Sept. 19, 2023, 12:55 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


  • Cisco Talos recently discovered a new malware family we’re calling “HTTPSnoop” being deployed against telecommunications providers in the Middle East.

  • HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute that content on the infected endpoint.

  • We also discovered a sister implant to “HTTPSnoop” we’re naming “PipeSnoop,” which can accept arbitrary shellcode from a named pipe and execute …

actor backdoor calling cisco cisco talos devices drivers family http implants interface kernel kernel drivers malware middle east novel requests simple talos techniques telecommunications windows

Business Information Security Officer

@ Metrolink | Los Angeles, CA

Cyber Security Consultant

@ Cybit | Belfast, Northern Ireland, United Kingdom

Physical Operations Specialist, AWS Security Operations Center

@ Amazon.com | Herndon, Virginia, USA

Product Cybersecurity Officer (m/w/div.)

@ Bosch Group | Wien, Linz oder Graz, Austria

SC2023-003098 Security Risk Consultant 1 (NS) - WED 11 Oct

@ EMW, Inc. | Braine-l'Alleud, Wallonia, Belgium

Sr Power Design Engineer (Hardware - NetSec)

@ Palo Alto Networks | Santa Clara, CA, United States