Malware

Botnet Exploits IoT Device Vulnerability

Threat actors are exploiting a critical flaw in the Realtek Jungle software development kit to deploy the Cling botnet with a novel STUN-based command-and-control channel. The malware repurposes standard internet protocols for covert communication.

The Hacker News · Dark Reading · Infosecurity Magazine · +1 more

PoeLLM Botnet Malware Compromises 3,400 Servers in Cryptomining Campaign

A new malware family dubbed PoeLLM has infected over 3,400 servers in a coordinated campaign to deploy cryptocurrency miners. The malware obscures its command infrastructure using encoded data hidden within a poem.

The Register · BleepingComputer · The Hacker News · +1 more

MALFEX Campaign Spreads RAT Malware Via NPM Packages

A sophisticated malware campaign called MALFEX has distributed eight malicious npm packages since August 2023, delivering information stealers and remote access trojans to thousands of developers in a long-running supply chain attack.

SecurityWeek · The Hacker News

New Linux Backdoor Exploits STUN Protocol Vulnerabilities

Security researchers discovered a sophisticated Linux backdoor that abuses the STUN protocol to infiltrate systems. The vulnerability affects dozens of systems and poses significant cybersecurity risks.

BSI CERT-Bund · SecurityWeek