Category: Threats

  • Hackers Tricks macOS Users to Execute Command in Terminal to Deliver FlexibleFerret Malware

    Hackers Tricks macOS Users to Execute Command in Terminal to Deliver FlexibleFerret Malware Cybercriminals are successfully targeting Apple users through a sophisticated social engineering scheme that tricks victims into running harmful commands on their computers. The threat, called FlexibleFerret, is attributed to North Korean operators and represents a continuing evolution of the Contagious Interview campaign…

  • Beware of North Korean Fake Job Platform Targeting U.S. Based AI-Developers

    Beware of North Korean Fake Job Platform Targeting U.S. Based AI-Developers A sophisticated recruitment scam linked to North Korea has emerged, targeting American artificial intelligence developers, software engineers, and cryptocurrency professionals through an elaborate fake job platform. Validin security researchers have uncovered a new variant of what they call the “Contagious Interview” operation, designed to…

  • AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload

    AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload A new wave of malicious Android applications impersonating a well-known Korean delivery service has emerged, featuring advanced obfuscation techniques powered by artificial intelligence. These apps work to bypass traditional antivirus detection methods while extracting sensitive user information. The threat actors behind this campaign have…

  • Malicious ‘Free’ VPN Extension with 9 Million Installs Hijacks User Traffic and Steals Browsing Data

    Malicious ‘Free’ VPN Extension with 9 Million Installs Hijacks User Traffic and Steals Browsing Data A deceptive browser campaign has exposed millions of users to extensive surveillance through seemingly innocent VPN extensions. Chrome extensions marketed as “Free Unlimited VPN” services accumulated over 9 million installations before security detection, with the malware remaining hidden for nearly…

  • UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins

    UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins Since mid-2024, a sophisticated Iranian-backed threat group known as UNC1549 has been conducting targeted campaigns against aerospace, aviation, and defense organizations across the globe. The hackers employ an advanced dual approach, combining carefully crafted phishing campaigns with the exploitation of trusted connections…

  • Threat Actors Leveraging Compromised RDP Logins to Deploy Lynx Ransomware After Deleting Server Backups

    Threat Actors Leveraging Compromised RDP Logins to Deploy Lynx Ransomware After Deleting Server Backups Lynx ransomware has emerged as a significant threat to enterprise environments, with recent intrusions demonstrating sophisticated attack strategies that prioritize data exfiltration and infrastructure destruction. The malware campaign combines compromised credentials with careful planning to ensure maximum impact on target networks.…

  • Cisco Catalyst Center Vulnerability Let Attackers Escalate Priveleges

    Cisco Catalyst Center Vulnerability Let Attackers Escalate Priveleges A serious security flaw in Cisco Catalyst Center Virtual Appliance has been discovered that allows attackers with low-level access to gain full administrator control over affected systems. The vulnerability, tracked as CVE-2025-20341, impacts virtual appliances running on VMware ESXi and carries a high severity rating with a…

  • RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools

    RONINGLOADER Weaponizes Signed Drivers to Disable Defender and Evade EDR Tools A new threat targeting Chinese users has appeared with a dangerous ability to shut down security tools. RONINGLOADER, a multi-stage loader spreading a modified version of the gh0st RAT, uses clever tricks to bypass antivirus protection. The malware arrives through fake software installers that…

  • A Multi-Stage Phishing Kit Using Telegram to Harvest Credentials and Bypass Automated Detection

    A Multi-Stage Phishing Kit Using Telegram to Harvest Credentials and Bypass Automated Detection Phishing attacks continue to be one of the most persistent threats targeting organizations worldwide. Cybercriminals are constantly improving their methods to steal sensitive information, and a recently discovered phishing kit demonstrates just how advanced these operations have become. This particular framework was…

  • Formbook Malware Delivered Using Weaponized Zip Files and Multiple Scripts

    Formbook Malware Delivered Using Weaponized Zip Files and Multiple Scripts A new wave of Formbook malware attacks has appeared, using weaponized ZIP archives and multiple script layers to bypass security controls. The attacks begin with phishing emails containing ZIP files that hold VBS scripts disguised as payment confirmation documents. These scripts trigger a chain of…

  • Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report

    Akira Ransomware Targets Over 250 Organizations, Extracts $42 Million in Ransom Payments – New CISA Report A new advisory from the Cybersecurity and Infrastructure Security Agency reveals that Akira ransomware has become one of the most active threats targeting businesses worldwide. Since March 2023, this ransomware group has impacted more than 250 organizations across North…

  • Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications

    Lumma Stealer Uses Browser Fingerprinting to Collect Data and for Stealthy C&C Server Communications Lumma Stealer has emerged as a serious threat in the cybercrime world, targeting users through fake software updates and cracked applications. This information-stealing malware targets the collection on login details, payment card information, and cryptocurrency wallet data from infected systems. The…

  • Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover

    Malicious Chrome Extension as Ethereum Wallet Enables Full Wallet Takeover A deceptive Chrome extension named Safery: Ethereum Wallet has emerged as a serious threat to cryptocurrency users. Published on the Chrome Web Store on November 12, 2024, this extension masquerades as a secure Ethereum wallet while secretly stealing user seed phrases. The malware’s sophisticated design…

  • New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware

    New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware A growing social engineering technique called ClickFix has emerged as one of the most successful methods for distributing malware in recent months. This attack tricks users into copying and running commands directly into their operating systems command line interface, ultimately installing dangerous information-stealing…

  • Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments

    Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments In August 2025, a new ransomware threat emerged with capabilities that fundamentally changed how organizations should approach enterprise security. Kraken, a Russian-speaking cybercriminal group, began executing sophisticated attacks targeting large organizations across multiple continents. What makes Kraken particularly dangerous is its ability…

  • New KomeX Android RAT Advertised on Hacker Forums with Multiple Subscription Options

    New KomeX Android RAT Advertised on Hacker Forums with Multiple Subscription Options A newly identified Android remote access trojan (RAT) dubbed KomeX has surfaced on underground hacker forums, generating widespread concern within the cybersecurity community. Marketed by a threat actor under the alias “Gendirector,” KomeX is built atop the infamous BTMOB RAT codebase and presents…

  • New Phishing Attack Targeting Meta Business Suite Users to Steal Login Credentials

    New Phishing Attack Targeting Meta Business Suite Users to Steal Login Credentials A large-scale phishing campaign has emerged, exploiting Meta’s Business Suite to compromise credentials across thousands of small and medium-sized businesses worldwide. Check Point security researchers identified approximately 40,000 phishing emails distributed to more than 5,000 customers, primarily targeting industries including automotive, education, real…

  • Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware

    Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware A sophisticated wave of ransomware attacks targeting UK organizations has emerged in 2025, exploiting vulnerabilities in the widely-used SimpleHelp Remote Monitoring and Management platform. Two prominent ransomware groups, Medusa and DragonForce, have weaponized three critical vulnerabilities (CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728) to gain unauthorized access…

  • German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure

    German ISP Aurologic GmbH has Become a Central Nexus for Hosting Malicious Infrastructure German hosting provider aurologic GmbH has emerged as a central facilitator within the global malicious infrastructure ecosystem, providing upstream transit and data center services to numerous high-risk hosting networks. Operating from its primary facility at Tornado Datacenter GmbH & Co. KG in…

  • ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process

    ClickFix Attacks Evolved With Weaponized Videos That Tricks Users via Self-infection Process ClickFix attacks have experienced a dramatic surge over the past year, establishing themselves as a cornerstone of modern social engineering tactics. These sophisticated attacks manipulate victims into executing malicious code directly on their devices through deceptive copy-and-paste mechanisms. The threat has evolved beyond…

  • Herodotus Android Banking Malware Takes Full Control Of Device Evading Antivirus

