ADVERTISEMENT
Sunday, April 26, 2026
No Result
View All Result
The AZB More Than Just News
  • HOME
  • Latest News
  • Business
  • PAKISTAN
  • SPORTS
  • WORLD
  • E-Paper
  • SCI-TECH
  • BANKING
  • ARTICLES
  • OPINION
  • MORE
    • MOBILE
    • TELECOM
    • PERSONALITY
    • HEALTH / EDUCATION
  • HOME
  • Latest News
  • Business
  • PAKISTAN
  • SPORTS
  • WORLD
  • E-Paper
  • SCI-TECH
  • BANKING
  • ARTICLES
  • OPINION
  • MORE
    • MOBILE
    • TELECOM
    • PERSONALITY
    • HEALTH / EDUCATION
No Result
View All Result
Daily The Azb
No Result
View All Result
Home Business

Kaspersky uncovers global malicious campaign targeting fintech users through Telegram.

News Desk by News Desk
November 8, 2024
Kaspersky uncovers global malicious campaign targeting fintech users through Telegram.
Share on FacebookShare on Twitter

November 08, 2024 : Kaspersky Global Research and Analysis team (GReAT) has uncovered a malicious global
campaign in which attackers used Telegram to deliver Trojan spyware, potentially targeting individuals and businesses in the fintech and trading industries in multiple countries across Europe, Asia including Pakistan, Latin America, and the Middle East. The malware is designed to steal sensitive data, such as passwords, and take control of users’ devices for espionage purposes. The campaign is believed to be linked to DeathStalker, an infamous hack-for-hire APT (Advanced Persistent Threat) actor offering specialized hacking and financial intelligence services. In the recent wave of attacks observed by Kaspersky, threat actors attempted to infect victims with DarkMe malware – a remote access Trojan (RAT), designed to steal information and execute remote
commands from a server controlled by the perpetrators. Deathstalker, previously known as Deceptikons, is a threat actor group active since at least 2018, and potentially since 2012. The group’s primary goal is collecting business, financial and private personal information, possibly for competitive or business intelligence purposes serving their clientele. They typically target small and medium businesses, financial, fintech, law firms, and on a few occasions, governmental entities. Despite going after these types of targets, DeathStalker has never been
observed stealing funds, which is why Kaspersky believes it to be a private intelligence outfit.
“Instead of using traditional phishing methods, threat actors relied on Telegram channels to deliver the
malware. In earlier campaigns, we also observed this operation using other messaging platforms,
such as Skype, as a vector for initial infection. This method may make potential victims more inclined
to trust the sender and open the malicious file than in the case with a phishing website. Additionally,
downloading files through messaging apps may trigger fewer security warnings compared to standard
internet downloads, which is favourable for the threat actors,” explains Maher Yamout, Lead Security
Researcher from GReAT. “While we typically advise vigilance against suspicious emails and links, this
campaign highlights the need for caution when dealing even with instant messaging apps like Skype
and Telegram.” The infection chain analysis reveals the attackers were most likely attaching malicious archives to
posts in Telegram channels. The archives themselves, such as RAR or ZIP files, were not malicious,
but they contained harmful files with extensions like .LNK, .com, and .cmd. If potential victims
launched these files, it leads to the installation of the final-stage malware, DarkMe, in a series of
actions. In addition to using Telegram for malware delivery, the attackers improved their operational security
and post-compromise cleanup. After installation, the malware removed the files used to deploy the
DarkMe implant. To further hinder analysis and try to evade detection, perpetrators increased the
implant’s file size and deleted other footprints, such as post-exploitation files, tools, and registry keys,
after achieving their goal. The group also has an interesting tendency to attempt to avoid attribution of their activities by mimicking other APT actors and incorporating false flags. For personal security, Kaspersky recommends to Install a trusted security solution and follow its recommendations. Organizations are advised to provide InfoSec professionals with in-depth visibility into cyberthreats targeting organizations of their sector. The latest Kaspersky Threat Intelligence will supply them with rich and meaningful context across the entire incident management cycle and help to identify cyber risks in time. With practically-oriented Kaspersky Expert training, InfoSec professionals can advance their hard skills and be able to defend their companies against
sophisticated attacks. They can choose the most appropriate format and follow either self-guided,
online courses or trainer-led live courses. To protect the company against a wide range of threats, use
solutions from Kaspersky Next product line that provide real-time protection, threat visibility,
investigation and response capabilities.

Advertisements
News Desk

News Desk

Welcome to our web desk! We're a dedicated team of digital enthusiasts passionate about delivering timely and engaging content to our online audience.

