Verticals Targeted: Oil & Gas, Energy, Legal Services
MintsLoader Delivering StealC and BOINC
Jan 31, 2025 12:35:53 PM / by The Hivemind posted in Threat Bulletin, Loader, MintsLoader, BOINC, StealC
AIRASHI Botnet
Jan 27, 2025 11:08:56 AM / by The Hivemind posted in Threat Bulletin, DDoS, Botnet, Emerging Threat, Evolving Threat, AIRASHI
Related Families: AISURU
Executive Summary
AIRASHI is a variant of the AISURU botnet that has been active since at least late 2024. It is in active development and has the capability to conduct large-scale DDoS attacks.
Medusa Ransomware
Jan 24, 2025 2:18:04 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Medusa
Verticals Targeted: Government, Insurance, Real Estate, Healthcare, Manufacturing, Legal Services, Construction, Retail, Business Services, Energy, Education, Telecommunications, Software, Hospitality, Transportation, Financial
Executive Summary
Medusa ransomware is a RaaS that has been active since at least 2023. Medusa has claimed several victims so far in 2025, including UK’s Gateshead Council.
FunkSec Ransomware
Jan 21, 2025 2:22:27 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Emerging Threat, FunkSec
Verticals Targeted: Government, Business Services, Education, Insurance, Software, Media, Finance, Agriculture, Manufacturing, Construction, Healthcare, Retail
Banshee MacOS Stealer
Jan 17, 2025 2:31:03 PM / by The Hivemind posted in Threat Bulletin, Infostealer, MacOS, Banshee
Executive Summary
Banshee is a stealer that targets MacOS systems. The latest variant of Banshee uses a string encryption algorithm that is the same as the one used in Apple’s Xprotect antivirus engine for MacOS systems.
"FakePOC" Infostealer Masquerading as LDAPNightmare PoC Exploit
Jan 13, 2025 3:00:14 PM / by The Hivemind posted in Threat Bulletin, Infostealer, FakePOC, LDAPNightmare
Executive Summary
An infostealer, dubbed “FakePOC”, was recently observed masquerading as an LDAPNightmare proof of concept (PoC) exploit.
FireScam Android Malware
Jan 10, 2025 1:36:56 PM / by The Hivemind posted in Threat Bulletin, Android, Stealer, Spyware, FireScam
Executive Summary
FireScam is a sophisticated Android malware family that is disguised as a Telegram Premium app. It has both infostealer and spyware capabilities.
2024 Recap - Malware Hall of Fame
Dec 30, 2024 12:05:01 PM / by The Hivemind posted in Threat Bulletin, Malware, 2024 Recap