Emotet Resurgence: TrickBot Delivers the Loader Back
Ten months after its takedown, Emotet returned via a TrickBot module. The lesson: criminal franchises rebuild through partners.
Ten months after its takedown, Emotet returned via a TrickBot module. The lesson: criminal franchises rebuild through partners.
Attackers abused a misconfigured FBI notification system to spam fake cyber-warnings from the real fbi.gov address, exposing the limits of email trust.
Two months of undetected access to managed WordPress hosting, wholesale sFTP and database credential harvesting, and SSL keys in the bargain.
Popular packages with dormant maintainers pushed info-stealers through postinstall scripts. The registry was fine; the accounts were not.