Advanced Espionage Malware “Stealth Soldier” Hits Libyan Firms

0
[ad_1]

The Stealth Soldier campaign marks the possible reappearance of a threat actor known as “The Eye on the Nile” since its last operation in 2019.

Check Point Research has recently uncovered a series of highly-targeted espionage attacks in Libya, shedding light on a previously undisclosed backdoor called Stealth Soldier. This sophisticated malware operates as a custom modular backdoor with surveillance functionalities, including file exfiltration, screen and microphone recording, keystroke logging, and stealing browser information.

The campaign, which appears to be targeting Libyan organizations, marks the possible re-appearance of a threat actor known as “The Eye on the Nile” since its last operation in 2019.

Advanced Espionage Malware "Stealth Soldier" Hits Libyan Firms

Stealth Soldier, an implant used in limited and targeted attacks, has shown active maintenance with the latest version, Version 9, compiled in February 2023. Check Point Research’s investigation began with the discovery of multiple files submitted to VirusTotal between November 2022 and January 2023 from Libya.

These files, named in Arabic, such as “هام وعاجل.exe” (Important and Urgent.exe) and “برقية 401.exe” (Telegram 401.exe), turned out to be downloaders for different versions of the Stealth Soldier malware.

The execution flow of Stealth Soldier starts with the downloader, which triggers the infection chain. Although the delivery mechanism of the downloader remains unknown, social engineering is suspected.

The malware’s infection process involves downloading multiple files from the Command and Control (C&C) server, including the loader, watchdog, and payload. These components work together to establish persistence and execute the surveillance functionalities.

First, the loader downloads an internal module called PowerPlus to enable PowerShell commands and create persistence. Then, the watchdog periodically checks for updated versions of the loader and runs it accordingly. Finally, the payload collects data, receives commands from the C&C server, and executes various modules based on the attacker’s instructions.

The victim’s information collected by the Stealth Soldier’s payload includes the hostname, username, drive list, and files within specific directories. The malware supports various commands, including directory listing, file upload, screenshot capture, microphone recording, keylogging, browser credential extraction, and PowerShell command execution. 

Check Point Research identified three different versions of Stealth Soldier (Versions 6, 8, and 9), each with slight variations in functionality, filenames, and persistence mechanisms.

Additionally, the investigation uncovered a set of phishing domains linked to the campaign, with some masquerading as websites belonging to the Libyan Ministry of Foreign Affairs.  The phishing domains, hosted on IP addresses associated with previous malicious activities, indicated a likely intention to conduct phishing campaigns.

Check Point Research also discovered similarities between this recent operation and the “Eye on the Nile” campaign, previously linked to government-backed bodies by Amnesty International and Check Point Research. The overlapping infrastructure suggests a possible connection between the two campaigns, indicating the persistence and adaptability of the threat actor behind them.

The Stealth Soldier malware campaign targeting Libyan organizations highlights the increasing sophistication of cyber espionage operations. The use of custom backdoors and advanced surveillance capabilities poses significant threats to targeted entities’ data security and privacy.

Detecting and mitigating advanced threats like Stealth Soldier requires a combination of proactive threat intelligence, user awareness, and effective security solutions to ensure a resilient defence against evolving cyber threats.

  1. Facebook removes accounts over iOS, Android malware
  2. Worok Hackers Hit Orgs, Govts in Asia, Middle East, Africa
  3. Russia used Triton malware to sabotage Saudi petro plant

[ad_2]
Source link

ASUS confirms that the Zenfone 10 will launch this month

0
[ad_1]

We have a bunch of new and exciting devices coming out to kick off the Summer. After following rumors about the Asus Zenfone 10, the company confirmed when this phone is going to launch. It’s going to be coming out later this month.

Winter is the Galaxy S season and Fall is the iPhone/Galaxy foldable/Pixel phone season. Right in the middle, we have summer, which is the time of year when we should expect the latest phones from companies like Nothing, Asus, Etc. That’s the case with the upcoming Zenfone 10, the latest flagship from computer company Asus.

The Zenfone 10 will launch later this month

Asus launches its ROG phones which are meant to be top-tier phones for hardcore Gamers. However, if you’re looking for your basic core Android smartphone experience, then the Zenfone should be the one for you. The latest iteration is the Zenfone 10, and ASUS just confirmed that it’s coming out on June 29th.

As for this phone’s specs, we have a ton of information about it. However, these are merely rumors at this point. You’ll want to take them with a grain of salt until the company launches the device.

