<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>malware families &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/malware-families/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Wed, 10 Aug 2022 16:51:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>malware families &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cyberattacks with LNK files on the rise in business environments</title>
		<link>https://bitfinance.news/en/cyberattacks-with-lnk-files-on-the-rise-in-business-environments/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Fri, 12 Aug 2022 12:00:55 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[States & entities]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[files with shortcuts]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[LNK]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware families]]></category>
		<category><![CDATA[Wolf Security Threat Insights report]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=84818</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="950" height="534" src="https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Aumentan ciberataques con archivos LNK en entornos empresariales" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques.jpg 950w, https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques-300x169.jpg 300w, https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques-768x432.jpg 768w" sizes="(max-width: 950px) 100vw, 950px" /></div><p>HP has noted, in its latest global HP Wolf Security Threat Insights report on real-world cyberattacks, that the most common attacks are via files with shortcuts (LNK). In fact, they have become the most used method to threaten businesses and companies. The technology company points out that there has been a wave of cyberattacks whose [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/cyberattacks-with-lnk-files-on-the-rise-in-business-environments/">Cyberattacks with LNK files on the rise in business environments</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="950" height="534" src="https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Aumentan ciberataques con archivos LNK en entornos empresariales" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques.jpg 950w, https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques-300x169.jpg 300w, https://bitfinance.news/wp-content/uploads/2022/08/Ciberataques-768x432.jpg 768w" sizes="(max-width: 950px) 100vw, 950px" /></div><p style="text-align: justify;">HP has noted, in its latest global <strong>HP Wolf Security Threat Insights report</strong> on real-world cyberattacks, that the most common attacks are via files with shortcuts <strong>(LNK)</strong>. In fact, they have become the most used method to threaten businesses and companies.</p>
<p style="text-align: justify;">The technology company points out that there has been a wave of<strong> cyberattacks</strong> whose protagonists are families of <strong>&#8216;malware&#8217; such as QakBot, IceID, Emotet and RedLine Stealer</strong>, using files with the <strong>nomenclature &#8216;.lnk&#8217;.</strong></p>
<p style="text-align: justify;"><strong>LNKs are Windows shortcut files</strong> that can contain malicious code and are used to abuse legitimate system tools, such as running<strong> Microsoft HTML application files.</strong></p>
<p style="text-align: justify;">According to HP, <strong>shortcuts are replacing Office macros</strong> as they require too much user intervention and risk alerts to overcome. Thus, shortcuts are a trap through which attackers trick their victims into infecting their PCs.</p>
<p style="text-align: justify;">This access to company systems can be used to steal relevant company information or sell it to <strong>ransomware groups</strong>, which can lead to large-scale breaches.</p>
<p style="text-align: justify;">It is not surprising then that, after carrying out an analysis, HP has verified an 11 percent increase in compressed files containing &#8216;malware&#8217;, among which those of the LNK type stand out.</p>
<p style="text-align: justify;">Specifically, it is common for attackers to place shortcut files in <strong>ZIP attachments</strong>, in order to evade email security scanners in business environments.</p>
<p style="text-align: justify;">In addition, the research team has detected LNK malware creators available for purchase on hacker forums, making it easier for cybercriminals to opt for this technique of executing malicious code.</p>
<p style="text-align: justify;">In this sense, HP Wolf Security has pointed out the identification of several<strong> &#8216;phishing&#8217; campaigns</strong> that used emails that pretended to be regional postal services. Among them, those warned in <strong>the run-up to Expo 2023 in Doha</strong>, when <strong>cybercriminals</strong> used the sending of massive HTML files to carry out their attacks.</p>
<p style="text-align: justify;">Separately, HP has exposed another case where attackers took advantage of the flaw created by the zero-day vulnerability in the <strong>Microsoft Support Diagnostic Tool (MSDT), also called &#8216;Follina&#8217;,</strong> to distribute OakBot, Agent Tesla and the<strong> Remcos RAT remote access Trojan</strong> before a patch was available.</p>
<p style="text-align: justify;">Likewise, a new execution technique has been identified that spreads the S<strong>VCReady malware</strong> in the shellcode hidden in documents. This campaign stands out precisely because of the unusual way in which it is distributed to PCs.</p>
<h2 style="text-align: justify;">The number of malware families grows</h2>
<p style="text-align: justify;">HP has highlighted other conclusions reached in this analysis and has pointed out that threat actors used a <strong>greater number of &#8216;malware&#8217; families</strong> in their attempts to infect organizations (593 compared to 545 in the quarter previous).</p>
<p style="text-align: justify;">Likewise, the technology company has put the focus on new malicious file formats used to evade detection, since its collected data indicates that 14 % of email malware evaded at least one gateway scanner. by email.</p>
<p style="text-align: justify;">HP has also highlighted that <strong>69 % of detected malware</strong> was sent <strong>via email,</strong> while web downloads were responsible for <strong>17 % of cyberattacks.</strong> Likewise, it has pointed out that the most common phishing scams were transactions such as<strong> &#8216;Order&#8217;, &#8216;Payment&#8217;, &#8216;Purchase&#8217;, &#8216;Request&#8217; and &#8216;Invoice&#8217;.</strong></p>
<p style="text-align: justify;"><em>Click the link to subscribe for free to our news and media group on Telegram: </em><a href="https://t.me/G_ELSUMARIO_News" target="_blank" rel="noopener"><em>https://t.me/G_ELSUMARIO_News</em></a></p>
<p style="text-align: justify;">Source: dpa</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/cyberattacks-with-lnk-files-on-the-rise-in-business-environments/">Cyberattacks with LNK files on the rise in business environments</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
