processes

AppWizard
March 9, 2025
A new malware targeting Android users on Telegram has been discovered, involving videos that conceal malicious code activated upon download. The malware, named EvilLoader, exploits how Telegram processes media files, misclassifying '.htm' files as videos, which allows HTML code to execute in a browser. This malware can lead to credential theft, private data loss, and the installation of banking trojans. It can bypass security measures by redirecting users to their browsers or prompting them to open files as HTML documents, executing malicious JavaScript that sends IP information to attackers. EvilLoader has evolved to check for sandbox environments and generate fake security warnings. Users are advised to update their Telegram app and be cautious with unfamiliar video files. Telegram has stated that the exploit does not indicate a flaw in their platform and has implemented a server-side fix for enhanced protection.
Winsage
March 9, 2025
Security researchers have identified a malware campaign targeting YouTubers to spread SilentCryptoMiner malware disguised as tools to bypass restrictions. Over 2,000 victims in Russia have been reported, with the actual number likely higher. The malware exploits Windows Packet Divert drivers, with over 2.4 million detections in the past six months. Threat actors issue copyright strikes to compel YouTubers to promote infected files, manipulating their reputations. One YouTuber with 60,000 subscribers linked to a malicious archive that was downloaded over 40,000 times. The infection starts with an archive containing a modified script that executes a malicious executable via PowerShell. If security software removes the file, users are prompted to disable their antivirus. The malware's infection chain is multi-staged, using a Python-crafted loader to retrieve payloads from specific domains. It employs anti-VM techniques, modifies defender exclusions, and stealthily mines cryptocurrencies while pausing during certain program activities. Security experts warn against using restriction bypass tools due to their association with malware distribution.
AppWizard
March 7, 2025
Mojang Studios announced that the Minecraft LIVE event will return on March 22nd, featuring exclusive insights from developers, new game content, and special movie content related to Minecraft. Details for the live stream will be available on Minecraft’s official website.
Winsage
March 7, 2025
Windows 11 Insider Preview Build 27808 has been released to the Canary Channel. There are no plans to release SDKs for the 27xxx series builds. A significant update to the Task Manager has been initiated, aligning CPU utilization metrics with industry standards, and a new optional CPU Utility column is available on the Details tab. Several fixes have been made, including resolving issues with popular games, printing bugs, blank search windows, Settings app crashes, inaccurate battery icon colors, and BitLocker performance. Known issues include a d3d9.dll crash affecting application launches and a warning for Copilot+ PCs transitioning to the Canary Channel regarding the loss of Windows Hello PIN and biometrics. Enhancements to the Microsoft Store include a new spotlight design and updates to the Downloads page. Insiders in the Canary Channel are reminded that builds may not correspond to specific releases and may evolve or be removed. A clean installation is required to exit the Canary Channel.
Winsage
March 7, 2025
Windows Insiders in the Canary Channel can download build 27808, which includes enhancements to CPU monitoring in Task Manager and various fixes for gaming, printing, search, graphics, BitLocker, and more. Notable updates include a change in how Task Manager calculates CPU utilization, aligning it with industry standards, and the introduction of an optional CPU Utility column on the Details tab. Fixes include: - Resolved a bug causing games like Roblox to crash upon launch. - Corrected a printing issue that triggered crashes in certain applications. - Fixed a glitch resulting in a blank search window in the taskbar. - Addressed a crash issue in Settings when adding a color profile. - Rectified inaccurate color displays in the battery icon. - Improved performance for loading BitLocker UI elements and fixed a looping issue with BitLocker. - Resolved an error with the Get-BitLockerVolume command. Known bugs include issues with Windows Hello PIN and biometrics for users transitioning from other channels, and ongoing investigations into a d3d9.dll crash affecting application launches.
Winsage
March 6, 2025
A malware campaign has emerged, exploiting the popularity of Windows Packet Divert drivers. The SilentCryptoMiner malware, disguised as legitimate tools, has affected over 2,000 victims in Russia. Cybercriminals manipulate YouTubers to share malicious links, with one YouTuber having 60,000 subscribers attracting over 400,000 views on infected videos. Compromised files were hosted on gitrok[.]com, with over 40,000 downloads. Attackers issue copyright strikes to content creators, threatening channel shutdowns to propagate malware. The infection begins with a modified script that executes an executable via PowerShell, using a Python-crafted loader to fetch the payload. SilentCryptoMiner, based on XMRig, mines various cryptocurrencies stealthily, employing techniques to evade detection and dynamically adjust its behavior. This campaign highlights the evolving tactics of cybercriminals, leveraging demand for bypass tools to distribute malware. Users are advised to be cautious when downloading tools from untrusted sources.
Search