<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>trojan - Latest News &amp; Reviews</title>
	<atom:link href="https://www.thetechoutlook.com/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.thetechoutlook.com/tag/trojan/</link>
	<description>Daily Tech News, Interviews, Reviews and Updates</description>
	<lastBuildDate>Fri, 02 Sep 2022 16:44:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://www.thetechoutlook.com/wp-content/uploads/2019/09/cropped-favicon-1-150x150.png</url>
	<title>trojan - Latest News &amp; Reviews</title>
	<link>https://www.thetechoutlook.com/tag/trojan/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>US IT firms with New Malspam are being targeted by Snake Keylogger</title>
		<link>https://www.thetechoutlook.com/news/security/us-it-firms-with-new-malspam-are-being-targeted-by-snake-keylogger/</link>
					<comments>https://www.thetechoutlook.com/news/security/us-it-firms-with-new-malspam-are-being-targeted-by-snake-keylogger/#respond</comments>
		
		<dc:creator><![CDATA[Somya Agrawal]]></dc:creator>
		<pubDate>Fri, 02 Sep 2022 16:44:01 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[malspam]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=72425</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div>
<p>This week, a fresh malspam campaign that appears to be aimed at enterprise IT decision-makers made its way back into the threat landscape. On August 23, Bitdefender Antispam Labs learned about the email campaign delivering the notorious Snake Keylogger. It seems to mostly be aimed towards US users. The attack, which originated from IP addresses [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/us-it-firms-with-new-malspam-are-being-targeted-by-snake-keylogger/">US IT firms with New Malspam are being targeted by Snake Keylogger</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/09/Untitled-design-2022-09-02T215701.096-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p>This week, a fresh malspam campaign that appears to be aimed at enterprise IT decision-makers made its way back into the threat landscape. On August 23, Bitdefender Antispam Labs learned about the email campaign delivering the notorious Snake Keylogger. It seems to mostly be aimed towards US users. The attack, which originated from IP addresses in Vietnam, has already affected thousands of inboxes, according to Bitdefender telemetry.</p>
<p>Threat actors in this attack leverage the business portfolio of a reputed Qatari IT provider of cloud storage and security solutions to dupe potential victims into opening a malicious ZIP archive.</p>
<p>In the archive (ba8e072f51e1b944bfa3466da15cefa3), the software COMPANY PROFILE.exe (9df140013f2b8627f7ea911d9767acdc) installs the Snake Keylogger payload onto the system host of the victims. Data recorded is exfiltrated using SMTP.</p>
<p>Snake Keylogger, also known as 404 Keylogger, is a data thief that can record keystrokes from infected PCs, take screenshots, and copy data from clipboards. Additionally, it can monitor keyboard usage. The infamous credential-stealing software may be purchased on message boards and dark web marketplaces for just a few hundred dollars or less, depending on the level of service the consumer requires.</p>
<p>The majority of snake bites are financially motivated, and victims may also be subjected to other crimes including identity theft and fraud. The credential-stealing malware also poses a serious security concern for enterprises because of its ability to collect data and act as a spy tool. Threat actors might get access to high-level accounts as a result and carry out more harmful attacks on a company.</p>
<p>In the past, PDFs and Microsoft Office documents (Word and Excel) have been used in Snake assaults, making them particularly potent social engineering methods.</p>
<p>Cybercriminals running the campaign run the risk of putting their victims at major security and privacy risk, like data ransom and financial data exfiltration.</p>
<p>Use security tools to help protect yourself and your company from keylogger attacks, and always verify the origin and legality of correspondence before clicking any links or attachments. Install a security program on their devices, and make sure that two-factor (2FA) or multi-factor (MFA) authentication processes are used to safeguard accounts. These measures will prevent hackers from accessing accounts if your system is hacked.</p>
<p>Users of Bitdefender are shielded from the snake virus. Both the Bitdefender spam filter and the Bitdefender anti-spam technology have identified this spam campaign.</p>
<p>Our enterprise and consumer solutions both classify the attachment as a Trojan. GenericKD.61435093, and forbid its opening.</p>
<p>With Bitdefender Total Security and XDR, users and businesses receive the best anti-malware protection, threat detection, and response against e-threats across all major operating systems. Bitdefender security solutions provide real-time protection against e-threats like keyloggers or spyware, viruses, worms, Trojan horses, ransomware, and zero-day exploits to protect you and your data.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/us-it-firms-with-new-malspam-are-being-targeted-by-snake-keylogger/">US IT firms with New Malspam are being targeted by Snake Keylogger</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/security/us-it-firms-with-new-malspam-are-being-targeted-by-snake-keylogger/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New ransomware is added to the Advanced SOVA Android Banking Trojan</title>
		<link>https://www.thetechoutlook.com/news/security/new-ransomware-is-added-to-the-advanced-sova-android-banking-trojan/</link>
					<comments>https://www.thetechoutlook.com/news/security/new-ransomware-is-added-to-the-advanced-sova-android-banking-trojan/#respond</comments>
		