    Herodotus Android Banking Malware Takes Full Control Of Device Evading Antivirus A sophisticated banking trojan named Herodotus has emerged as a significant threat to Android users worldwide. Operating as Malware-as-a-Service, this malicious application disguises itself as a legitimate tool to trick users into downloading and installing an APK file outside the official Play Store. Once…

  • Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares

    Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares The Russia-aligned Sandworm threat group has intensified its destructive cyberattacks against Ukrainian organizations, deploying sophisticated data wiper malware designed to cripple critical infrastructure and economic operations. Unlike traditional cyberespionage campaigns, Sandworm’s recent operations focus exclusively on destruction, targeting governmental entities, energy providers, logistics companies, and the…

  • AI Browsers Bypass Content PayWall Mimicking as a Human-User

    AI Browsers Bypass Content PayWall Mimicking as a Human-User The emergence of advanced AI browsing platforms such as OpenAI’s Atlas and Perplexity’s Comet has created a sophisticated challenge for digital publishers worldwide. These tools leverage agentic capabilities designed to execute complex, multistep tasks that fundamentally transform how content is accessed and consumed online. Unlike traditional…

  • APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data

    APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data A sophisticated espionage campaign targeting recruitment professionals has emerged, with the APT-C-60 threat group weaponizing VHDX files to compromise organizations. The threat actors impersonate job seekers in spear-phishing emails sent to recruitment staff, exploiting trust relationships to deliver malicious…

  • Ransomware Attack on European Organizations Surge as Hackers Leveraging AI-Tools for Attacks

    Ransomware Attack on European Organizations Surge as Hackers Leveraging AI-Tools for Attacks European organizations are facing an unprecedented wave of ransomware attacks as cybercriminals increasingly integrate artificial intelligence tools into their operations. Since January 2024, big game hunting threat actors have named approximately 2,100 Europe-based victims on more than 100 dedicated leak sites, representing a…

  • Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials

    Silent Lynx APT New Attack Targeting Governmental Employees Posing as Officials Silent Lynx, a sophisticated threat group that has been tracked since 2024, continues its relentless espionage campaign against government entities across Central Asia. Seqrite analysts identified the group as the first to assign this nomenclature, distinguishing it from multiple overlapping aliases including YoroTrooper, Sturgeon…

  • Stolen Credentials and Valid Account Abuse Fuel the Financially Motivated Attacks

    Stolen Credentials and Valid Account Abuse Fuel the Financially Motivated Attacks Throughout the first half of 2025, financially motivated threat actors have shifted their approach to intrusions, abandoning traditional implant-heavy methods in favor of a more cost-effective strategy. Rather than deploying sophisticated malware payloads, attackers are leveraging stolen credentials and valid account access to establish…

  • Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability

    Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability Chinese-affiliated threat actor UNC6384 has been actively leveraging a critical Windows shortcut vulnerability to target European diplomatic entities across Hungary, Belgium, Serbia, Italy, and the Netherlands. Arctic Wolf researchers identified this sophisticated cyber espionage campaign operating throughout September and October 2025, representing a significant…

  • Threat Actors Using Multilingual ZIP File to Attack Financial and Government Organizations

    Threat Actors Using Multilingual ZIP File to Attack Financial and Government Organizations Sophisticated threat actors have orchestrated a coordinated multilingual phishing campaign targeting financial and government organizations across East and Southeast Asia. The campaign leverages carefully crafted ZIP file lures combined with region-specific web templates to deceive users into downloading staged malware droppers. Recent analysis…

  • Kimsuky and Lazarus Hacker Groups Unveil New Tools That Enable Backdoor and Remote Access

    Kimsuky and Lazarus Hacker Groups Unveil New Tools That Enable Backdoor and Remote Access Threat actors operating under the control of North Korea’s regime have demonstrated continued technical sophistication by introducing advanced malware toolsets designed to establish persistent backdoor access and remote control over compromised systems. Recent findings have revealed that Kimsuky, known for orchestrating…

