Zloader: Entailing Different Office Files

Zloader aka Terdot – a variant of the infamous Zeus banking malware is well known for aggressively using “.xls”, “.xlsx” documents as its initial vector to deliver its payload. Despite this, recently we have come across “.docm” file which is being used by Zoader family to perform its initial activity. This shows adversaries like to […]

Ransomware erupts supporting farmer protests

SARBLOH: A NEW RANSOMWARE THAT DOES NOT DEMAND MONEY

Quick Heal Security Labs came across a Ransomware named “SARBLOH RANSOMWARE”, which claims to support the ongoing farmers protests in the country. In this attack, a malicious document is being spread which downloads ransomware from the following URLs – hxxps://s3.ap-south-1.amazonaws.com/ans[.]video.input/transcode_input/profile16146815778005vw0qb.png hxxp://s3.ap-south-1.amazonaws.com/ans[.]video.input/transcode_input/profile16146815778005vw0qb.png The downloaded ransomware encrypts the files on the system with extension .sarbloh and shows […]

Protect yourself from UPI frauds

Five tips to stay away from UPI frauds

If there was one silver lining to the COVID-19 pandemic, it was the effect it had on India’s digital payment journey. According to the Chief Operating Officer of the National Payments Corporation of India (NPCI), the digitization of India’s payment landscape was accelerated by the pandemic. The number of Unified Payments Interface (UPI) transactions in […]

Malware smuggled through Cyberpunk 2077

Ransomware attacks erupt via Cyberpunk 2077

Cyberpunk 2077 has been one of the most anticipated releases in gaming history. In development since 2012 and plagued by delays, the action role-playing game’s much-awaited release in December 2020 was an event in its own right. While the game itself received mixed reviews, cybercriminals also took advantage of the huge hype surrounding the game. […]

Spear Phishing attacks siphon off Microsoft credentials

Spear Phishing targets Microsoft to amass large numbers of credentials

We observed a considerable uptick in Phishing Attacks during the COVID-19 pandemic. During our analysis, we came across a Spear Phishing Campaign targeting high-profile individuals for credential harvesting. The emails that we analysed link to fake login pages mimicking Office 365 logins for the victim organizations. Here is the technical analysis of a few of […]

Joker spyware creeps its way into Google Play Store.

Stay Alert, Joker still making its way on Google Play Store!

We recently came across 2 malicious Joker family malware applications on Google Play Store  — the company was quick to remove these malicious applications from their store based on our report. These two applications, namely “Easy QR Scanner” and “Free Translator” have more than 10k installs each. What is Joker Malware? Joker is spyware which […]