Category: Threats
-
APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies
APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies Russian state-sponsored actors known as APT28 have initiated a sophisticated cyber espionage campaign targeting high-value government and military entities across Europe. The primary targets include maritime and transport organizations in nations such as Poland, Ukraine, and Turkey. The attackers are actively exploiting a critical vulnerability…
-
New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture
New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture A sophisticated new threat has surfaced in the wild, identified as the DesckVB RAT version 2.9. This modular Remote Access Trojan, built on the .NET framework, has been observed in active malware campaigns throughout early 2026. Unlike simple backdoors, this threat demonstrates a high level…
-
New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support Scam Kit
New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support Scam Kit A sophisticated new cyber threat has emerged within the digital advertising ecosystem, specifically targeting users through the vast reach of Facebook’s paid advertising platform. Malicious actors are increasingly weaponizing social media ads to bypass traditional security filters and deliver harmful…
-
Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands
Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands The cybersecurity landscape has darkened with the sophisticated evolution of the KongTuke campaign. Active since mid-2025, this threat actor group has continuously refined its techniques to bypass conventional enterprise security filters. Their primary weapon remains the “ClickFix” strategy, a social engineering vector that…
-
GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers
GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers GlassWorm has emerged as a serious threat to developers using the Open VSX Registry, where popular VSX extensions were silently turned into delivery vehicles for malware. Threat actors compromised a trusted publisher account and pushed poisoned updates that looked like routine releases but…
-
Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms
Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms Infostealer campaigns that once focused mainly on Windows are now expanding aggressively to macOS, using Python and trusted platforms to reach new victims. Recent attacks show a clear shift: threat actors are abusing online ads, fake apps, and familiar tools to quietly steal…
-
Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials
Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials Cybercriminals are launching a dangerous phishing campaign that tricks users into giving away their login credentials by impersonating Dropbox. This attack uses a multi-stage approach to bypass email security checks and content scanners. The threat actors exploit trusted cloud platforms and harmless-looking PDF files to…
-
Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware
Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection. The malicious application was cleverly hidden as a document reader, making it appear harmless to unsuspecting users searching for…
-
DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data
DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. The malware surfaced in December 2025 when security researchers detected its deployment at a Polish energy firm. Unlike typical ransomware that encrypts…
-
Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics
Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics The ShinyHunters threat group has expanded its extortion operations with sophisticated attack methods targeting cloud-based systems across multiple organizations. These cybercriminals use voice phishing and fake credential harvesting websites to steal login information from employees. Once they gain access, they extract sensitive data from…
-
UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS
UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active from late 2025 through early 2026, focuses primarily on victims in Thailand and…
-
175,000 Exposed Ollama Hosts Enable Code Execution and External System Access
175,000 Exposed Ollama Hosts Enable Code Execution and External System Access A significant security discovery reveals that approximately 175,000 Ollama servers remain publicly accessible across the internet, creating a serious risk for widespread code execution and unauthorized access to external systems. Ollama, an open-source framework designed to run artificial intelligence models locally, has become unexpectedly…
-
TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome
TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers. This malware operates as part of espionage campaigns conducted by APT42, an Iranian state-sponsored cyber-espionage group that has been…
-
Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed
Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed Security researchers have uncovered a sophisticated traffic distribution network leveraging deceptive education-themed domains to deliver malware and phishing attacks. The operation, tracked under infrastructure indicators pointing to TOXICSNAKE, uses legitimate-looking university and educational institution branding to deceive users into visiting malicious websites. This tactic exploits the…
-
Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5060+ Downloads
Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5060+ Downloads A dangerous malware campaign has infiltrated the Open VSX extension marketplace, compromising over 5,000 developer workstations through a fake Angular Language Service extension. The malicious package disguised itself as legitimate development tooling, bundling authentic Angular and TypeScript components alongside encrypted malware code that…
-
Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants
Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants Microsoft is preparing a major security shift for cloud email customers as Exchange Online moves toward deprecating SMTP AUTH Basic Authentication for all tenants. The change targets one of the oldest and weakest ways to sign in to email systems, where usernames and passwords…
-
Attackers Targeting Canadian Citizens by Exploiting Their Reliance on Digital Services
Attackers Targeting Canadian Citizens by Exploiting Their Reliance on Digital Services Attackers are increasingly targeting Canadian citizens by abusing their heavy dependence on online government and commercial services. From paying traffic fines and renewing licenses to tracking parcels and booking flights, people now expect these tasks to be quick and digital. Threat actors are taking…
-
Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors
Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors A Chinese national named Jingliang Su has been sentenced to 46 months in prison for his involvement in a major cryptocurrency fraud scheme targeting American investors. On January 27, 2026, federal courts ordered Su to serve his sentence and pay…
-
Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware
Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware A newly discovered campaign demonstrates a sophisticated approach to delivering information-stealing malware through a combination of social engineering and legitimate Windows components. The attack begins with a deceptive CAPTCHA prompt that tricks users into executing commands manually through the Windows Run dialog, presenting the…
-
HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer
HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer The HoneyMyte threat group, also known as Mustang Panda or Bronze President, continues to pose a significant risk to government organizations across Asia and Europe. Recent security research has revealed that this advanced hacker collective is actively upgrading its digital arsenal with enhanced…
-
Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files
Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files Caminho Loader is a new Loader-as-a-Service threat that blends steganography, fileless execution, and cloud abuse to quietly deliver malware across several regions. First seen in March 2025 and believed to originate from Brazil, this service hides .NET payloads inside harmless-looking image files hosted on…
-
APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware
APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware Advanced persistent threat actors operating from Pakistan have launched coordinated attacks against Indian government organizations using newly discovered tools and malware designed to bypass security defenses. The campaign, identified as Gopher Strike, emerged in September 2025 and represents a significant escalation in targeted cyber…
-
China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates
China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates Since 2023, a dangerous malware framework called PeckBirdy has emerged as a primary weapon used by Chinese-aligned hacking groups. This JavaScript-based tool serves as a command-and-control platform designed to work across multiple system environments, giving attackers remarkable flexibility in how they deploy their…
-
New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool
New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool A sophisticated phishing campaign active between November 2025 and January 2026 has been exploiting Vercel’s legitimate hosting platform to distribute remote access tools to unsuspecting victims. The attack chain combines social engineering with trusted domain exploitation, making it particularly effective at bypassing…
-
Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware
Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware Late December 2025 brought alarming news to Poland as its energy infrastructure became the target of what security experts describe as the country’s largest cyberattack in years. The Russian-aligned Sandworm group, known for orchestrating some of the most damaging attacks on critical infrastructure, emerged as…
-
20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation
20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation A critical backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor, a popular WordPress plugin used by more than 20,000 active sites. This security flaw allows attackers to create administrator accounts without any authentication, putting thousands of websites at risk…
-
North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams
North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams North Korea–aligned hackers have launched a new campaign that turns artificial intelligence into a weapon against software teams. Using AI-written PowerShell code, the group known as KONNI is delivering a stealthy backdoor that blends real project content with malicious scripts. This operation…
-
New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks
New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks A newly discovered ransomware family called Osiris launched attacks against a major food service company in Southeast Asia during November 2025. Security researchers have identified this threat as a completely new malware variant with no connection to an older…
-
New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature
New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature ClearFake has entered a new and more dangerous phase, turning a familiar fake CAPTCHA scam into a highly evasive malware delivery chain. Across hundreds of hacked websites, visitors now see what looks like a routine verification challenge, but behind the scenes…
-
Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware
Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware A large-scale campaign is turning a trusted Windows security driver into a weapon that shuts down protection tools before ransomware and remote access malware are dropped. The attacks abuse truesight.sys, a kernel driver from Adlice Software’s RogueKiller antivirus, and use more than 2,500 validly…