  • Threat Actors Weaponizes Judicial Documents to Deliver PureHVNC RAT

    Threat Actors Weaponizes Judicial Documents to Deliver PureHVNC RAT Between August and October 2025, a sophisticated phishing campaign has emerged targeting Colombian and Spanish-speaking users through deceptive emails masquerading as official communications from Colombia’s Attorney General’s office. The campaign employs a carefully crafted social engineering strategy, luring victims with notifications about supposed lawsuits processed through…

  • Russian Hackers Attacking Government Entity Using Stealthy Living-Off-the-Land Tactics

    Russian Hackers Attacking Government Entity Using Stealthy Living-Off-the-Land Tactics Ukrainian government organizations continue facing relentless cyber threats from Russian-backed threat actors employing sophisticated evasion techniques to maintain persistent network access. Recent investigations have uncovered coordinated campaigns targeting critical infrastructure and government entities, with attackers deploying advanced tactics that circumvent traditional security defenses. These operations represent…

  • New Beast Ransomware Actively Scans for Active SMB Port from Breached System to Spread Across Network

    New Beast Ransomware Actively Scans for Active SMB Port from Breached System to Spread Across Network The Beast ransomware group has emerged as a significant threat in the cybersecurity landscape, evolving from the Monster ransomware strain to establish itself as a formidable Ransomware-as-a-Service operation. Officially launched in February 2025, the group rapidly expanded their infrastructure…

  • 81% Router Usres Have Not Changed Default Admin Passwords, Exposing Devices to Hackers

    81% Router Usres Have Not Changed Default Admin Passwords, Exposing Devices to Hackers In late 2025, a staggering 81% of broadband users were found to have never changed their router’s default administrative password, opening the door to significant malware risk. This widespread negligence was revealed in Broadband Genie’s fourth major router security survey, where 3,242…

  • iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The ‘shutdown.log’ file on Reboot

    iOS 26 Deletes Pegasus and Predator Spyware Infection Evidence by Overwriting The ‘shutdown.log’ file on Reboot The emergence of Pegasus and Predator spyware over the past several years has transformed the landscape of mobile device security. These advanced malware strains—deployed by sophisticated threat actors for surveillance and espionage—have repeatedly demonstrated their ability to exploit zero-click…

  • Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control

    Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control A sophisticated backdoor named Android.Backdoor.Baohuo.1.origin has been discovered in maliciously modified versions of Telegram X messenger, granting attackers complete control over victims’ accounts while operating undetected. The malware infiltrates devices through deceptive in-app advertisements and third-party app stores, masquerading as legitimate dating…

  • LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments

    LockBit 5.0 Actively Attacking Windows, Linux, and ESXi Environments The notorious LockBit ransomware operation has resurfaced with a vengeance after months of dormancy following Operation Cronos takedown efforts in early 2024. Despite law enforcement disruptions and infrastructure seizures, the group’s administrator, LockBitSupp, has successfully rebuilt the operation and launched LockBit 5.0, internally codenamed “ChuongDong.” This…

  • Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program

    Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program Southeast Asia’s online gambling ecosystem has become a breeding ground for sophisticated cyber threats, with criminal networks leveraging seemingly legitimate platforms to distribute malicious software to millions of unsuspecting users. A recently uncovered operation demonstrates how threat actors exploit the region’s thriving…

  • Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials

    Google Warns of Threat Actors Using Fake Job Posting to Deliver Malware and Steal Credentials Cybercriminals have adopted a sophisticated social engineering strategy that exploits the trust inherent in job hunting, according to a recent security advisory. A financially motivated threat cluster operating from Vietnam has been targeting digital advertising and marketing professionals through fake…

  • New Caminho Malware Loader Uses LSB Steganography and to Hide .NET Payloads Within Image Files

    New Caminho Malware Loader Uses LSB Steganography and to Hide .NET Payloads Within Image Files A sophisticated malware operation has emerged from Brazil, leveraging advanced steganographic techniques to conceal malicious payloads within seemingly harmless image files. The Caminho loader, active since at least March 2025, represents a growing threat to organizations across South America, Africa,…

