New “Stealc” Malware Builds on Prevalent Infostealers

On February 20, 2023, researchers with Sekoia.io reported the technical details of a new infostealer malware advertised for sale as “Stealc” by developers on dark web criminal forums. Context According to the report, “The threat actor presents Stealc as a fully featured and ready-to-use stealer, whose development relied on Vidar, Raccoon, Mars and Redline stealers.”…

Read More

Retail & Hospitality ISAC joins the CyberWire Podcast Network

Fulton, MD (February 22, 2023) —  CyberWire, an N2K Networks brand, and the Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) announced today that the organization’s podcast has joined the CyberWire Podcast Network. Already the leading audio network in the cybersecurity industry, CyberWire will expand its support to the retail and hospitality industry through…

Read More

Call for Speakers Now Open for the RH-ISAC Cyber Intelligence Summit

Vienna, VA (February 15, 2023) – The Retail and Hospitality Information Sharing and Analysis Center (RH-ISAC) is now accepting speaker submissions for the 2023 RH-ISAC Cyber Intelligence Summit. The event, which is the premier conference for retail and hospitality cybersecurity professionals, will bring together experts from across the industry to discuss the latest threats and…

Read More

Phishing Campaigns Targeting German and U.S. Organizations with Multiple Malware

On February 8, 2023, Proofpoint researchers reported multiple phishing campaigns targeting organizations in multiple industries in the U.S. and Germany. Context Proofpoint attributes the activity to the likely financially-motivated TA866, which they assess is a new threat group. The campaign is currently active and has been since at least October 2022. Technical Details The emails…

Read More

Prilex POS Malware Targeting Contactless Credit Card Transactions

Context Prilex has been active since at least 2014 and evolved from an automated teller machine (ATM) malware into a POS malware in 2016, primarily targeting Brazilian and South American retailers. In 2022, the malware evolved further, conducting fraudulent “GHOST transactions” using EMV cryptograms generated by payment cards during the payment process. In previous cases,…

Read More