LIVE · cybersecurity feed
Live wire

evasion news

4 stories
clickfix

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Recent reports indicate a significant evolution in ClickFix attack methodologies, with cybercriminals now employing more sophisticated techniques to mask their malicious payloads. The updated tactics reportedly involve the use of DNS TXT records and browser cache pre-fetching, strategies designed to make the early detection of these threats considerably more difficult for security systems and…

phishinghigh

Attackers conceal phishing lures using invisible Unicode characters

Threat actors have been observed employing an advanced phishing technique known as ASCII smuggling, which leverages invisible Unicode characters to bypass email security filters. This method, previously noted in AI prompt injection attacks, involves embedding Unicode characters from the Tags block (U+E0000 to U+E007F) to obscure malicious instructions or keywords.

ransomwarehigh

Akira Ransomware Uses Safe Mode to Bypass EDR

An Akira ransomware affiliate recently attempted to deploy ransomware on a victim's network by first rebooting the compromised host into Safe Mode with Networking, a tactic aimed at disabling endpoint detection and response (EDR) tools. While the maneuver successfully bypassed security controls, the ransomware itself failed to execute due to memory constraints within the stripped-down Safe…

malwarehigh

Malware Crypting Services Aid Threat Actors in Evading Detection

Cybersecurity researchers have identified a growing market for "crypting" services, which enable threat actors to modify malicious payloads to evade detection by antivirus (AV) and endpoint detection and response (EDR) tools. These services are becoming increasingly sophisticated, offering a range of features beyond basic encryption to complicate analysis and preserve malware usability.