Articles

Decrypted: Rhysida Ransomware
Avast Releases Rhysida Ransomware Decryptor In October 2023, we published a blog post containing technical analysis of the Rhysida ransomware. What we intentionally omitted in the blog

Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day
Zero-Day Exploit Powers Advanced Rootkit Key Points Avast discovered an in-the-wild admin-to-kernel exploit for a previously unknown zero-day vulnerability in the appid.sys AppLocker driver. Thanks

GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
Malware Campaign Exploiting Antivirus Updates Key Points Avast discovered and analyzed a malware campaign hijacking an eScan antivirus update mechanism to distribute backdoors and coinminers

Beyond espionage — how the Lazarus Group is reshaping cybersecurity threats
Cybercriminal organization transitions from espionage to exploitation, preying on individuals for financial gain Meet the Lazarus Group, also known as Hidden Cobra. The group is

Stay Alert: Beware of Scams Targeting Major Sports Fans
Rising threats during the world’s biggest sporting event call for increased awareness As the world’s most elite athletes gather for this summer’s competitions, cybercriminals are

Safeguarding Digital Freedom: How a Gen Discovery Helped to Protect Windows Users Everywhere
Gen identifies and helps fix a vulnerability exploited by a notorious hacker group, reinforcing global cybersecurity Gen Threat Labs recently uncovered and reported a major

The Spread of AI-Generated Disinformation
How deepfakes and AI-created content shape perceptions in today’s digital world As the digital landscape rapidly evolves, so do the risks associated with it. Among

Beware: Lumma Stealer Spreading via GitHub Comments
GitHub Users Targeted by Lumma Stealer Malware Campaign As attackers become increasingly innovative, they are beginning to leverage popular platforms more and more to spread

AliGater: Malvertising Chasing Users of Outdated Windows in Europe
Magniber ransomware and Lumma stealer are suspected Malvertising is one of the dark sides of pervasive advertising on the modern web that continues to retain

Evolution of Lazarus ‘FudModule – no longer (stand)alone’
In early June, we discovered a sample that was exploiting a new zero-day vulnerability within Winsock driver (CVE-2024-38193) to achieve local privilege escalation to deploy

Global Surge in Fake Captcha Attacks
How Fake Captcha Campaigns are Distributing Lumma Stealer Over the past four weeks, we’ve protected more than 1.4 million customers against attempts to distribute malware

How Elon Musk ‘Almost’ Made Me Rich: A TikTok Tale
A shocking encounter with a fake Elon Musk and tips to avoid social media scams On Instagram or TikTok, it’s common to receive follow requests

Part-Time Job Scams: A Growing Threat
Scammers Now Using Phone Calls to Initiate Fraudulent Schemes The promise of easy money can often be too tempting to ignore, especially when it arrives

Q2 2024 Cybersecurity Trends: Rising Threats from Ransomware, Social Engineering and Identity Theft
Discover the latest cyberthreats — social engineering, ransomware and identity theft — and learn how to protect yourself In today’s digital age, where cybersecurity concerns

Decrypted: Mallox ransomware
Researchers uncover flaw in Mallox ransomware, offering free file recovery for early victims Researchers from Avast have discovered a flaw in the cryptographic schema of

How a Skype notification turned into a costly lesson
A Cautionary Tale of Digital Deception Imagine you are enjoying your weekend when you suddenly get a notification. You check it out, and it turns

Glove Stealer: Leveraging IElevator to Bypass App-Bound Encryption & Steal Sensitive Data
A .NET malware, bypasses Chrome’s App-Bound Encryption, stealing data from browsers, crypto wallets, 2FA authenticators Key points: Glove Stealer is an information stealer written

Gen Q3/2024 Threat Report
2 Million Users Protected from Fake CAPTCHA Scams, Ransomware Risk Doubled, and Lumma Information Stealer Surges Eleven-Fold Foreword The Gen Q3/2024 Threat Report is

Predictions 2025: Navigating the Future of Cybersecurity
Exploring Tomorrow’s Threats, Today’s Solutions: Predictions for the Cybersecurity Landscape in 2025 Today, technology is deeply woven into our daily lives and is

Cybercriminals Actively Leveraging ChatGPT To Create And Refine Malicious Payloads
How ChatGPT Is Aiding Cybercriminals in Crafting Advanced Malware Scripts Clipboard Protection Reveals ChatGPT’s Role in Malware Attacks Attackers are constantly seeking innovative ways to