Initial compromise with Nnice ransomware enables not only the exfiltration of credentials, web session cookies, and emails and the identification of security software but also the escalation of privileges, attainment of boot-level persistence, and encryption of files with the “.xdddd” extension, according to an investigation by the CYFIRMA Research and Advisory team.
Related Posts
Additional Pegasus spyware-hit devices identified
New infections of NSO Group’s Pegasus spyware have been discovered by mobile threat hunting firm iVerify across seven of 2,500…
Abuse of Cloudflare domains for phishing doubled in 2024, report says
Phishing campaigns leveraging Cloudflare domains more than doubled between 2023 and 2024, Fortra revealed in a report published Monday. Cloudflare’s…
Solana private key exfiltration facilitated by illicit npm packages
Installation of Tanzeem or Tanzeem Update triggers a bogus chat page containing a “Start Chat” button, which when clicked would…