- Gone Phishing
- Posts
- New Jupyter Infostealer Malware Resurfaces with Tricky Tactics π¦
New Jupyter Infostealer Malware Resurfaces with Tricky Tactics π¦

Welcome to Gone Phishing, your daily cybersecurity newsletter that wishes cyberattacks only happened βNow and thenβ π #NewBeatles ππΈποΈ
Todayβs hottest cybersecurity news stories:
πͺ Watch out! βJupyterβ malware ups its game stealthy infostealer π€π
ππ² N. Korea criminals βBlueNoroffβ blamed for macOS hack-attack π¨βπ»
π Ransomware attackers leak 5 Canadian hospitalsβ patientsβ data π₯
Men Are From Mars, Malware Is From Jupyter πͺ
π¨ New Jupyter Infostealer Malware Resurfaces with Tricky Tactics π¦
The Jupyter Infostealer, also known as Polazert, SolarMarker, and Yellow Cockatoo, is back with sneaky "simple yet impactful changes." π» Researchers from VMware Carbon Black uncovered this dangerous malware's latest tactics.
π Initial Access: Jupyter tricks users with manipulated SEO tactics and malvertising to download it from dubious websites. π
π What Does It Do?
Harvests Credentials π€
Establishes Encrypted Command-and-Control Communication π
Executes Arbitrary Commands βοΈ
π Latest Updates:
The malware now uses certificates to make itself appear legitimate, but it's a disguise! Fake installers launch the infection chain, connecting to a remote server using PowerShell. π±
π Evolving Threats:
Other malware, like Lumma Stealer and Mystic Stealer, have been updated to include loaders for more devious attacks, including ransomware. π
π Constant Evolution:
Jupyter Infostealer has updated its network communication and gained popularity among cybercriminals. It now distributes other malware like RedLine, DarkGate, and GCleaner using its loader functionality. π
πΎ More Malware:
Keep an eye out for Akira Stealer and Millenium RAT, equipped with various features for data theft. The world of cyber threats is constantly changing! π
π€ Proxy Botnet Alert:
PrivateLoader and Amadey malware have infected thousands of devices with a proxy botnet called Socks5Systemz. 𧦠This botnet turns infected machines into proxies for anonymity. π°
π Where Are the Threat Actors?
The actors behind these attacks may be of Russian origin, given the lack of infections in the country. π»ββοΈ
Stay safe online! πͺ Update your security tools and stay vigilant. π‘

Cybersecurity is more important than ever, and your Mac or PC are no exception. Over time, your Mac or PC can accumulate junk files, malware, and other threats that can slow it down and make it vulnerable to attack.
That's where MacPaw comes in. MacPaw offers a suite of easy-to-use apps that can help you clean, optimize, and secure your Mac. With MacPaw, you can:
Remove junk files and malware to free up space and improve performance
Protect your privacy by erasing sensitive data
Optimize your startup settings to speed up boot times
Manage your extensions and apps to keep your Mac or PC running smoothly
Since 2008 MacPaw is trusted by over 30 million users worldwide, and it's the perfect solution for keeping your Mac or PC safe and secure.

Kim Jong Un: When Iβm called off, I grab the Noroff. Squeeze the trigger and macbooks get hauled off π«πͺππΏππ

π¨ North Korea's BlueNoroff Unleashes macOS Malware: ObjCShellz Strikes π₯οΈπ£
The notorious BlueNoroff, also known as APT38 and more, linked to North Korea, is behind a new macOS malware named ObjCShellz.
π§ What You Need to Know:
Part of the RustBucket malware campaign πΌ
Likely delivered via social engineering π€―
Used in multi-stage attacks π₯
π΅οΈββοΈ How It Works:
ObjCShellz, written in Objective-C, is a remote shell for executing commands from an attacker's server. π
π― Potential Targets:
It's suspected that this malware targets companies in the cryptocurrency industry or those closely related. βΏ
π Cyber Threats Evolve:
North Korea-sponsored groups like Lazarus, to which BlueNoroff is linked, are constantly evolving and sharing tactics and tools. π
π« Stay Vigilant:
While it's a simple malware, it's highly functional. Keep your cybersecurity tools updated! πͺ
Watch out for more macOS malware campaigns as these threat actors adapt and expand their reach. π π«π¦

