S2 Group’s threat intelligence team has detected a covert spear phishing campaign utilizing Snake Keylogger, a credential-stealing malware developed in .NET and associated with Russian threat actors. This campaign specifically targets individuals in the logistics and energy sectors by taking advantage of rising tensions between Iran and Israel. Cybercriminals are impersonating Kazakhstan-based energy company LLP KSK Petroleum LTD Oil and Gas, distributing phishing emails that include ZIP files disguised as legitimate oil-related documents. These files contain malicious executables that exploit a newly observed method involving the legitimate Java debugger jsadebugd.exe, used in conjunction with InstallUtil.exe to execute DLL sideloading—an uncommon tactic not widely reported before. The phishing scheme builds credibility by referencing the risk of oil shortages and disruptions in global supply chains, particularly due to potential instability in the Strait of Hormuz. When a user opens the deceptive attachment, jsadebugd.exe is leveraged to sideload a tampered DLL, concrt141.dll, which activates the Snake Keylogger. This malware is capable of stealing credentials from web browsers, email and FTP clients, as well as extracting Windows product keys and sensitive personal files. The stolen data is then sent out through compromised SMTP accounts. Investigators have connected this activity to known threat actors like UAC-00411 and TA558, suggesting its use in a broader Malware-as-a-Service (MaaS) operation. To mitigate the threat, companies—especially those in high-risk industries—should deploy robust email filtering and inspect all attachments carefully. Security teams should watch for suspicious DLL sideloading behavior, particularly involving known tools like jsadebugd.exe. Regular cybersecurity training and up-to-date endpoint protection are also essential in defending against such advanced threats.
Cornwell Quality Tools, a prominent supplier of automotive and industrial tools, has confirmed a significant data breach that exposed the sensitive personal information of 103,782 ...
A critical security vulnerability, CVE-2025-10127, has been discovered in the Daikin Security Gateway. The flaw is a serious industrial control systems threat, especially in the en...
On September 9, 2025, Microsoft reported four significant security vulnerabilities in the Windows Defender Firewall Service CVE-2025-53808, CVE-2025-54104, CVE-2025-54109, and CVE-...