< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 5 sources · 5 days · First seen · Last updated

Emerging cybersecurity malware and phishing threats

Overview

Cybersecurity researchers have identified several distinct malware campaigns and vulnerabilities targeting various users and enterprise infrastructures.

Initial reports highlighted the RevStealer malware, which masquerades as a free version of the Claude AI assistant to steal passwords, browser cookies, and cryptocurrency wallet information. Concurrently, a critical authentication bypass vulnerability in Citrix NetScaler was identified, allowing unauthenticated attackers to access corporate systems.

Subsequent findings detailed the emergence of SloppyRAT, a Windows-based malware that uses a multi-stage delivery chain involving legitimate utilities to execute Python payloads for host reconnaissance and lateral movement. Additionally, phishing campaigns have been observed impersonating university leadership to distribute malicious files via Google Drive, ultimately deploying the Zoho Assist remote management tool to gain unauthorized access to sensitive data.

Entities

Zoho Assist · Citrix NetScaler · University of Virginia · Notre Dame · Citrix

Timeline

  1. 1 day ago

    [TECHNOLOGY] 3 sources
    Cybersecurity threats involve SloppyRAT malware and university-themed phishing

    New cyber threats include SloppyRAT, a multi-stage malware used for ransomware movement, and phishing campaigns impersonating university leaders to deploy malicious remote access tools.

  2. 6 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity threats target AI users and Citrix NetScaler systems

    Cybercriminals are using fake Claude AI desktop apps to deploy RevStealer malware targeting crypto wallets, while attackers actively exploit a critical authentication bypass vulnerability in Citrix NetScaler.

Sources

cybernoz.com · newsbit.nl · security.nl · securityopenlab.it · vegandisneyfood.com