Newly Registered Domains Distributing SpyNote Malware
Cybercriminals are employing deceptive websites on newly registered domains to distribute AndroidOS SpyNote malware. These sites imitate the Google Chrome install page on the Google Play Store, tricking users into downloading SpyNote, a powerful Android remote access trojan. SpyNote is used for surveillance, data exfiltration, and remote control of infected devices. The investigation uncovered multiple domains, IP addresses, and APK files associated with this campaign. The malware utilizes various C2 endpoints for communication and data exfiltration, with functions designed to retrieve and manipulate device information, contacts, SMS, and applications.
Pulse ID: 67feb504b76dd387be73309b
Pulse Link: https://otx.alienvault.com/pulse/67feb504b76dd387be73309b
Pulse Author: AlienVault
Created: 2025-04-15 19:35:32
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Happy Neil Day, here's my piece from this year! May he bang out the tunes forever and ever
Daily old piece 4!
On his way to bang out the tunes
From 2024.
AkiraBot Spammed Websites by using Evasion Techniques
Akirabot is a sophisticated Python framework has successfully targeted websites
using advanced techniques to bypass security measures and deliver AI-generated
spam.
Pulse ID: 67f87aa1dffcefb96c594f87
Pulse Link: https://otx.alienvault.com/pulse/67f87aa1dffcefb96c594f87
Pulse Author: cryptocti
Created: 2025-04-11 02:12:49
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Smishing Triad: Chinese eCrime Group Targets 121+ Countries, Introduces New Banking Phishing Kit
The Chinese eCrime group Smishing Triad has launched a global SMS phishing campaign targeting over 121 countries across various industries. Their infrastructure generates over one million page visits in 20 days, averaging 50,000 daily. The group has introduced a new 'Lighthouse' phishing kit focusing on banking and financial organizations, particularly in Australia and the Asia-Pacific region. Smishing Triad claims to have '300+ front desk staff worldwide' supporting their operations. They frequently rotate domains, with approximately 25,000 active during any 8-day period. The majority of phishing sites are hosted by Chinese companies Tencent and Alibaba. The campaign primarily targets postal, logistics, telecommunications, transportation, finance, retail, and public sectors.
Pulse ID: 67f80a4937d04f9036252cf7
Pulse Link: https://otx.alienvault.com/pulse/67f80a4937d04f9036252cf7
Pulse Author: AlienVault
Created: 2025-04-10 18:13:29
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Newly Registered Domains Distributing SpyNote Malware
Deceptive websites hosted on newly registered domains are being used to deliver AndroidOS SpyNote malware, mimicking the Google Chrome install page on the Google Play Store. The campaign utilizes a mix of English and Chinese-language delivery sites, with Chinese-language comments in the code. The malware is distributed through a two-stage installation process, using an APK dropper to deploy the core SpyNote RAT. SpyNote is a potent Android remote access trojan capable of extensive surveillance, data exfiltration, and remote control. It aggressively requests numerous intrusive permissions, allowing for theft of sensitive data and significant remote access capabilities. The malware's keylogging functionality and ability to manipulate calls, activate cameras and microphones, and remotely wipe data make it a formidable tool for espionage and cybercrime.
Pulse ID: 67f80a4aa4c9d5d796071af6
Pulse Link: https://otx.alienvault.com/pulse/67f80a4aa4c9d5d796071af6
Pulse Author: AlienVault
Created: 2025-04-10 18:13:30
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Four of my favourite pet portraits so far!
I love drawing your little pals, it feels like a great honour!
I have one spot open: https://evanskyarts.com/en/products/custom-pet-portrait
Super Rat: the record-setting rodent sniffing out landmines and saving lives.
From @CNN: "Rats don’t always have the best reputations, but one named Ronin with a super sense of smell is working to change that."
Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools
The Lotus Blossom espionage group has been conducting cyber espionage campaigns targeting government, manufacturing, telecommunications, and media sectors in the Philippines, Vietnam, Hong Kong, and Taiwan. The group employs various versions of the Sagerunex backdoor, including new variants that use cloud services like Dropbox, Twitter, and Zimbra for command and control. Lotus Blossom utilizes multiple hacking tools and techniques to maintain long-term persistence in compromised networks. The attacks involve multi-stage operations, including reconnaissance, lateral movement, and data exfiltration. The group has been active since at least 2012 and continues to evolve its tactics and malware to evade detection.
Pulse ID: 67f038f22c3d7acc43c35cb7
Pulse Link: https://otx.alienvault.com/pulse/67f038f22c3d7acc43c35cb7
Pulse Author: AlienVault
Created: 2025-04-04 19:54:26
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
@LinuxAndYarn @GossiTheDog I've to applaud #WSJ for showing how much #Apple is shafting #consumers with overpriced #parts, because even if the #battery had only 10% tariff there's no reason for a #replacement part to cost more than $50.
Congratulations Ronin! I hope you have lots of bananas, scritches and boops!
#rat #HeroRat
https://apopo.org/herorat-ronin-breaks-guinness-world-records-title/
It is apparently #WorldRatDay today #rat #rats
The landmine-sniffing rats are continuing their slow and steady task of demining Cambodia (and other places). Here's an article about a rat named Ronin setting a record for most mines discovered (109). The previous record holder had cleared 71 landmines by the time of his retirement.