Tuesday , February 18 2025
malware

Top 4 Malware you have to Prepare for in 2025

In 2025, malware attacks will persist. To prepare, organizations should familiarize themselves with common malware families. Here are five to focus on now.

LockBit:

150 Gov.t Portal affected
Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

Indian government and educational websites, along with reputable financial brands, have experienced SEO poisoning, causing user traffic to be redirected...
Read More
150 Gov.t Portal affected  Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

The Cyber Threat Intelligence Unit of BGD e-GOV CIRT has found 600 vulnerable PRTG instances in Bangladesh, affected by the...
Read More
CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

Builder claims Rs 150 cr for data loss; AWS faces FIR In Bengaluru

Amazon Web Services (AWS) has been named in an FIR after a builder claimed damages to the tune of Rs...
Read More
Builder claims Rs 150 cr for data loss;  AWS faces FIR In Bengaluru

CISA Warns Active Exploitation of Apple iOS Security Flaw

CISA has issued an urgent warning about a critical zero-day vulnerability in Apple iOS and iPadOS, known as CVE-2025-24200, which...
Read More
CISA Warns Active Exploitation of Apple iOS Security Flaw

Massive IoT Data Breach Exposes 2.7 Billion Records

A major IoT data breach has exposed 2.7 billion records, including Wi-Fi network names, passwords, IP addresses, and device IDs....
Read More
Massive IoT Data Breach Exposes 2.7 Billion Records

SonicWall Firewall Auth Bypass Vulnerability Exploited in Wild

A serious authentication bypass vulnerability in SonicWall firewalls, called CVE-2024-53704, is currently being exploited, according to cybersecurity firms. The increase...
Read More
SonicWall Firewall Auth Bypass Vulnerability Exploited in Wild

AMD Patches High-Severity SMM Vulns Affecting EPYC and Ryzen Processors

AMD has released security patches for two high-severity vulnerabilities in its System Management Mode (SMM). If exploited, these could let...
Read More
AMD Patches High-Severity SMM Vulns Affecting EPYC and Ryzen Processors

Lazarus Group Unleashes New Malware Against Developers Worldwide

Lazarus Group has initiated a complex global campaign aimed at software developers and cryptocurrency users. Operation Marstech Mayhem uses the...
Read More
Lazarus Group Unleashes New Malware Against Developers Worldwide

Daily Security Update Dated : 15.02.2025

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated : 15.02.2025

Salt Typhoon to target Bangladeshi Universities, One identified

RedMike (Salt Typhoon) targeted university devices in Bangladesh, likely to access research in telecommunications, engineering, and technology, especially from institutions...
Read More
Salt Typhoon to target Bangladeshi Universities, One identified

LockBit is a major ransomware targeting Windows devices and is a significant threat in Ransomware-as-a-Service (RaaS) attacks. Its decentralized structure has allowed it to infiltrate high-profile organizations globally, such as the UK’s Royal Mail and India’s National Aerospace Laboratories in 2024.

Law enforcement has arrested several members of the LockBit group, but it still operates and plans to release LockBit 4.0 in 2025.

Lumma:

Lumma is a widely available malware that steals sensitive information, sold on the Dark Web since 2022. It collects data from apps, including login credentials and financial details.

Regular updates enhance its capabilities, allowing it to log browsing history and cryptocurrency wallet data. Lumma can also install other malware on infected devices. In 2024, it was spread through fake CAPTCHA pages, torrents, and phishing emails.

XWorm:

XWorm is a malware that allows cybercriminals to remotely control infected computers. Since its emergence in July 2022, it collects sensitive data such as financial information, browsing history, passwords, and cryptocurrency wallet details.

It enables attackers to monitor victims through keystroke tracking, webcam captures, audio recording, network scans, and viewing open windows. XWorm can also access and alter the clipboard, which could lead to stealing cryptocurrency credentials.

By 2024, XWorm was implicated in several major attacks, including those that exploited CloudFlare tunnels and used legitimate digital certificates.

AsyncRAT:

AsyncRAT is a remote access trojan first seen in 2019, initially spread through spam emails related to the COVID-19 pandemic. It has since become popular for various cyber attacks.

The malware has developed to include numerous harmful features, such as recording screen activity, logging keystrokes, installing other malware, stealing files, maintaining a presence on infected systems, disabling security software, and launching denial-of-service attacks.

As of 2024, AsyncRAT remains a major threat, often disguised as pirated software, and was one of the first malware types distributed in complex attacks using AI-generated scripts.

You can visit here to know more of the article.

US introduces Cyber Trust Mark for smart devices

Check Also

Zuckerberg

Everything I Say Leaks,’ Zuckerberg Says in Leaked Meeting Audio

At an all-hands meeting at Meta on Thursday, Mark Zuckerberg did not mention the company’s …

Leave a Reply

Your email address will not be published. Required fields are marked *