this post was submitted on 22 Feb 2024
5 points (100.0% liked)

Cybersecurity

5984 readers
182 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

Cisco Talos researchers have reported an alarming rise in banking malware campaigns exploiting Google Cloud Run, with evidence of spread from Latin America to Europe and North America. The attacks, which began in September 2023, involve phishing emails with themes like invoices or tax documents, sometimes impersonating local tax agencies. These emails contain links to malicious Cloud Run web services that deploy banking Trojans such as Astaroth, Mekiotio, and Ousaban. Attackers use evasion techniques like geoplugin to avoid detection. The Astaroth variant has targeted over 300 institutions in 15 Latin American countries, primarily from Brazil. No specific CVEs are mentioned.

IOCs: https://github.com/Cisco-Talos/IOCs/blob/main/2024/02/google-cloud-run-abuse.txt

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here