The Shelby Strategy
The SHELBY malware family exploits GitHub for command-and-control operations, employing sophisticated techniques to evade detection. The malware consists of a loader (SHELBYLOADER) and a backdoor (SHELBYC2), both obfuscated using Obfuscar. SHELBYLOADER employs various sandbox detection methods and uses GitHub for initial registration and key retrieval. SHELBYC2 communicates with the attacker's infrastructure using GitHub API, allowing for file uploads, downloads, and command execution. The campaign targets Iraqi telecommunications and potentially UAE airports, utilizing highly targeted phishing emails. Despite its sophistication, the malware's design has a critical flaw: anyone with the embedded Personal Access Token can control infected machines, exposing a significant security vulnerability.
Pulse ID: 67ebfcac2fcbc0b80399f243
Pulse Link: https://otx.alienvault.com/pulse/67ebfcac2fcbc0b80399f243
Pulse Author: AlienVault
Created: 2025-04-01 14:48:12
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Reminder: #iOS18.4 now available - be sure to disable #AppleIntelligence once you update
Delivering Trojans Via ClickFix Captcha
A new social engineering technique exploiting ClickFix Captcha has emerged as an effective method for delivering various types of malware, including Quakbot. This technique deceives users and bypasses security measures by utilizing a seemingly harmless captcha. The process involves redirecting users to a ClickFix captcha that tricks them into executing a malicious command on their local machine. The command downloads and executes obfuscated PowerShell scripts, which then retrieve and deploy the actual malware payload. The attackers use sophisticated obfuscation techniques, including fake ZIP files and PHP-based droppers, to evade detection and analysis. This method's success lies in exploiting user trust in captchas and legitimate-looking websites, increasing the likelihood of unknowing malware execution.
Pulse ID: 67ebfca624fc8265928a8775
Pulse Link: https://otx.alienvault.com/pulse/67ebfca624fc8265928a8775
Pulse Author: AlienVault
Created: 2025-04-01 14:48:06
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
Versión 3.5.0 de BetterDisplay, aplicación para sacarle el máximo partido a nuestras pantallas en macOS: https://www.dekazeta.net/foro/files/file/3670-betterdisplay/
Mit der gestrigen #Update-Flut für das #iPhone, #iPad und den #Mac hat #Apple nicht nur zahlreiche neue Features für unterstützte Apple-Geräte freigegeben – darunter auch erstmals #AppleIntelligence-Funktionen wie #Genmoji, #ImagePlayground und Schreibwerkzeuge in Deutschland – sondern auch so einige #Sicherheitslücke|n geschlossen. Keine davon soll aber wirklich aktiv ausgenutzt worden sein.
Alle Infos: https://www.appgefahren.de/?p=376617