		<dc:creator><![CDATA[Somya Agrawal]]></dc:creator>
		<pubDate>Sat, 13 Aug 2022 15:08:10 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Cleafy]]></category>
		<category><![CDATA[computing]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[sova]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=68112</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div>
<p>The Android banking Trojan SOVA has returned with improved functionality, and a brand-new version with a ransomware module is now being created. Researchers at Cleafy, who saw the resurgence of SOVA, believe that Version 4 of SOVA targets more than 200 mobile applications, including banking apps and cryptocurrency exchanges/wallets. After the US and the Philippines, [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/new-ransomware-is-added-to-the-advanced-sova-android-banking-trojan/">New ransomware is added to the Advanced SOVA Android Banking Trojan</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-13T202105.412-768x432.jpg 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>The Android banking Trojan SOVA has returned with improved functionality, and a brand-new version with a ransomware module is now being created.</p>
<p>Researchers at Cleafy, who saw the resurgence of SOVA, believe that Version 4 of SOVA targets more than 200 mobile applications, including banking apps and cryptocurrency exchanges/wallets. After the US and the Philippines, Spain appears to be the country that the malware is targeting most frequently.</p>
<p>The SOVA v4 virus is included in fake Android applications that bear the logos of well-known services like Chrome and Amazon. The most recent version includes a refactored and improved cookie-stealer approach that can now specify a list of targeted Google services and other applications. The update also gives the malware the ability to protect itself by detecting and preventing users&#8217; attempts to uninstall the program.</p>
<p>The command-and-control (C2) interface in more current SOVA versions also allows attackers to seize control of specified targets. This increases the malware&#8217;s ability to adjust to a variety of attack scenarios. It also has tools that enable attackers to record instructions, capture screenshots, and run them. An attacker now has the chance to look for opportunities to switch to possibly more valuable systems or applications.</p>
<p>&#8220;The most fascinating component is connected to the [virtual network computing] capabilities,&#8221; the report claims. The fact that threat actors have been adding new features and functionalities to the malware since September 2021 is strong evidence that they are doing so. This capacity has been on the SOVA roadmap since that time.</p>
<p>Additionally, the Cleafy team found evidence that malware version 5, which will include a ransomware module that was first indicated in a September 2021 development plan, is currently under development.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/new-ransomware-is-added-to-the-advanced-sova-android-banking-trojan/">New ransomware is added to the Advanced SOVA Android Banking Trojan</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/security/new-ransomware-is-added-to-the-advanced-sova-android-banking-trojan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>This Android malware hid inside an app downloaded 50,000 times from Google Play Store</title>
		<link>https://www.thetechoutlook.com/news/apps/this-android-malware-hid-inside-an-app-downloaded-50000-times-from-google-play-store/</link>
					<comments>https://www.thetechoutlook.com/news/apps/this-android-malware-hid-inside-an-app-downloaded-50000-times-from-google-play-store/#respond</comments>
		
		<dc:creator><![CDATA[Yamini Sharma]]></dc:creator>
		<pubDate>Wed, 23 Feb 2022 12:48:20 +0000</pubDate>
				<category><![CDATA[Apps]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[trojan]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=39381</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3.png 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3-300x169.png 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3-1024x576.png 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3-768x432.png 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div>
<p>A new type of Android banking trojan malware has been downloaded by over 50,000 users in just a few weeks, targeting customers of 56 different European banks.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/apps/this-android-malware-hid-inside-an-app-downloaded-50000-times-from-google-play-store/">This Android malware hid inside an app downloaded 50,000 times from Google Play Store</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3.png 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3-300x169.png 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3-1024x576.png 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/02/Untitled-design-1-3-768x432.png 768w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></div><p>This malware first appeared this month, according to cybersecurity researchers at ThreatFabric, who dubbed it &#8216;Xenomorph&#8217; due to links to another trojan called Alien. The malware is intended to steal usernames and passwords in order to gain access to bank accounts and other sensitive personal information.</p>
<p>The malware, like many other types of Android malware, appears to be able to circumvent security measures and infiltrate smartphones via apps in the Google Play Store. One of the apps discovered was a cleaner app that promised to help a device speed up by removing unused clutter: the app has been downloaded over 50,000 times.</p>
<p>The app appeared to provide the functionality advertised, but it also delivered malware, which steals usernames and passwords via fake overlays that activate when the victim attempts to log in to banking apps. Because the overlay replaces the actual login screen, any information entered is sent to the attackers. Banks in Spain, Portugal, Italy, and Belgium are currently under attack. The malware also includes overlays capable of stealing passwords for email accounts and cryptocurrency wallets.</p>
<p>Xenomorph can intercept SMS and app notifications to help steal authentication needed to bypass multi-factor authentication. Researchers have linked Xenomorph to another Android trojan malware, Alien, because of design similarities. Both forms of malware use the same HTML resource page to trick victims into granting access to accessibility services. The researchers note that the malware still appears to be in the early stages of development as many commands present in the code aren&#8217;t active yet.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/apps/this-android-malware-hid-inside-an-app-downloaded-50000-times-from-google-play-store/">This Android malware hid inside an app downloaded 50,000 times from Google Play Store</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/apps/this-android-malware-hid-inside-an-app-downloaded-50000-times-from-google-play-store/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