  • New Text Message Based Phishing Attack from China Targeting Users Around the Globe

    New Text Message Based Phishing Attack from China Targeting Users Around the Globe A sophisticated text message phishing campaign originating from China has emerged as one of the most extensive cybersecurity threats targeting users worldwide. The operation, attributed to a threat collective known as the Smishing Triad, represents a massive escalation in SMS-based fraud, impersonating…

  • New Malware Attack Using Variable Functions and Cookies to Evade and Hide Their Malicious Scripts

    New Malware Attack Using Variable Functions and Cookies to Evade and Hide Their Malicious Scripts A sophisticated malware campaign targeting WordPress sites has emerged, utilizing PHP variable functions and cookie-based obfuscation to evade traditional security detection mechanisms. The attack represents an evolution in obfuscation techniques, where threat actors fragment malicious code across multiple HTTP cookies…

  • Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories

    Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories Cybersecurity researchers have identified a sophisticated campaign where threat actors are leveraging compromised credentials to infiltrate Azure Blob Storage containers, targeting organizations’ critical code repositories and sensitive data. This emerging threat exploits misconfigured storage access controls to establish persistence and exfiltrate valuable intellectual property. The…

  • New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient

    New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient Remcos, a commercial remote access tool marketed as legitimate surveillance software, has become the leading infostealer in malware campaigns during the third quarter of 2025, accounting for approximately 11 percent of detected cases. In a notable shift from traditional deployment methods, threat actors are now…

  • Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset

    Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset Cloud account takeover attacks have evolved into a sophisticated threat as cybercriminals and state-sponsored actors increasingly weaponize OAuth applications to establish persistent access within compromised environments. These malicious actors are exploiting the fundamental trust mechanisms of cloud authentication systems, specifically targeting Microsoft Entra…

  • Pakistani Threat Actors Targeting Indian Govt. With Email Mimic as ‘NIC eEmail Services’

    Pakistani Threat Actors Targeting Indian Govt. With Email Mimic as ‘NIC eEmail Services’ A sophisticated phishing campaign orchestrated by Pakistan-linked threat actors has been discovered targeting Indian government entities by impersonating the National Informatics Centre’s email services. The operation, attributed to APT36, also known as TransparentTribe, leverages social engineering tactics to compromise sensitive government infrastructure…

  • Threat Actors Leverage npm Ecosystem to Deliver AdaptixC2 Post-Exploitation Framework

    Threat Actors Leverage npm Ecosystem to Deliver AdaptixC2 Post-Exploitation Framework The emergence of the AdaptixC2 post-exploitation framework in 2025 marked a significant milestone in the evolution of attacker toolsets targeting open-source supply chains. Positioning itself as a formidable alternative to established tools like Cobalt Strike, AdaptixC2 quickly attracted threat actors seeking agility and stealth in…

  • Cavalry Werewolf APT Hackers Attacking Multiple Industries with FoalShell and StallionRAT

    Cavalry Werewolf APT Hackers Attacking Multiple Industries with FoalShell and StallionRAT A sophisticated threat campaign has emerged targeting Russia’s public sector and critical industries between May and August 2025. The Cavalry Werewolf APT group, also known as YoroTrooper and Silent Lynx, has been actively deploying custom-built malware toolsets through highly targeted phishing operations that exploit…

  • Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution

    Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution Cybercriminals are exploiting TikTok’s massive user base to distribute sophisticated malware campaigns that promise free software activation but deliver dangerous payloads instead. The attack leverages social engineering tactics reminiscent of the ClickFix technique, where unsuspecting users are tricked into executing malicious PowerShell…

  • North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency

    North Korean Hackers Using EtherHiding to Deliver Malware and Steal Cryptocurrency In recent months, a sophisticated malware campaign—dubbed EtherHiding—has emerged from North Korea-aligned threat actors, sharply escalating the cybersecurity risks facing cryptocurrency exchanges and their users worldwide. The campaign surfaced in the wake of heightened regulatory crackdowns on illicit crypto transactions, with attackers shifting tactics…