-
New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework
New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework The cybersecurity landscape has entered a dangerous new chapter with the discovery of VoidLink, the first documented advanced malware framework built almost entirely by artificial intelligence. Unlike earlier attempts where inexperienced hackers used AI to create basic malicious…
-
Attackers Leverages LinkedIn to Deliver Remote Access Trojan Targeting Corporate Environments
Attackers Leverages LinkedIn to Deliver Remote Access Trojan Targeting Corporate Environments A sophisticated phishing campaign is actively exploiting LinkedIn’s trusted social media platform to distribute a dangerous remote access trojan to corporate employees. Attackers are leveraging the professional credibility of LinkedIn to craft convincing messages that appear legitimate, making employees more likely to download and…
-
Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste
Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste A new clipboard hijacker is quietly draining cryptocurrency from gamers and streamers by abusing trust inside Discord communities. The campaign centers on a malicious Windows program shared as a supposed streaming or security tool. Once installed, it silently watches the user’s clipboard,…
-
Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data
Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data SolyxImmortal represents a notable advancement in information-stealing malware targeting Windows systems. This Python-based threat combines multiple data theft capabilities into a single, persistent implant designed for long-term surveillance rather than destructive activity. The malware operates silently in the background, collecting credentials, documents, keystrokes, and screenshots…
-
Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef
Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef A malvertising campaign identified in September 2025 has brought a significant threat to Windows users worldwide. Attackers created fake PDF editing applications and promoted them through Google Ads to distribute a dangerous information-stealing malware called TamperedChef. The malware targets users searching for appliance manuals…
-
CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings
CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings Cybersecurity researchers have discovered a sophisticated malware campaign using an unusual but effective tactic: deliberately crashing users’ browsers. The threat, named CrashFix, operates through a malicious Chrome extension disguised as the legitimate ad blocker NexShield. When users search for privacy tools online, malicious advertisements…
-
17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data
17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data Cybercriminals have distributed 17 malicious browser extensions across Chrome, Firefox, and Edge platforms, collectively downloading over 840,000 times and compromising user security for years. The GhostPoster campaign, which emerged as early as 2020, used deceptive extension names like “Google Translate in Right Click,”…
-
Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits
Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits Threat actors are increasingly using trusted cloud and content delivery network platforms to host phishing kits, creating major detection challenges for security teams. Unlike traditional phishing campaigns that rely on newly registered suspicious domains, these attacks use legitimate infrastructure from providers like Google, Microsoft…
-
Promptware Kill Chain – Five-Step Kill Chain Model for Analyzing Cyberthreats
Promptware Kill Chain – Five-Step Kill Chain Model for Analyzing Cyberthreats Large language models have become deeply integrated into everyday business operations, from customer service chatbots to autonomous agents managing calendars, executing code, and handling financial transactions. This rapid expansion has created a critical security blind spot. Researchers have identified that attacks targeting these systems…
-
Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers
Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers Threat actors linked to Chinese hosting infrastructure have established a massive network of over 18,000 active command-and-control servers across 48 different hosting providers in recent months. This widespread abuse highlights a serious issue in how malicious infrastructure can hide within trusted networks and…
-
Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure
Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure A sophisticated malware loader known as CastleLoader has emerged as a critical threat to US government agencies and critical infrastructure organizations. First identified in early 2025, this stealthy malware has been used as the initial access point in coordinated attacks targeting multiple sectors including federal…
-
Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems
Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. First seen in December 2023 on BreachForums, the group advertises stolen data and uses a dark web blog to pressure…
-
New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages
New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents an evolving challenge to online retail…
-
Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins
Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins Facebook users are increasingly becoming targets of a sophisticated phishing technique that bypasses conventional security measures. With over three billion active users on the platform, Facebook represents an attractive target for attackers seeking to compromise accounts and harvest personal credentials. The primary objective of…
-
AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection
AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection A recent AsyncRAT campaign is using Cloudflare’s free tier services and TryCloudflare tunnels to hide remote access activity inside normal looking cloud traffic. In these attacks, threat actors send phishing emails that link to a Dropbox hosted ZIP archive named to look like an…
