Cybercriminals Use Malicious Memes that Communicate with Malware – TrendLabs Security Intelligence Blog

Steganography, or the method used to conceal a malicious payload inside an image to evade security solutions, has long been used by cybercriminals to spread malware and perform other malicious operations. We recently discovered malicious actors using this technique on memes. The malware authors have posted two tweets featuring malicious memes on October 25 and 26 via a Twitter account created in 2017. The memes contain an embedded command that is parsed by the malware after it’s downloaded from the malicious Twitter account onto the victim’s machine, acting as a C&C service for the already- placed malware. It should be noted that the malware was not downloaded from Twitter and that we did not observe what specific mechanism was used to deliver the malware to its victims.

Source: Cybercriminals Use Malicious Memes that Communicate with Malware – TrendLabs Security Intelligence Blog

Marriott’s breach response is so bad, security experts are filling in the gaps — at their own expense

Last Friday, Marriott sent out millions of emails warning of a massive data breach — some 500 million guest reservations had been stolen from its Starwood database. One problem: the email sender’s domain didn’t look like it came from Marriott at all. Marriott sent its notification email from “email-marriott.com,” which is registered to a third […]

Source: Marriott’s breach response is so bad, security experts are filling in the gaps — at their own expense