Decrypted: HomuWitch Ransomware

HomuWitch is a ransomware strain that initially emerged in July 2023. Unlike the majority of current ransomware strains, HomuWitch targets end-users – individuals – rather than institutions and companies. Its prevalence isn’t remarkably large, nor is the requested ransom payment amount, which has allowed the strain to stay relatively under the radar thus far. During…

Read More

Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day

Key Points Avast discovered an in-the-wild admin-to-kernel exploit for a previously unknown zero-day vulnerability in the appid.sys AppLocker driver.  Thanks to Avast’s prompt report, Microsoft addressed this vulnerability as CVE-2024-21338 in the February Patch Tuesday update.  The exploitation activity was orchestrated by the notorious Lazarus Group, with the end goal of establishing a kernel read/write…

Read More

From BYOVD to a 0-day: Unveiling Advanced Exploits in Cyber Recruiting Scams

Key Points Avast discovered a new campaign targeting specific individuals through fabricated job offers.  Avast uncovered a full attack chain from infection vector to deploying “FudModule 2.0” rootkit with 0-day Admin -> Kernel exploit.  Avast found a previously undocumented Kaolin RAT, where it could aside from standard RAT functionality, change the last write timestamp of…

Read More

GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining

Key Points Avast discovered and analyzed a malware campaign hijacking an eScan antivirus update mechanism to distribute backdoors and coinminers Avast disclosed the vulnerability to both eScan antivirus and India CERT. On 2023-07-31, eScan confirmed that the issue was fixed and successfully resolved The campaign was orchestrated by a threat actor with possible ties to…

Read More

Avast Q1/2024 Threat Report

Nearly 90% of Threats Blocked are Social Engineering, Revealing a Huge Surge of Scams, and Discovery of the Lazarus APT Campaign Foreword We’re pleased to present the latest edition of our report for the first quarter of 2024, which has been nothing short of eventful. Here are some highlights. Not all heroes wear capes. Just…

Read More

Predictions 2025: The Future of Cybersecurity Unveiled

The digital world is evolving at breakneck speed. In 2025, we’re set to witness transformative changes in cybersecurity that will redefine trust, security, and how we navigate our digital lives. Here’s what we see coming: AI Blurs Reality: Hyper-personalized AI experiences will raise questions about truth, ethics, and independent thought. Deepfake Evolution: Sophisticated forgeries will…

Read More

Gen Q3/2024 Threat Report

The third quarter threat report is here—and it’s packed with answers. Our Threat Labs team had uncovered some heavy stories behind the stats, exposing the relentless tactics shaping today’s threat landscape. Here’s what you need to know: 614% explosion in Scam-Yourself Attacks: Over 2 million users were protected from FakeCaptcha scams, where fake tutorials, phony…

Read More