-
ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details
ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details A new wave of attacks is using the ValleyRAT_S2 malware to quietly break into organizations, stay hidden for long periods, and steal sensitive financial information. ValleyRAT_S2 is the second-stage payload of the ValleyRAT family and is written in C++. Once inside a network, it…
-
Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware
Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware Cybersecurity threats continue to evolve with attackers using more creative social engineering techniques to target organizations. A recent threat has emerged involving the Guloader malware, which is being disguised as employee performance reports to trick users into downloading and executing malicious files. This sophisticated attack…
-
Everest Hacking Group Allegedly Claims Breach of Nissan Motors
Everest Hacking Group Allegedly Claims Breach of Nissan Motors Everest hacking group has allegedly claimed a major breach of Nissan Motor Co., Ltd., raising fresh concerns about data security at large automotive manufacturers. According to early reports, the cybercrime group says it exfiltrated around 900 GB of sensitive data from the Japanese carmaker, a volume…
-
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account Chinese threat actors have developed a dangerous new way to steal money directly from bank accounts using specially crafted Android applications. Known as Ghost Tapped, these malicious apps exploit Near Field Communication (NFC) technology, the same wireless technology that powers contactless payments.…
-
New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code
New ClickFix Attack Uses Fake Windows BSOD Screens to Trick Users into Executing Malicious Code A sophisticated malware campaign called PHALTBLYX has emerged, combining social engineering deception with advanced evasion techniques to compromise hospitality sector organizations. The attack chain begins with phishing emails impersonating Booking.com, featuring urgent reservation cancellation alerts with large financial charges displayed…
-
Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections
Threat Actors Hacked Global Companies via Leaked Cloud Credentials from Infostealer Infections Dozens of major global enterprises have been breached through a surprisingly simple yet devastating attack vector: stolen credentials extracted from infostealer malware. A threat actor operating under the nickname “Zestix” and his alias “Sentap” has been systematically accessing corporate cloud storage platforms, including…
-
Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes
Threat Actor Allegedly Claim Leak of NordVPN Salesforce Database with Source Codes A threat actor operating under the identifier 1011 has publicly claimed to have obtained and leaked sensitive data from NordVPN’s development infrastructure on a dark web forum. The breach reportedly exposes over ten database source codes, along with critical authentication credentials that could…
-
Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts
Handala Hackers Targeted Israeli Officials by Compromising Telegram Accounts In December 2025, the Iranian-linked hacking group Handala claimed to have fully compromised the mobile devices of two prominent Israeli political figures. However, detailed analysis by Kela cyber intelligence researchers revealed a more limited scope—the breaches targeted Telegram accounts specifically, not complete device access. The group…
-
RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware
RondoDoX Botnet Weaponizing a Critical React2Shell Vulnerability to Deploy Malware A sophisticated threat group has intensified its campaign against organizations by leveraging the latest vulnerabilities in web applications and Internet of Things (IoT) devices. The RondoDoX botnet, tracked through exposed command-and-control logs spanning nine months from March to December 2025, demonstrates a relentless approach to…
-
Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement
Potential Wallet Phishing Campaign Targets Cardano Users via ‘Eternl Desktop’ Announcement A sophisticated phishing campaign is currently circulating within the Cardano community, posing significant risks to users seeking to download the newly announced Eternl Desktop application. The attack leverages a professionally crafted email claiming to promote a legitimate wallet solution designed for secure Cardano token…
-
Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics
Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics After a decade of disappearing from the cybersecurity landscape, the Careto threat group, also known as “The Mask,” has resurfaced with sophisticated new attack methods targeting high-profile organizations. Security researchers have identified fresh evidence of Careto’s activity, revealing how the group…
-
Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users
Self-Propagating GlassWorm Weaponizing VS Code Extensions to Attack macOS Users A new wave of GlassWorm malware has emerged, marking a significant shift in targeting strategy from Windows to macOS systems. This self-propagating worm, distributed through malicious VS Code extensions on the Open VSX marketplace, has already accumulated over 50,000 downloads. The fourth wave introduces several…
-
New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks
New Cybercrime Tool ErrTraffic Let Attackers Automate ClickFix Attacks A dangerous cybercrime tool known as ErrTraffic has appeared in underground forums, making it easier for attackers to trick users into running harmful software on their devices. The tool automates what security experts call ClickFix attacks, where fake error messages push people to manually execute malicious…
-
DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware
DarkSpectre Hackers Infected 8.8 Million Chrome, Edge, and Firefox Users with Malware Researchers have uncovered DarkSpectre, a well-funded Chinese threat actor responsible for infecting over 8.8 million users across Chrome, Edge, and Firefox browsers through a series of highly coordinated malware campaigns spanning seven years. The discovery reveals a level of operational sophistication rarely seen…
-
Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation
Threat Actors Manipulating LLMs for Automated Vulnerability Exploitation Large Language Models (LLMs) have revolutionized software development, democratizing coding capabilities for non-programmers. However, this accessibility has introduced a severe security crisis. Advanced AI tools, designed to assist developers, are now being weaponized to automate the creation of sophisticated exploits against enterprise software. This shift fundamentally challenges…
-
Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass
Threat Actors Advertising AI-Enhanced Metamorphic Crypter with Claims of Windows Defender Bypass Dark web forums have become a marketplace for sophisticated malware tools, with threat actors continuously refining their capabilities to stay ahead of security solutions. The latest concerning development involves an emerging AI-powered crypter service that promises unprecedented evasion abilities, putting enterprise environments at…
-
Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows
Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. The attack demonstrates a significant…
-
Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims
Hackers Advertised VOID ‘AV Killer’ with Kernel-level Termination Claims The cybercriminal threat actor known as Crypt4You has recently emerged on underground forums and dark web marketplaces, advertising a sophisticated tool named VOID KILLER. This malicious software operates as a kernel-level antivirus and endpoint detection response (EDR) process killer, designed to evade and neutralize security defenses.…
-
EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack
EmEditor Editor Website Hacked to Deliver Infostealer Malware in Supply Chain Attack A major supply chain attack targeting EmEditor, a widely used text editor software, has exposed millions of users to sophisticated infostealer malware. Between December 19 and December 22, 2025, the official EmEditor website fell victim to unauthorized modification, serving compromised installer files to…
-
Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures Chinese threat actors operating under the name Silver Fox are targeting Indian organizations through sophisticated phishing campaigns that impersonate legitimate income tax documents. The attack campaign uses authentic-looking Income Tax Department emails to trick users into downloading a malicious executable disguised as a tax-related…
-
New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins A Spanish-speaking phishing operation targeting Microsoft Outlook users has been active since March 2025, using a sophisticated kit that shows clear indicators of AI-assisted development. The campaign, tracked through a unique signature of four mushroom emojis embedded in the string “OUTL,” has been…
-
Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks Public reports about cyberattacks often present a polished picture—threat actors working methodically through a well-planned playbook with every action perfectly executed. This perception leads many to believe that modern attackers operate with machine-like precision, seamlessly moving from one objective to another without facing obstacles. However,…
-
Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware
Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware The Evasive Panda APT group, also known as Bronze Highland, Daggerfly, and StormBamboo, has been running targeted campaigns since November 2022, using advanced techniques to deliver the MgBot malware. The group employs adversary-in-the-middle attacks combined with DNS poisoning to compromise specific victims across…
-
Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations
Threat Actors Using Weaponized AV-themed Word and PDF Documents to Attack Israeli Organizations Security researchers at Seqrite Labs have identified a campaign called Operation IconCat, targeting Israeli organizations with weaponized documents designed to look like legitimate security tools. The attacks began in November 2025 and have compromised multiple companies across information technology, staffing services, and…
-
Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass
Threat Actors Advertised NtKiller Malware on Dark Web Claiming Terminate Antivirus and EDR Bypass A malicious actor known as AlphaGhoul has begun promoting a tool called NtKiller, designed to silently shut down antivirus software and endpoint detection tools. The tool was posted on an underground forum where criminals gather to buy and sell hacking services.…
-
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users
WebRAT Malware via GitHub Repositories Claim as Proof-of-concept Exploits to Attack Users A new malware campaign has surfaced that uses GitHub repositories to spread the WebRAT malware by disguising it as proof-of-concept exploits and gaming utilities. The malware targets users searching for game cheats, pirated software, and application patches, particularly for popular titles like Rust,…
-
Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials
Malicious Chrome Extensions as VPN Intercept User Traffic to Steal Credentials Two fake Chrome extensions named “Phantom Shuttle” are deceiving thousands of users by posing as legitimate VPN services while secretly intercepting their web traffic and stealing sensitive login information. These malicious extensions, active since 2017, have been distributed to over 2,180 users through the…
-
Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan
Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan Researchers at Ontinue’s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access. The discovery reveals how sophisticated threat actors repurpose benign software to gain complete control over compromised systems while evading traditional security…
