Spyware isn’t going anywhere, and neither are its tactics
ID: 205d91ea-1d23-5c06-9d7a-bbe597f65f54
STIX ID: report--205d91ea-1d23-5c06-9d7a-bbe597f65f54
Feed Name: Cisco Talos
Talos reports a newly discovered, stealthy espionage campaign using a custom backdoor called "Zardoor" that has likely persisted since March 2021 and has been used to repeatedly exfiltrate data from at least one Islamic non-profit; Talos released detection signatures and encourages reporting and sharing of spyware detections. The bulletin also highlights active exploitation of Ivanti VPN vulnerabilities (including CVE-2024-21893) prompting a CISA disconnect directive, a zero-day in Apple Vision Pro that was patched, widespread commercial-spyware activity exploiting zero-days, and provides recent malware telemetry hashes and detection names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
