
WWW . INTELLIGENTCISO . COM 25