Russian hackers have exploited a vulnerability in popular file archiver 7-Zip to infiltrate Ukrainian governmental and private organisations with SmokeLoader malware, says Tokyo-based cybersecurity firm Trend Micro. The software defect lets hackers bypass Mark-of-the-Web protections which are put in place to red-flag downloads that could be harmful, while SmokeLoader is used to steal important device data such as operating system details and location data. The hackers targeted smaller local government bodies with fewer resources and expertise to prevent such attacks.
242,000 Times Downloaded Malicious Apps from Android and iOS Stealing Crypto Recovery Keys
Researchers have discovered a widespread malware operation, dubbed “SparkCat”, targeting Android and iOS users. The malware uses dated apps containing a malicious SDK, designed to