Secplicity Blog - Malware

Cyber Crime Campaign for AppSuite PDF Editor

WatchGuard has recently received reports of a cyber crime campaign underway where a weaponized version of a free PDF editor software “AppSuite PDF Editor” has been distributed to multiple sites for users to unknowingly download and run on their systems. It has been made aware of that the threat…

Encrypted Client Hello

What is Encrypted Client Hello? Encrypted Client Hello (ECH) is a TLS protocol extension that encrypts the initial "Client Hello" message in the TLS handshake, concealing the domain name a user is trying to access from network observers, enhancing privacy and security. This article explains this TLS protocol extension and the impact it has on the content filtering settings on your network security devices.

AsyncRAT Phishing Campaign Targeting Hotel Staff

At the beginning of April, WatchGuard received a report from a customer in the hospitality business describing a new phishing campaign targeting their staff. The attack starts with the threat actor opening a reservation request with the hotel, which they then cancel by email, citing a bad review for…

Code Red (2001): The Worm That Defaced Websites

While the world was captivated by the first Harry Potter movie, cybercriminals were busy launching one of the first major web server worms. What Was Happening in the World: The 9/11 attacks in the United States profoundly shifted global security policies, increasing focus on cybersecurity and…

Dr Joseph L Popp Jr and The First-Ever Ransomware – The AIDS Trojan

Publication: Dr. Joseph L Popp Jr and The First-Ever Ransomware – The AIDS Trojan If you work in information security or the computer science field, there's a good chance you've heard of the first-ever ransomware – the AIDS Trojan. There's also a chance you know the basics of that story. An…