Information-stealing malware

Information-stealing malware campaigns are running rampant in 2024, used in many different campaigns to steal infected users’ browser information, cookies, saved credentials, credit cards, and cryptocurrency wallets.

These stolen credentials are then used to breach corporate networks, bank accounts, cryptocurrency exchanges, and email accounts. Unfortunately, for those who become infected with an infostealer, it can lead to devastating financial losses as threat actors steal cryptocurrency and access victims’ bank accounts. The best way to prevent these types of attacks is to enable two-factor authentication with an authenticator app on all accounts that offer the protection.

FrostyGoop

FrostyGoop malware is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.

Backmydata ransomware

Backmydata ransomware targets Remote Desktop Protocol (RDP) vulnerabilities, including weak credentials. Upon gaining a foothold, Backmydata establishes persistence, disables firewalls, encrypts, and exfiltrates data. It also deletes backups to prevent victims from restoring their systems without paying the ransom. It was linked to the Romanian hospitals attack in Feb 2024.

CryptoLocker

CryptoLocker is a Trojan horse that infects your computer and then searches for files to encrypt. This includes anything on your hard drives and all connected media — for example, USB memory sticks or any shared network drives. In addition, the malware seeks out files and folders you store in the cloud. Only computers running a version of Windows are susceptible to Cryptolocker; the Trojan does not target Macs.