-
Hackers Using ClickFix Technique to Hide Images within the Image Files
Hackers Using ClickFix Technique to Hide Images within the Image Files Threat actors have evolved their attack strategies by combining the deceptive ClickFix social engineering lure with advanced steganography techniques to conceal malicious payloads within PNG image files. This sophisticated approach, discovered by Huntress analysts, represents a significant shift in how cybercriminals deliver information-stealing malware…
-
Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from $3,000 to $15,000 for Access or Data
Threat Actors are Hiring Insiders in Banks, Telecoms, and Tech from $3,000 to $15,000 for Access or Data Cyber criminals are changing their tactics by recruiting insiders within organizations instead of relying on traditional attack methods like brute force or social engineering. Recent findings show that employees in banks, telecom companies, and technology firms are…
-
BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service
BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service A new credential-harvesting campaign has been discovered targeting users of UKR.NET, a popular Ukrainian webmail and news platform. The attacks are linked to BlueDelta, a Russian state-sponsored hacker group also known as APT28, Fancy Bear, and Forest Blizzard. This group has been running…
-
Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data
Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data The Clop ransomware group has launched a new data extortion campaign targeting Internet-facing Gladinet CentreStack file servers, marking another chapter in the threat actor’s pattern of exploiting file transfer solutions. The campaign appears to leverage multiple security weaknesses in CentreStack and its sister product Triofox,…
-
China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware
China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware A sophisticated cyberespionage campaign targeting governmental entities in Southeast Asia and Japan has unveiled a new China-aligned threat actor dubbed LongNosedGoblin. Active since at least September 2023, this advanced persistent threat (APT) group distinguishes itself by leveraging a diverse toolset of custom C#/.NET malware families.…
-
Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide
Kimwolf Android Botnet Hijacked 1.8 Million Android Devices Worldwide A massive botnet targeting Android devices has emerged as one of the most significant threats in the cybersecurity landscape today. Named Kimwolf, this sophisticated malware has compromised approximately 1.8 million Android devices worldwide, including smart TVs, set-top boxes, tablets, and other Android-based systems. Security researchers discovered…
-
New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users
New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users A sophisticated new malware campaign dubbed “GhostPoster” has been uncovered, leveraging a clever steganography technique to compromise approximately 50,000 Firefox users. The attack vector primarily involves seemingly innocent browser extensions, such as “Free VPN Forever,” which conceal malicious payloads within their own interface icons.…
-
BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls
BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls In a sophisticated cyberespionage campaign, the BlindEagle threat actor has once again targeted Colombian government institutions. This latest operation specifically zeroed in on an agency under the Ministry of Commerce, Industry, and Tourism, leveraging a highly effective strategy to bypass standard email security…
-
APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators
APT-C-35 Infrastructure Activity Leveraged Using Apache HTTP Response Indicators A significant discovery in threat intelligence reveals that APT-C-35, commonly known as DoNot, continues to maintain an active infrastructure footprint across the internet. Security researchers have identified new infrastructure clusters linked to this India-based threat group, which has long been recognized as a state-sponsored actor with…
-
Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure
Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure A Russian state-sponsored hacking group has been targeting network edge devices in Western critical infrastructure since 2021, with operations intensifying throughout 2025. The campaign, linked to Russia’s Main Intelligence Directorate (GRU) and the notorious Sandworm group, represents a major shift in tactics. Instead of focusing…
-
New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number
New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number A newly discovered account takeover campaign targeting WhatsApp users demonstrates how attackers can compromise messaging accounts without stealing passwords or exploiting technical vulnerabilities. The threat, identified as the GhostPairing Attack, uses social engineering and WhatsApp’s legitimate device linking feature to grant attackers…
-
ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices
ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices Since December 2025, a concerning trend has emerged across Japanese organizations as attackers exploit a critical vulnerability in React/Next.js applications. The vulnerability, tracked as CVE-2025-55182 and known as React2Shell, represents a remote code execution flaw attracting widespread exploitation. While initial attacks primarily deployed cryptocurrency miners, security…
-
Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware
Ashen Lepus Hacker Group Attacks Eastern Diplomatic Entities With New AshTag Malware A Hamas‑affiliated threat group known as Ashen Lepus, also tracked as WIRTE, has launched a new espionage campaign against governmental and diplomatic entities across the Middle East. The group uses realistic Arabic‑language diplomatic lures that reference regional politics and security talks to trick…
-
Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer
Threat Actors Leverage ChatGPT to Attack Mac Devices With AMOS InfoStealer A new AMOS InfoStealer campaign is abusing trust in ChatGPT to infect Mac devices under the guise of simple troubleshooting help. Victims search for a fix to a sound problem, click a sponsored ChatGPT result, and are shown what looks like a normal chat…
-
Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File
Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File Security researchers have uncovered a significant threat targeting developers through the VS Code Marketplace. A coordinated campaign involving 19 malicious extensions has been actively infiltrating the platform, with the attack remaining undetected since February 2025. These deceptive extensions carry hidden malware in…
-
Shanya EDR Killer Leveraged by Ransomware Groups to Clear the Way for Ransomware Infection
Shanya EDR Killer Leveraged by Ransomware Groups to Clear the Way for Ransomware Infection The cybercriminal landscape has recently witnessed the aggressive rise of “Shanya,” a potent packer-as-a-service and EDR killer now fueling major ransomware operations. Emerging on underground forums in late 2024 under the alias “VX Crypt,” this tool was engineered to supersede previous…
-
ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos
ClayRat Android Malware Steals SMS Messages, Call Logs and Capture Victim Photos A dangerous new Android spyware variant called ClayRat has emerged as a significant threat to mobile device security worldwide. First identified in October by the zLabs team, this malware represents a concerning evolution in mobile threats with capabilities that allow attackers to gain…
-
Beware of Solana Phishing Attacks That Let Hackers Initiate Unauthorized Account Transfer
Beware of Solana Phishing Attacks That Let Hackers Initiate Unauthorized Account Transfer A dangerous new wave of phishing attacks is targeting Solana users by changing wallet ownership permissions rather than stealing private keys. A victim lost more than USD 3 million in a single attack, with an additional USD 2 million locked in investment platforms.…
-
Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code
Hackers Actively Exploiting Worpress Plugin Vulnerability to Execute Remote Code A critical remote code execution vulnerability in the Sneeit Framework WordPress plugin has come under active exploitation by threat actors, posing an immediate risk to thousands of websites worldwide. The vulnerability, tracked as CVE-2025-6389 with a CVSS score of 9.8, exists in versions 8.3 and…
-
Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery
Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery Legitimate administrative tools are increasingly becoming the weapon of choice for sophisticated threat actors aiming to blend in with normal network activity. A recent campaign has highlighted this dangerous trend, where attackers are weaponizing Velociraptor, a widely respected Digital Forensics and Incident Response (DFIR)…
-
BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters
BPFDoor and Symbiote Rootkits Attacking Linux Systems Exploiting eBPF Filters Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion…
-
Threat Actors Leveraging Matanbuchus Malicious Downloader to Ransomware and Establish Persistence
Threat Actors Leveraging Matanbuchus Malicious Downloader to Ransomware and Establish Persistence Matanbuchus represents a significant threat in the cybercriminal landscape as a dangerous malware downloader written in C++. Since 2020, this tool has been sold as Malware-as-a-Service, allowing threat actors to rent access and deploy it against targeted organizations. In July 2025, security researchers discovered…
-
4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign
4.3 Million Chrome and Edge Users Hacked in 7-Year ShadyPanda Malware Campaign A sophisticated threat group operating under the name ShadyPanda has successfully compromised millions of browser users through a methodical seven-year campaign targeting popular Chrome and Edge extensions. The attack represents a significant breach of user trust, as the malicious extensions gained verified status…
-
Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’
Hackers Registered 18,000 Holiday-Themed Domains Targeting ‘Christmas,’ ‘Black Friday,’ and ‘Flash Sale’ The 2025 holiday season has unleashed an unprecedented wave of cyber threats, with attackers deploying industrialized infrastructure to exploit the global surge in online commerce. This year’s threat landscape is characterized by a calculated expansion of deceptive digital assets, where criminals leverage automated tools…
-
Handala Hacker Group Attacking Israeli High-Tech and Aerospace Professionals
Handala Hacker Group Attacking Israeli High-Tech and Aerospace Professionals The Handala hacker group has launched a targeted campaign against Israeli high-tech and aerospace professionals, marking a concerning shift in geopolitically motivated cyber operations. The group recently published a list of individuals working in these critical sectors, accompanied by hostile descriptions that falsely label them as criminals.…
-
Hackers Actively Attacking Telecommunications & Media Industry to Deploy Malicious Payloads
Hackers Actively Attacking Telecommunications & Media Industry to Deploy Malicious Payloads Cybercriminals are launching increasingly sophisticated attacks against the telecommunications and media industry, focusing their efforts on deploying malicious payloads that compromise critical infrastructure. Recent security analysis reveals a concerning trend where threat actors are systematically targeting network operators, media platforms, and broadcasting services to…
-
Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents
Hackers Exploiting Fake Battlefield 6 Popularity to Deploy Stealers and C2 Agents Since its release in October, Battlefield 6 has become one of the year’s most anticipated game launches. However, cybercriminals have quickly seized on this popularity to distribute malicious software. Attackers have created fake cracked versions of the game and fraudulent game trainers, spreading…