Financial threat group UAC-0006 is conducting a phishing campaign targeting customers of Ukraine’s largest state-owned bank, PrivatBank, using password-protected archives to deploy SmokeLoader malware. Cybersecurity experts noted overlaps in the group’s tactics with EmpireMonkey and Russia-linked FIN7. The SmokeLoader malware is largely used for data theft, unauthorized access, and financial gain.

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens – The Hacker News
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens The Hacker News


