Follow the latest coverage, related explainers and connected technology stories.
Microsoft researchers observed a new delivery technique used by the Russian Star Blizzard group to deploy the CosmicPulse backdoor through phishing messages and malicious shortcut files. The campaigns, which targeted more than 100 organizations, enabled the infection chain to run with minimal victim involvement.
Microsoft observed the Russia-linked Star Blizzard group shifting to broader phishing campaigns and using compromised websites and the RedFlick technique to deploy the CosmicPulse backdoor with less victim interaction. The campaigns targeted more than 100 organizations, including government entities, nongovernmental organizations, and research centers associated with support for Ukraine.
A malicious campaign exploited custom versions of ChatGPT to direct users to fake pages asking them to run PowerShell commands, leading to the deployment of a remote-access Trojan. Huntress observed at least 40 connections to the malicious page, confirming two infections linked to a custom GPT.
Attackers have developed a method to distribute the MacSync information-stealing malware by hiding commands inside public iCloud calendar events, while adding a backdoor that impersonates Finder and enables command execution and data theft from macOS devices.
The domain third-party.com, used for years as a default address in programming documentation and code examples, has begun displaying a fake Cloudflare page that pressures Windows users into executing malicious PowerShell commands. There are no confirmed reports that the attack succeeded, but the domain’s prevalence in public repositories and projects makes it a potential danger for code copied verbatim.
Brevo confirmed that attackers stole an API key for its Cloudflare account and used it to modify the content of its websites and JavaScript files embedded in customer websites, resulting in the distribution of ClickFix pages and malware. The campaign included adding a persistent backdoor to some WordPress sites, while the company said its application interface, customer data, and email delivery infrastructure were not affected.