Related Posts

Field Marshal Asim Munir Meets Iranian FM Abbas Araghchi in Islamabad to Discuss Regional Situation
Headline

Field Marshal Asim Munir Meets Iranian FM Abbas Araghchi in Islamabad to Discuss Regional Situation

April 25, 2026
Pakistan Successfully Launches Indigenous EO-3 Satellite, Marking Major Step in Space Technology
Headline

Pakistan Successfully Launches Indigenous EO-3 Satellite, Marking Major Step in Space Technology

April 25, 2026
PLL Accepts $18.4/mmBtu LNG Bid from TotalEnergies Amid Supply Disruptions and Power Shortfall
Business

PLL Accepts $18.4/mmBtu LNG Bid from TotalEnergies Amid Supply Disruptions and Power Shortfall

April 25, 2026
Iran FM Araghchi Meets Field Marshal Asim Munir in Islamabad as Pakistan Hosts Renewed US-Iran Diplomacy
Headline

Iran FM Araghchi Meets Field Marshal Asim Munir in Islamabad as Pakistan Hosts Renewed US-Iran Diplomacy

April 25, 2026
Govt hikes petrol, high-speed diesel prices by Rs26.77 per litre
Business

Govt hikes petrol, high-speed diesel prices by Rs26.77 per litre

April 24, 2026
Animal Therapy Brings Fleeting Joy to War-Traumatized Children in Gaza as Risks from Unexploded Ordnance Persist
Headline

Animal Therapy Brings Fleeting Joy to War-Traumatized Children in Gaza as Risks from Unexploded Ordnance Persist

April 24, 2026
Islamabad Becomes Emerging Diplomatic Hub as Iran–US Backchannel Talks Gain Momentum Amid Regional Tensions
Headline

Islamabad Becomes Emerging Diplomatic Hub as Iran–US Backchannel Talks Gain Momentum Amid Regional Tensions

April 24, 2026
Indonesia Promotes West Java Investment Summit 2026 to Strengthen Economic Ties with Pakistan
Business

Indonesia Promotes West Java Investment Summit 2026 to Strengthen Economic Ties with Pakistan

April 24, 2026
Faysal Bank receives Recognition at the 13th Annual CSR Summit & Awards.
Business

Faysal Bank Posts Rs 5.2 Billion Profit in Q1 2026, Declares 15% Dividend

April 24, 2026
No More SIM Swaps: Meezan Bank’s Visa Infinite Card Now Comes with Complimentary Visa Global eSIM
Business

Meezan Bank Posts Rs 23.4 Billion Profit in Q1 2026, Declares 75% Interim Dividend

April 24, 2026
Next Post
Justice Department Announces Murder-For-Hire and Related Charges Against IRGC.

Justice Department Announces Murder-For-Hire and Related Charges Against IRGC.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Most Popular

Indus Motor Company declares profit after tax of PKR 5.1 billion.

KP Power Reset: Bureaucratic Empire Shaken at the Top. 

Malik Khuda Bakhsh Meeting Between Humayun Khan, Additional Secretary NEECA on EV Charging Stations

Karachi Receives Widespread Rainfall as Authorities Issue High Alert

Murtaza Wahab Inaugurates Recycled Plastic Road by English Biscuit Manufacturers in Karachi

Must Read

Meta Hosts Ramzan Bazaar to Celebrate #MonthofGood in Pakistan
Business

Meta Hosts Ramzan Bazaar to Celebrate #MonthofGood in Pakistan

March 1, 2025
Prime Minister Shahbaz Sharif visited the residence of Sharjeel Inam Memon.
Business

Prime Minister Shahbaz Sharif visited the residence of Sharjeel Inam Memon.

January 8, 2025
The Azb is a 24/7 online news platform that covers a wide range of topics including business, economics, technology, finance, travel, fashion, and lifestyle.

Quick Links

  • Home
  • About us
  • SCI-TECH
  • Live TV
  • Banking

Useful Links

  • Videos
  • Reviews
  • Advertorial
  • Photos
  • About us
  • Author
  • Home
  • Latest News
  • Partner
  • Privacy Policy
  • Russian Theatre Group Celebrates Fifth Anniversary in Pakistan.
  • Terms and Conditions
  • The Azb – More Than Just News
  • Contact

© Copyright 2024 theazb. All Rights Reserved.

No Result
View All Result
  • HOME
  • Latest News
  • Business
  • PAKISTAN
  • SPORTS
  • WORLD
  • E-Paper
  • SCI-TECH
  • BANKING
  • ARTICLES
  • OPINION
  • MORE
    • MOBILE
    • TELECOM
    • PERSONALITY
    • HEALTH / EDUCATION

© Copyright 2024 theazb. All Rights Reserved.