Efimer steals cryptocurrency, hacks WordPress, and sends spam

📟 News

Date: 12/08/2025

Kaspersky Lab experts have observed a wave of attacks using the Efimer Trojan. The malware spreads via compromised WordPress sites, torrents, and email. Its primary goal is to steal and substitute cryptocurrency wallet addresses, but with additional scripts the threat also brute-forces passwords to WordPress sites and collects databases of email addresses for subsequent spam campaigns.

Read full article →


Paper Werewolf Group Exploits WinRAR Vulnerabilities for Attacks

📟 News

Date: 09/08/2025

In July and early August 2025, the espionage hacking group Paper Werewolf attacked several organizations from Russia and Uzbekistan. The phishing emails had RAR archives attached, supposedly containing important documents, but in reality, they included malware. The attackers exploited two vulnerabilities in WinRAR, which allow the installation of malicious software when the archive is unpacked.

Read full article →