Starting off with the display, this phone is expected to have a relatively small 6.3-inch full HD+ AMOLED  display. What’s neat is that it’s expected to run at 120Hz.

Moving on to the internals, rumors point to this phone using the Octa-Core Snapdragon 8 Gen 2 SoC. This could be backed up by an impressive 16GB of LPDDR5X RAM and 256GB/512GB of UFS 4.0 storage. It may come with a 5,000mAh battery with 67-watt fast charging.

As for the camera package, this phone is expected to have a 200-megapixel main camera that can record 8K video. This will make another phone to hit the market with a 200-megapixel camera.

Other specs include Android 13 out of the box running on top of Zen UI 10, dual SIM support, IP68 water and dust resistance, a 3.5mm headphone jack, Wi-Fi 6, and Bluetooth 5.3. Overall, this is going to be a very feature-rich phone with a lot to love.

We don’t know the price just yet, but FoneArena speculates that the phone could start at around $749 for the 16GB/256GB variant. There are just a few more weeks to wait before this phone launches.


[ad_2]
Source link

Bally Sports will probably lose 4 more MLB Teams after refusing to pay them

0
[ad_1]

Bally Sports’ parent-company, Diamond Sports Group or DSG, is currently in bankruptcy court. It is trying to restructure its deals with different sports teams – which it inherited from Fox when Disney bought Fox and had to sell off the Fox Sports RSNs.

However, during this time, Bally Sports has also not been paying the teams that they broadcast. That included 9 teams: Angels, Braves, Cardinals, Diamondbacks, Guardians, Padres, Rangers, Reds and Twins. However, last week, a judge ordered that they pay what they owe, or they will forfeit the TV rights to those teams.

Now, the company is considering not paying for four of these MLB teams. That’s the Twins, Diamondbacks, Guardians and Rangers. So it’s likely that these teams will be put onto MLB.TV for the rest of the year. That’s if Bally Sports does go through with this and doesn’t pay them.

Bankruptcy is getting messy for DSG

For DSG, bankruptcy is getting pretty messy, and when all is said and done, they may not have many teams left to broadcast. RSNs have had a tough time lately, with AT&T SportsNet shutting down their RSNs, and Bally Sports now in bankruptcy. It’s getting harder and harder for sports fans to watch their local teams.

However, local sports is expensive, and with so many people cutting the cord, it leaves RSNs like Bally Sports with less revenue for the teams they do broadcast. And of course, teams don’t want to lose Bally Sports or any other RSN, because they pay the teams a pretty large sum every few months. Those payments are what help make the crazy, historic contracts that some players receive.

There are sharks in the water, as others are looking to grab these RSNs from DSG. Like Scripps. Scripps believes that all local sports should be on free TV, also known as OTA channels. That’s how it should be, as it will get more and more people on-board to watching the games. Since they won’t have to pay $20 per month for a single team – like Bally Sports+ currently does.


[ad_2]
Source link

A dedicated YouTube Music App may be coming to more devices soon

0
[ad_1]

As we already reported, Siri on HomePod will soon gain support for YouTube Music, which means you will be able to tell Siri to play songs directly from YouTube’s streaming music service. However, it appears that Apple‘s HomePod won’t be the only device gaining support for the service.

As 9to5Google first reported, YouTube Music will soon be available on more devices, according to an unnamed source familiar with the matter. For example, the source claims that Google is planning to release a new YouTube Music app specifically for Apple TV. At the moment, there is no information on whether Google plans to release a separate YouTube Music app on Android TV as well, but we have our hopes up that we will see such an app on Android TV too.

9to5Google’s source also claims that a dedicated YouTube Music app is also coming to Garmin smartwatches. At the moment, Garmin smartwatch users have access to Spotify, Deezer, and Amazon Music through the Connect IQ store, and it’s great news that YouTube Music subscribers will also be able to listen to their favorite songs directly from their favorite Garmin smartwatch.

The source also informed the publication that a dedicated YouTube Music app is coming to other wearables as well, but they did not specify which ones. There is also no information on when Google plans to release the YouTube Music app on Apple TV and Garmin smartwatches.

We are excited to see that Google is planning to make the YouTube Music app available to more and more devices. A lot of people are using the streaming service, and having a dedicated app always makes the user experience better.

[ad_2]
Source link

Nothing OS 2.0 might look wildly different from version 1.0

0
[ad_1]

From a hardware standpoint, the Nothing phone (1) really sticks out. From the software standpoint, by stark contrast, there’s nothing notable about it. However, XDA Developers was able to have a conversation with Mladen M. Hoyss, the software creative director at Nothing, and he has some interesting news to tell us about the software coming up. Nothing OS 2.0 is said to look very different from the first-generation software.