π£ Catch of the Day!! πππ¦
π The Motley Fool: βFool me once, shame on β shame on you. Fool me β you can't get fooled again.β Good olβ George Dubya π Let us tell whoβs not fooling around though; thatβs the CrΓΌe π at Motley Fool. Youβd be a fool (alright, enough already! π) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! π Kidding aside, if you check out their website theyβve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets π€ (LINK)
π΅ Wander: Find your happy place. Cue Happy Gilmore flashback ποΈβ³πποΈ Mmmm Happy Placeβ¦ π So, weβve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itβs easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ποΈπ (LINK)
π Digital Ocean: If you build it they will come. Nope, weβre not talking about a baseball field for ghosts βΎπ»πΏ (Great movie, to be fair π). This is the Digital Ocean whoβve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youβll find yourself catching the buzz even if you canβt code (guilty π). But if you can and youβre looking for somewhere to test things out or launch something new or simply enhance what youβve got, weβd recommend checking out their services foβ sho π And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! πΏ (LINK)

Guess they werenβt bluffing, eh? πππ
π¨ Data Breach Alert: 5 Canadian Hospitals Hit by Ransomware π₯
π± In a major security breach, patient and employee data from five Canadian hospitals have been stolen and leaked online due to a ransomware attack.
π¨ Hospitals Impacted:
Bluewater Health
Chatham-Kent Health Alliance
Erie Shores HealthCare
HΓ΄tel-Dieu Grace Healthcare
Windsor Regional Hospital
Plus, service provider TransForm Shared Service Organization
π Shared Drive Compromised:
A shared drive was breached as part of this incident, leading to the exposure of sensitive information.
π₯ Data Stolen:
Bluewater Health suffered the most significant impact, with approximately 5.6 million patient visits and some employee data stolen.
Chatham-Kent Health Alliance had employee information compromised, including names, addresses, social insurance numbers, and more.
Erie Shores HealthCare patients' information and employee social insurance numbers were also stolen.
Limited patient and employee data was accessed for Windsor Regional Hospital and HΓ΄tel-Dieu Grace Healthcare.
π No Banking Info Compromised: Fortunately, no banking information was stolen in the attack.
π Ongoing Investigation:
All hospitals are actively working to identify affected individuals and the extent of employee data compromised. The Ontario Information and Privacy Commissioner has been notified.
π¦ Ransomware Gang Claims Responsibility:
While the threat actor remains unnamed, the Daixin ransomware gang has claimed responsibility and posted allegedly stolen data online, including thousands of personally identifiable and protected health information records.
π Cybersecurity Warning:
Last year, the US cybersecurity agency CISA and the FBI warned about the risks associated with the Daixin ransomware.
Stay vigilant! π«π»π‘οΈ Itβs unclear at this juncture whether any or all of the affected hospitals straight up refused to pay the hackerβs ransom or never even had the chanceβ¦ Goes to show, you canβt negotiate with cyber-terrorists β οΈβ οΈβ οΈ
Reminds us of the old scorpion and the frog fable π¦πΈ Screwing people over is in these hackersβ very nature even if it means they wind up losing out.
Anyway, on that bombshell: till next time homies βοΈ

ποΈ Extra, Extra! Read all about it!
Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!
The GeekAI: A daily 3 min newsletter on what matters in AI, with all the new AI things coming to market its good to stay ahead of the curve.
Libby Copa: The Rebel Newsletter helps writers strengthen their writing and creative practice, navigate the publishing world, and turn their art into an act of rebellion.
Techspresso: Receive a daily summary of the most important AI and Tech news, selected from 50+ media outlets (The Verge, Wired, Tech Crunch etc)
Let us know what you think!
So long and thanks for reading all the phish!
Give us a rating? |


