elhacker.NET(@elhackernet) 's Twitter Profile Photo

El popular editor de texto Notepad++ se ve afectado por el malware 'WikiLoader'

Secuestro de DLL

Atacantes modificaron librería plugins 'mimeTools.dll', para ejecutar código malicioso cada vez que se inicia el editor de texto
securityonline.info/popular-text-e…

El popular editor de texto Notepad++ se ve afectado por el malware 'WikiLoader'

Secuestro de DLL

Atacantes modificaron  librería plugins 'mimeTools.dll', para ejecutar código malicioso cada vez que se inicia el editor de texto
securityonline.info/popular-text-e…
account_circle
Smart Group Systems(@SmartGrpSystems) 's Twitter Profile Photo

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88ky

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88ky
account_circle
CTComp(@ct_comp) 's Twitter Profile Photo

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88kl

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88kl
account_circle
Cryptolaemus(@Cryptolaemus1) 's Twitter Profile Photo

- - .pdf > url > .zip > .js > .js > .dll

wscript Invoice_818493.js

wscript out.js

C:\Users\Admin\AppData\Local\Temp\npp.8.6.4.portable.x64\notepad.exe (sideload)👇

\npp.8.6.3.portable.x64\plugins\mimeTools.dll

(1/3) 👇

IOC's
github.com/pr0xylife/Wiki…

#WikiLoader - #TA544 - .pdf > url > .zip > .js > .js > .dll  

wscript Invoice_818493.js

wscript out.js

C:\Users\Admin\AppData\Local\Temp\npp.8.6.4.portable.x64\notepad.exe (sideload)👇

\npp.8.6.3.portable.x64\plugins\mimeTools.dll

(1/3) 👇

IOC's
github.com/pr0xylife/Wiki…
account_circle
Avinext(@Avinext) 's Twitter Profile Photo

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88kx

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88kx
account_circle
Virus Bulletin(@virusbtn) 's Twitter Profile Photo

Proofpoint researchers have identified a new sophisticated downloader they call WikiLoader. The malware contains interesting evasion techniques and custom implementation of code designed to make detection and analysis challenging. proofpoint.com/us/blog/threat…

Proofpoint researchers have identified a new sophisticated downloader they call WikiLoader. The malware contains interesting evasion techniques and custom implementation of code designed to make detection and analysis challenging. proofpoint.com/us/blog/threat…
account_circle
Memory Lane Computer(@MemoryLaneComp) 's Twitter Profile Photo

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88l0

Just released - HP's Q4 2023 Wolf Security Threat Insights Report. Q4 saw a 7% point rise in PDF threats compared to Q1 2023. We also saw malware, including WikiLoader, Ursnif and DarkGate, increasingly spread through PDF documents. Download: imptr.io/88l0
account_circle
Cryptolaemus(@Cryptolaemus1) 's Twitter Profile Photo

- - .pdf > url > .zip > .js > .js > .dll

wscript.exe Invoice-808.js

wscript.exe sso.js

C:\Users\Admin\AppData\Local\Temp\npp.8.6.4.portable.x64\notepad.exe (sideload)👇

\npp.8.6.3.portable.x64\plugins\mimeTools.dll

(1/3)👇

IOC's
github.com/pr0xylife/Wiki…

#WikiLoader - #TA544 - .pdf > url > .zip > .js > .js > .dll  

wscript.exe Invoice-808.js

wscript.exe sso.js

C:\Users\Admin\AppData\Local\Temp\npp.8.6.4.portable.x64\notepad.exe (sideload)👇

\npp.8.6.3.portable.x64\plugins\mimeTools.dll

(1/3)👇

IOC's
github.com/pr0xylife/Wiki…
account_circle
Cryptolaemus(@Cryptolaemus1) 's Twitter Profile Photo

- - .pdf > url > .zip > .js > .js > .dll

wscript Inv_03_20_2024.js

wscript confidential-legal.js

C:\Users\Admin\AppData\Local\Temp\npp.8.6.4.portable.x64\notepad.exe (sideload)👇

\npp.8.6.3.portable.x64\plugins\mimeTools.dll

IOC's
github.com/pr0xylife/Wiki…

#WikiLoader - #TA544 - .pdf > url > .zip > .js > .js > .dll

wscript Inv_03_20_2024.js

wscript confidential-legal.js

C:\Users\Admin\AppData\Local\Temp\npp.8.6.4.portable.x64\notepad.exe (sideload)👇

\npp.8.6.3.portable.x64\plugins\mimeTools.dll

IOC's
github.com/pr0xylife/Wiki…
account_circle
JAMESWT(@JAMESWT_MHT) 's Twitter Profile Photo

Too in -

'Invoice Reminder: Your payment to Allen&Overy LLP '
EML>PDF>url>zip>js>js>dll

⚠️zip Url
https[:]//infplaute[.]com/international-commercial

❇️Samples
bazaar.abuse.ch/browse/tag/Wik…

Too in #italy #WikiLoader - #TA544 #quickbooks

'Invoice Reminder: Your payment to Allen&Overy LLP '  
EML>PDF>url>zip>js>js>dll

⚠️zip Url 
https[:]//infplaute[.]com/international-commercial  

❇️Samples
bazaar.abuse.ch/browse/tag/Wik…
account_circle
CSIRT Financiero Asobancaria(@CSIRTFinanciero) 's Twitter Profile Photo

🔎 Se ha observado un nuevo downloader denominado WikiLoader que ha sido detectado en varias campañas dirigidas específicamente a organizaciones financieras en Italia. Este está relacionado con el actor de amenaza (TA) conocido como TA544.
👉 Más info: csirtasobancaria.com/sala-de-prensa…

account_circle