December 02, 2021 Two flavors of Tor2Mine miner dig deep into networks with PowerShell, VBScript Using remote scripts and code, one variant can even execute filelessly until it gains administrative credentials. Threat Research
November 18, 2021 New ransomware actor uses password-protected archives to bypass encryption protection Calling themselves "Memento team", actors use Python-based ransomware that they reconfigured after setbacks. Threat Research
October 24, 2021 Node poisoning: hijacked package delivers coin miner and credential-stealing backdoor A hacked NPM account was used to deliver Linux and Windows Monero miners and Windows credential-stealing malware along with a popular node.js library. SophosLabs UncutThreat Research
October 12, 2021 Exchange Server, Windows Print Spooler get more patches in October’s Patch Tuesday SophosLabs UncutThreat Research
October 04, 2021 Atom Silo ransomware actors use Confluence exploit, DLL side-load for stealthy attack A new ransomware operator uses stealthy techniques, but borrows heavily from other players. SophosLabs UncutThreat Research
September 23, 2021 Phishing and malware actors abuse Google Forms for credentials, data exfiltration Threat Research
September 03, 2021 Conti affiliates use ProxyShell Exchange exploit in ransomware attacks Security OperationsThreat Research
September 01, 2021 Fake pirated software sites serve up malware droppers as a service Sites advertising "cracked" software packages lead into a network that serves up downloads full of malware instead. Threat Research
August 10, 2021 Microsoft pushes fixes for 44 more vulnerabilities in August Patch Tuesday update A publicly-disclosed remote Print Spooler exploit, and bugs in JScript and NFS, lead the list of the most concerning CVEs. SophosLabs UncutThreat Research