Hoyss spoke about why the software was so derivative of stock Android. The software and its overall aesthetic look very similar to Android 11, and that seems pretty odd. We were looking for a wild and completely different Android experience. The truth of the matter is that Nothing was working with a very limited team of people with Nothing for OS 1.0.

There were about five people on the team with additional third-party contractors. So, it seemed that the company needed to keep things relatively simple.

However, Nothing OS 2.0 might look very different

The Nothing Phone (1) was popular enough to warrant a second iteration, and that means more people to work on the software. Hoyss said that the team ballooned to over a hundred people, and the company is able to bring a refreshing change to the software. We’re expecting the software to look very different from the first iteration, and we’re all excited.

While we have no visual on Nothing OS 2.0, Hoyss described the driving mentality behind the software. The thing is, Hoyss believes that your phone’s home screen is underutilized in Android. It’s just a screen full of “company logos.” However, the home screen can be used in a much different manner.

It seems that the company wants to surface more core functionality on the home screen. So, you won’t have to leave your home screen to dig in and find certain functions that should be accessible readily. We’re not quite sure what he means by that, but it appears that the company wants to have functionality accessible on a more at-a-glance basis.

This might remind you of the At a Glance widget on pixel devices. However, Hoyss mentioned that the company is going to put its own spin on it. That’s great news to hear, as we are always looking forward to things that are new and refreshing in the tech world. Many Android OEMs tend to stick with a near-stock Android look, While others take Android in a wildly different Direction.

We’re all excited about Nothing OS 2.0 and the Nothing Phone (2). It’s set to launch sometime in July, so there’s not much more time to wait.


[ad_2]
Source link

How to check Air Quality (AQI) on Android and iPhone

0
[ad_1]

With the recent wildfires in Canada having pushed the smoke down into the US, there’s been a lot of news lately about just how bad the air quality has been along the east coast. From Chicago all the way to New York City, and it’s only starting to move further south. Recently, the AQI in New York City was well over 400. The scale only goes to 500, and once it hits 300, it’s dangerous to be outside. So that tells you just how bad it’s been lately.

So, how can you check the air quality around you? It’s actually quite easy, and today, we’re going to show you how to do this on both Android and iOS.

How to check Air Quality on Android

The easiest way to check the AQI on Android is by opening Google Maps.

Once you’ve opened Google Maps, tap on the Layers button.

Now at the bottom, you’ll see an option for “Air Quality”. This is a new feature for Google Maps, and couldn’t have come at a better time.

Screenshot 20230608 100025

Now, you’ll see the AQI for your area, and you can also zoom out to see what it looks like elsewhere.

How to check Air Quality on iPhone

Google Maps on iOS also allows you to check the Air Quality. So you can follow the same steps above to check on the iPhone. But you can also use the Weather App.

Typically, when the air is very unhealthy, it’ll show a card at the top with the AQI, and show that it might be “unhealthy for sensitive groups”.

IMG 0017

If you’re not in an area where the air quality is that bad, you might not see it at the top, but it will be shown towards the bottom of the screen as another card along with the sunrise/sunset, humidity and other factors.

That’s how you can check the Air Quality Index for your area on both Android and iPhone.


[ad_2]
Source link

YouTube Music update to include a carousel in Now Playing

0
[ad_1]

YouTube Music might have abandoned its old revamp, but it could still be working on changes to the Now Playing interface. Interestingly enough, pictures that surfaced on Reddit show a new and updated version of the music app, which promises a ton of spanking-new buttons. One of them is a carousel.

What changes can users expect with the rumored new redesign? For one, the top corner doesn’t feature “Playing from,” which was first introduced in the now-abandoned mid-November redesign. The album cover now takes up slightly more space on the interface. Plus, the rounded corners are much more prominent than before.The video/song switcher, and overflow menu, alongside the Cast button, remain largely the same. The artist/song name is aligned left on the new interface, just like in the now-ditched YouTube Music Now Playing redesign on Android. And then, there’s the carousel.

Without a doubt, the most exciting new feature is a carousel of actions. It allows users to download, share, and save their favorite songs easily. The existing thumb up/down buttons are kept, but now they don’t appear on either end of the song name. Instead, they’re united in a separate section on the farthest left of the carousel, just below the song/artist name.

