• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
a new wave of malware attack targeting organizations in south

A New Wave of Malware Attack Targeting Organizations in South America

You are here: Home / General Cyber Security News / A New Wave of Malware Attack Targeting Organizations in South America
September 20, 2021

A spam campaign delivering spear-phishing email messages aimed at South American businesses has retooled its tactics to involve a extensive selection of commodity remote accessibility trojans (RATs) and geolocation filtering to stay clear of detection, according to new study.

Cybersecurity firm Pattern Micro attributed the attacks to an highly developed persistent risk (APT) tracked as APT-C-36 (aka Blind Eagle), a suspected South America espionage group that has been lively because at minimum 2018 and formerly known for placing its sights on Colombian government establishments and corporations spanning economical, petroleum, and manufacturing sectors.

Mainly distribute by using fraudulent emails by masquerading as Colombian governing administration companies, these kinds of as the National Directorate of Taxes and Customs (DIAN), the infection chain commences when the information recipients open a decoy PDF or Word document that statements to be a seizure purchase tied to their lender accounts and simply click on a url which is been created from a URL shortener service like cort.as, acortaurl.com, and gtly.to.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“These URL shorteners are able of geographical targeting, so if a user from a region not focused by the risk actors clicks on the url, they will be redirected to a reputable site,” Pattern Micro scientists comprehensive in a report revealed previous 7 days. “The URL shorteners also have the capacity to detect the main VPN solutions, in which scenario, the shortened link potential customers the users to a authentic web-site rather of redirecting them to the destructive website link.”

Prevent Ransomware Attacks

Really should the victim meet the site standards, the person is redirected to a file hosting server, and a password-shielded archive is quickly downloaded, the password for which is specified in the email or the attachment, finally leading to the execution of a C++-based remote accessibility trojan referred to as BitRAT that 1st arrived to gentle in August 2020.

Various verticals, which includes government, fiscal, healthcare, telecommunications, and strength, oil, and fuel, are explained to have been impacted, with a bulk of the targets for the latest campaign situated in Colombia and a scaled-down portion also coming from Ecuador, Spain, and Panama.

“APT-C-36 selects their targets primarily based on area and most probable the money standing of the email recipient,” the researchers explained. “These, and the prevalence of the e-mail, lead us to conclude that the danger actor’s supreme target is financial obtain somewhat than espionage.”

Uncovered this short article interesting? Abide by THN on Fb, Twitter  and LinkedIn to study a lot more special material we put up.


Some areas of this short article are sourced from:
thehackernews.com

Previous Post: «irish dpc threatens probe over facebook’s ray ban smart glasses Irish DPC threatens probe over Facebook’s Ray-Ban smart glasses
Next Post: Infosecurity Magazine Autumn Online Summit 2021 – Last Chance to Register! Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.