by Ophtek, LLC | Nov 12, 2024 | Chrome, ClickFix, DarkGate, Facebook, Google, Google Meet, Lumma Stealer, malware, Ophtek, Phishing Email
Hackers have designed fake Google Meet error pages to distribute info-stealing malware which can compromise all the data on a network. It feels as though malicious websites are springing up on a daily basis, and with 12.8 million websites infected with malware,...
by Ophtek, LLC | Oct 22, 2024 | contact_sender, malware, Ophtek, Palo Alto Networks, Phishing, RomCom, SnipBot, spam_filters, Suspicious links, verify sources
A new malware attack has been discovered which uses the SnipBot malware to dig deep into the victim’s network and harvest data. SnipBot is a variant of the RomCom malware, which has previously been used for data harvesting and financially motivated attacks such...
by Ophtek, LLC | Oct 15, 2024 | banking_trojans, BBTok, Brazil, Italy, malware, Mekotio, Ophtek, phishing_email, SambaSpy
Italian PC users have become the target of SambaSpy, a new strain of malware which appears to originate from Brazil and employs phishing emails. First detected by Kaspersky in May 2024, SambaSpy currently only seems to have targeted PC users in Italy. This is...
by Ophtek, LLC | Oct 8, 2024 | Amadey, antivirus software, Chrome, Google, hard_reset, hotkeys, kiosk_mode, malware, Ophtek, StealC
There’s nothing worse that a new and innovative malware approach, but that’s exactly what Google users have been exposed to. This latest attack takes advantage of Google’s kiosk mode. For those of you not familiar with kiosk mode, here’s a quick breakdown: it’s...
by Ophtek, LLC | Oct 1, 2024 | anti-malware_software, Brute_Ratel, Havoc, macros, malware, MS_Office, Ophtek, PhantomCore, Phishing, security_updates
Macros make our lives easier when it comes to repetitive tasks on PCs, but they’re also a potential route for malware to take advantage of. The most up to date version of MS Office prevents macros from running automatically, and this is because macros have long...
by Ophtek, LLC | Sep 24, 2024 | BYOVD, DSE, EDRKillShifter, install updates, malware, Ophtek, Russian Hackers, Sophos
The hacking collective RansomHub has unveiled a new strain of malware, one which is used to disable security software and leave PCs open to attack. Discovered by security firm Sophos, RansomHub’s new malware has been dubbed EDRKillShifter. First detected during...