In case you missed it, the now-dumped Now Playing update, initially launched by YouTube Music for Android devices in mid-November, was ditched at the beginning of this year. Expectedly, the old design was returned to Now Playing for Android smartphones afterward.


There’s one thing a specific audience has been demanding for some time that’s still missing from Now Playing. We are talking about a live lyrics function, which, sadly, isn’t included in this update. In comparison, both Spotify and Apple Music apps have live lyrics. When (and if) users get to enjoy this particular extra is yet to be determined.


[ad_2]
Source link

Clop ransomware gang threatens BBC, Boots and BA

0
[ad_1]

Ransomware gang Clop, who was responsible for a cyber attack on data transfer service MOVEit, has issued a threat to all those affected by the breach.

The attack on MOVEit directly led to a data breach affecting payroll services provider Zellis, as the company uses MOVEit as a third-party provider. This exposed the data for over 100,000 employees from a number of companies including the British Broadcasting Company (BBC), health and beauty retailer Boots and UK airline British Airways. This data includes all data employees will have provided for payroll purposes including their names, home and email addresses, dates of birth, UK National Insurance number, bank details and phone number.

The threat, which was issued via the dark web, tells the companies affected to contact the ransomware group by June 14 or their data will be posted online. According to the BBC, a victim of the cyber attack, the post addressed the others affected by the attack: “This is [sic] announcement to educate companies who use Progress MOVEit product that chance is that we download [sic] a lot of your data as part of [sic] exceptional exploit.”  
The post went on to urge victims to contact the gang via their darknet portal to begin a negotiation for the release of their or their fellow employee’s data.

Usually, ransomware demands are sent directly to victims rather than requesting victims get in touch. This unusual action has prompted some speculation on why Clop would proceed in this way, with Amir Hadžipasić, CEO of cyber security software company SOS Intelligence, telling the BBC that he predicts that the malicious actors “just have so much data that it is difficult for them to get on top of it all” and that they are “betting” on victims contacting them.

Only employees who work for local or national government or the police services may be safe from the attack, with Clop addressing them directly. The ransomware gang told these employees to “not worry”. They continued, saying “we erased your data you do not need to contact us. We have no interest to expose [sic] such information”. The legitimacy of this statement has been called into question, however.

The cyber attack on MOVEit and Zellis

The cyber attack against MOVEit saw Clop exploit of a critical vulnerability in MOVEit’s infrastructure. This allowed the malicious actors to break into multiple company networks and steal data. 

The vulnerability was flagged by security researchers and the US government on June 1. The US Cybersecurity and Infrastructure Security Agency (CISA) urged all MOVEit clients to check for indications that malicious actors had gained unauthorized access to their networks over the past 30 days and to download and install the software patch released by MOVEit to address the issue.  

On June 5, a third-party user of MOVEit, Zellis, issued a statement to its users that MOVEit had been the victim of a cyber attack. The payroll services company explained that this had lead to a “small number of [its] customers [were] impacted by this global issue”, meaning their employee data had been breached.

Once Zellis became aware of the attack, the company disconnected its server that utilizes MOVEit software and engaged an external cyber security company to conduct a forensic investigation into the cyber attack and to further monitor its systems. The Information Commissioner’s Office (ICO), the Data Protection Commission (DPC) and the National Cyber Security Center (NCSC) in both the UK and Ireland have also been contacted regarding the cyber security incident

Find out more about the dangers of ransomware in our exclusive guide to malware.


[ad_2]
Source link

Guardz Launches AI-Powered Multilayered Phishing Protection To Secure SMEs – Latest Hacking News

0
[ad_1]

[TEL AVIV, Israel, June 8, 2023] – Guardz, the cybersecurity company securing and insuring SMEs, today announced a new AI-powered Multilayered Phishing Protection solution to help small and medium-sized enterprises (SMEs) and managed service providers (MSPs) prevent phishing attacks before their security is compromised. The hassle-free and cost effective solution uses AI to provide small businesses and the MSPs that support them with automatic detection and remediation capabilities to protect against phishing attacks – the number one threat they face. By combining email security, web browsing protection, perimeter posture, and awareness culture in one native solution, businesses can now efficiently safeguard against phishing threats, bolstering resilience and future-proofing their systems.

Ninety percent of all cyber attacks are initiated with phishing, which relies on social engineering to prey on human nature. Cybercriminals attempt to obtain sensitive information such as usernames, passwords, and credit card details by tricking recipients clicking on malicious links or providing personal information, which can then be used for identity theft, ransomware attacks, or other malicious activities. These attacks can result in data breaches, financial loss, and reputational damage to small businesses and even compromise the security of a business’s entire network, leading to the exposure of further confidential information.

