Cisco Talos discovered a consistent cyber campaign by threat group Gamaredon against Ukrainian users. The campaign uses spear-phishing tactics, sending malicious LNK files disguised as office documents related to the Ukraine conflict. The attack initiates by executing a PowerShell downloader within the LNK file. The downloaded payload allows the attackers to sidestep traditional detection mechanisms. The files suggest an attempt to exploit sensitive geopolitical themes.

Hackers Scanning From 24,000 IP’s to Gain Access to Palo Alto Networks
Researchers observed a significant increase in malicious scanning of Palo Alto Networks’ GlobalProtect VPN portals, with nearly 24,000 unique IP addresses targeting the systems. This