Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 5 sources · 5 days · First seen · Last updated
Emerging cybersecurity malware and phishing threats
Overview
Cybersecurity researchers have identified several distinct malware campaigns and vulnerabilities targeting various users and enterprise infrastructures.
Initial reports highlighted the RevStealer malware, which masquerades as a free version of the Claude AI assistant to steal passwords, browser cookies, and cryptocurrency wallet information. Concurrently, a critical authentication bypass vulnerability in Citrix NetScaler was identified, allowing unauthenticated attackers to access corporate systems.
Subsequent findings detailed the emergence of SloppyRAT, a Windows-based malware that uses a multi-stage delivery chain involving legitimate utilities to execute Python payloads for host reconnaissance and lateral movement. Additionally, phishing campaigns have been observed impersonating university leadership to distribute malicious files via Google Drive, ultimately deploying the Zoho Assist remote management tool to gain unauthorized access to sensitive data.
Entities
Zoho Assist · Citrix NetScaler · University of Virginia · Notre Dame · Citrix
Timeline
-
1 day ago
[TECHNOLOGY] 3 sourcesCybersecurity threats involve SloppyRAT malware and university-themed phishingNew cyber threats include SloppyRAT, a multi-stage malware used for ransomware movement, and phishing campaigns impersonating university leaders to deploy malicious remote access tools.
-
6 days ago
[TECHNOLOGY] 2 sourcesCybersecurity threats target AI users and Citrix NetScaler systemsCybercriminals are using fake Claude AI desktop apps to deploy RevStealer malware targeting crypto wallets, while attackers actively exploit a critical authentication bypass vulnerability in Citrix NetScaler.
Sources
cybernoz.com · newsbit.nl · security.nl · securityopenlab.it · vegandisneyfood.com