Guardz’s new Multilayered Phishing Protection: continuously scans for all inbound traffic with its advanced anti-phishing email protection solution; initiates detection through AI-powered anti-phishing and anti-malware engines; removes risky emails from users’ inboxes and automatically sends them to quarantine; monitors internet browsing to detect potential phishing attempts and delivers real-time alerts to system admins to enable timely responses; and  provides ongoing, active cyber awareness training and tailored phishing simulations for employees, fostering a culture of caution and vigilance. Perhaps most importantly when dealing with phishing, the Guardz solution empowers every employee to behave in ways that support and strengthen the business’s cybersecurity posture.

“The proliferation of phishing attack as a service (AaaS) tools sold on the dark web is putting the SME ecosystem increasingly at risk. Our new AI-powered phishing protection solution provides SMEs and MSPs with a holistic and accessible solution to prevent the success of phishing attacks,” said Dor Eisner, CEO and Co-Founder of Guardz. “This is a significant addition to Guardz’s holistic cyber security offering for small businesses, ensuring that they can react to cyber risks in real time with swift remediations, but also be protected by cyber insurance for complete peace of mind – a true secure and insure approach.”

The Multilayered Phishing Protection enables MSPs to provide their SME customers complete protection across all potential phishing attack vectors. It does so by automatically scanning the perimeter posture, inbound email traffic and internet browsing, and by providing ongoing, tailored cyber awareness training and simulation for employees. The platform automatically verifies emails for authentication protocols including Domain-based Message Authentication, Reporting and Conformance (DMARC), Sender Policy Framework (SPF) and checks for malicious forwarding rules.

The new Multilayered Phishing Protection solution is available now from Guardz. For further details, please visit Guardz’s website: https://guardz.com/phishing-protection/

About Guardz

Guardz is a holistic cyber security and insurance solution designed for SMEs. Guardz’s solution continuously monitors businesses’ digital landscapes to protect their entire range of assets, enables them to react to cyber risks in real time with swift remediations, and provides cyber insurance for peace of mind.  Its all-in-one, affordable platform is on guard 24/7, and is easy to use for both in-house IT personnel and MSPs. With cutting-edge technologies stacked into a robust platform, Guardz was founded in 2022 by Dor Eisner and Alon Lavi along with a team of cyber and insurance experts who combine innovation, experience, and creativity to create a safer digital world for small businesses.

Media Contact

Allison Grey
Headline Media
[email protected]
US: +1 323 283 8176
UK: +44 203 807 4482
IL: +972 53 820 2606


[ad_2]
Source link

How to sign up for Bluesky

0
[ad_1]

There’s been a lot of hype around Bluesky as of late, and that’s because the platform has been able to get some big names on-board. That includes names like AOC and Chrissy Teigen, among others. Which brought Bluesky a lot of notability as of late. And a lot more interest in people getting invites to the platform. It was smart, but what Bluesky forgot is that these people aren’t going to use it that much. So now there’s over 100,000 people on Bluesky, but it seems pretty dead still.

That should change once more invites are sent out. But here’s how you can sign up for Bluesky.

What is Bluesky?

Bluesky is the latest social media platform aimed at competing with Twitter. It was founded by Twitter’s co-founder, Jack Dorsey, even before Elon Musk had bought Twitter. So you know it has someone behind it that knows what they are doing. So why did Dorsey start Bluesky? Well, he wanted to make a decentralized social media platform.

The idea with Bluesky and its AT Protocol is that you can take your Bluesky profile and account and use it anywhere. Using the same username, posts and profile picture across any other network that uses the Protocol. This might sound similar to what Mastodon is doing with ActivityPub. And that’s because it is, but with a different protocol. This is likely the future of social media.

How to sign up for Bluesky

To sign up for Bluesky, you’ll first need to get an invite code. The service is still invite only, and no one knows for how much longer.

Once you’ve gotten your invite code, head over to Bluesky’s website here. Or open the Bluesky app.

Then click on Sign up.

On this next page, you’ll be asked to enter your email address, and your invite code.

After the invite code has been confirmed, you’ll now be directed to add your username and password.

Then you’re all set. You’re signed up for Bluesky. It’s just that easy.

You probably noticed that there were a few things missing there, like setting your name and bio, picture, etc. You can head over to your profile and edit it from there.


[ad_2]
Source link