  • New Banking Malware Abusing WhatsApp to Gain Complete Remote Access to Your Computer

    New Banking Malware Abusing WhatsApp to Gain Complete Remote Access to Your Computer A sophisticated banking Trojan named Maverick has emerged in Brazil, leveraging WhatsApp as its primary distribution channel to compromise thousands of users. The malware campaign was detected in mid-October 2025, with cybersecurity solutions blocking over 62,000 infection attempts in just the first…

  • NCSC Warns of UK Experiencing Four Cyber Attacks Every Week

    NCSC Warns of UK Experiencing Four Cyber Attacks Every Week The United Kingdom faces an unprecedented cyber security crisis as the National Cyber Security Centre (NCSC) reports handling an average of four ‘nationally significant’ cyber attacks weekly. This alarming escalation represents a dangerous shift in the threat landscape, with the NCSC managing 204 nationally significant…

  • Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access

    Russian Cybercrime Market Hub Transferring from RDP Access to Malware Stealer Logs to Access A new evolution is underway in the Russian cybercrime ecosystem: market operators and threat actors are rapidly shifting from selling compromised Remote Desktop Protocol (RDP) access to trading malware stealer logs for unauthorized system entry. This transition marks a significant change…

  • Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads

    Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads A sophisticated campaign targeting macOS users has emerged through spoofed Homebrew installer websites that deliver malicious payloads alongside legitimate package manager installations. The attack exploits the widespread trust users place in the popular Homebrew package manager by creating pixel-perfect replicas of the official…

  • Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials

    Pro-Russian Hacktivist Attacking OT/ICS Devices to Steal Login Credentials A newly identified pro-Russian hacktivist group has successfully infiltrated operational technology and industrial control systems belonging to critical infrastructure organizations, employing sophisticated techniques to steal login credentials and disrupt vital services. The threat actor, known as TwoNet, represents an emerging class of hacktivists who have expanded…

  • 175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

    175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide Socket’s Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages that collectively accumulated over 26,000 downloads. The campaign, dubbed “Beamglea” based on consistent artifacts across all packages, represents a novel abuse of npm’s public registry and the…

  • Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware

    Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances to deploy Akira ransomware on enterprise networks. Beginning in July, multiple incidents of initial access via unpatched SonicWall devices were reported across North America and EMEA. Attackers…

  • New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands

    New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial investigations revealed that threat actors gained entry by exploiting compromised CiscoVPN credentials coupled with over-privileged Active Directory service accounts. Once inside, ChaosBot was stealthily deployed via side-loading techniques…

  • SnakeKeylogger via Weaponized E-mails Leverage PowerShell to Exfiltrate Sensitive Data

    SnakeKeylogger via Weaponized E-mails Leverage PowerShell to Exfiltrate Sensitive Data Emerging from a recent wave of targeted campaigns, SnakeKeylogger has surfaced as a potent infostealer that capitalizes on PowerShell and social engineering. The malware’s operators craft convincing spear-phishing e-mails under aliases such as “CPA-Payment Files,” impersonating reputable financial and research firms. Recipients encounter ISO or…

  • New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users

    New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users A sophisticated Android spyware campaign dubbed ClayRat has emerged as one of the most concerning mobile threats of 2025, masquerading as popular applications including WhatsApp, Google Photos, TikTok, and YouTube to infiltrate devices and steal sensitive user data. The malware demonstrates remarkable adaptability…

  • Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments

    Microsoft Warns of Hackers Compromising Employee Accounts to Steal Salary Payments A sophisticated financially motivated threat actor known as Storm-2657 has been orchestrating elaborate “payroll pirate” attacks targeting US universities and other organizations, Microsoft Threat Intelligence has revealed. These attacks represent a concerning evolution in cybercriminal tactics, where hackers compromise employee accounts to gain unauthorized…

  • Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack

    Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack A sophisticated technique known as hidden text salting has emerged as a significant threat to email security systems, allowing cybercriminals to bypass detection mechanisms through the strategic abuse of cascading style sheets (CSS) properties. This attack vector enables threat actors…

  • IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed

    IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the Middle East and beyond. Initially focused on credential harvesting via targeted phishing campaigns, the group has evolved…

  • Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently

    Hackers Weaponizing WordPress Websites by Injecting Malicious PHP Codes Silently WordPress websites have become a prime target for threat actors seeking to monetize traffic and compromise visitor security. In recent months, a new malvertising campaign has emerged, leveraging silent PHP code injections within theme files to serve unwanted third-party scripts. The attack blends seamlessly with…

  • Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware

    Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware The Confucius hacker group, active since 2013, has recently escalated its operations by weaponizing malicious Office documents to compromise Windows endpoints with a new Python-based backdoor, dubbed AnonDoor. Historically known for deploying document stealers such as WooperStealer, the threat actor has now…

  • Hundreds of Free VPN Apps for Both Android and iOS Leaks Users Personal Data

    Hundreds of Free VPN Apps for Both Android and iOS Leaks Users Personal Data Mobile VPN apps promise to protect privacy and secure communications on smartphones, but a comprehensive analysis of nearly 800 free Android and iOS VPN applications reveals a troubling reality: many of these tools expose sensitive information rather than shield it. From…

  • Ukraine Warns of Weaponized XLL Files Delivers CABINETRAT Malware Via Zip Files

    Ukraine Warns of Weaponized XLL Files Delivers CABINETRAT Malware Via Zip Files Ukrainian security agencies have issued an urgent warning regarding a sophisticated malware campaign targeting government and critical infrastructure sectors through weaponized XLL files distributed via compressed archives. The malicious campaign leverages Microsoft Excel add-in files containing the CABINETRAT backdoor, representing a significant evolution…

  • Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details

    Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details A sophisticated phishing campaign has emerged targeting job seekers through fake Google career recruitment opportunities, leveraging social engineering tactics to harvest Gmail credentials and personal information. The malicious operation exploits the trust associated with Google’s brand reputation, crafting convincing recruitment emails that direct victims…

  • Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links

    Hackers Exploit Cellular Router’s API to Send Malicious SMS Messages With Weaponized Links Hackers have recently leveraged a vulnerability in the web-based management interfaces of certain cellular routers to co-opt their built-in SMS functionality for nefarious purposes. By targeting exposed APIs, attackers are able to dispatch large volumes of malicious SMS messages containing weaponized links…

  • Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information

    Hackers Weaponizing SVG Files to Deliver PureMiner Malware and Steal Sensitive Information In recent weeks, a sophisticated phishing campaign has emerged, targeting organizations in Ukraine with malicious Scalable Vector Graphics (SVG) files designed to propagate the PureMiner cryptominer and a data-stealing payload dubbed Amatera Stealer. Attackers masquerade as the Ukrainian police, sending emails that claim…

  • Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes

    Threat Actors Leveraging Dynamic DNS Providers to Use for Malicious Purposes Cybersecurity researchers are raising alarms about a growing threat vector as malicious actors increasingly exploit Dynamic DNS providers to establish robust command and control infrastructure. These publicly rentable subdomain services, traditionally designed for legitimate hosting purposes, have become the preferred platform for threat actors…

  • Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users

    Apache Airflow Vulnerability Exposes Sensitive Details to Read-Only Users A critical security flaw has emerged in Apache Airflow 3.0.3, exposing sensitive connection information to users with only read permissions. The vulnerability, tracked as CVE-2025-54831 and classified as “important” severity, fundamentally undermines the platform’s intended security model for handling sensitive data within workflow connections. Apache Airflow…

  • New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads

    New Botnet Loader-as-a-Service Exploiting Routers and IoT Devices to Deploy Mirai Payloads A sophisticated botnet operation has emerged, employing a Loader-as-a-Service model to systematically weaponize internet-connected devices across the globe. The campaign exploits SOHO routers, IoT devices, and enterprise applications through command injection vulnerabilities in web interfaces, demonstrating an alarming evolution in cybercriminal tactics. The…

  • Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations

    Malware Operators Collaborate With Covert North Korean IT Workers to Attack Corporate Organizations A sophisticated cybercriminal alliance between malware operators and covert North Korean IT workers has emerged as a significant threat to corporate organizations worldwide. This hybrid operation, known as DeceptiveDevelopment, represents a dangerous convergence of traditional cybercrime and state-sponsored activities, targeting software developers…

  • LummaStealer Technical Details Uncovered Using ML-Based Detection Approach

    LummaStealer Technical Details Uncovered Using ML-Based Detection Approach LummaStealer has emerged as one of the most prolific information-stealing malware families in recent years, targeting victims across multiple industry verticals including telecommunications, healthcare, banking, and marketing. The sophisticated malware gained widespread notoriety in early 2025 when cybercriminals extensively deployed it in coordinated campaigns worldwide. Although law…

  • Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups

    Researchers Uncovered Connections Between LAPSUS$, Scattered Spider, and ShinyHunters Hacker Groups The cybersecurity landscape continues to evolve as three of the most notorious English-speaking cybercrime groups—LAPSUS$, Scattered Spider, and ShinyHunters—have been found to share significant operational connections, tactical overlaps, and direct collaboration since 2023. These relationships have created what security experts now describe as a…

  • LLM-Based LAMEHUG Malware Dynamically Generate Commands for Reconnaissance and Data Theft

    LLM-Based LAMEHUG Malware Dynamically Generate Commands for Reconnaissance and Data Theft A sophisticated new threat has emerged in the cybersecurity landscape that represents a significant evolution in malware development. The LAMEHUG malware family, first identified by CERT-UA in July 2025, marks a concerning advancement in cyber attack methodology by integrating artificial intelligence directly into its…

  • New Malicious Rust Crates Impersonating fast_log to Steal Solana and Ethereum Wallet Keys

    New Malicious Rust Crates Impersonating fast_log to Steal Solana and Ethereum Wallet Keys Cybercriminals have launched a sophisticated supply chain attack targeting cryptocurrency developers through malicious Rust crates designed to steal digital wallet keys. Two fraudulent packages, faster_log and async_println, have infiltrated the Rust package registry by impersonating the legitimate fast_log logging library, embedding malicious…

  • Numerous Applications Using Google’s Firebase Platform Leaking Highly Sensitive Data

    Numerous Applications Using Google’s Firebase Platform Leaking Highly Sensitive Data Numerous mobile applications have been found to expose critical user information through misconfigured Firebase services, allowing unauthenticated attackers to access databases, storage buckets, Firestore collections, and Remote Config secrets. This widespread issue first came to light when security researcher Mike Oude Reimer published findings on…

  • New Russian Disinformation Campaign Targeting Upcoming Moldova’s Elections

    New Russian Disinformation Campaign Targeting Upcoming Moldova’s Elections On the eve of Moldova’s parliamentary elections scheduled for September 28, 2025, cybersecurity researchers have uncovered a sophisticated Russian-backed disinformation campaign designed to undermine public confidence in Moldova’s pro-European leadership. The campaign began surfacing in April 2025, when analysts first observed a cluster of newly registered domains publishing…

  • BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch

    BlockBlasters Steam Game Downloads Malware to Computer Disguised as Patch A seemingly innocent patch update for the popular 2D platformer game BlockBlasters has transformed into a sophisticated malware campaign, exposing hundreds of Steam users to data theft and system compromise. The malicious patch, deployed on August 30, 2025, demonstrates how threat actors are increasingly exploiting…

  • Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication

    Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication A critical authentication bypass vulnerability has emerged in Nokia’s CloudBand Infrastructure Software (CBIS) and Nokia Container Service (NCS) Manager API, designated as CVE-2023-49564. This high-severity flaw, scoring 9.6 on the CVSS v3.1 scale, enables unauthorized attackers to circumvent authentication mechanisms through specially crafted HTTP headers, potentially…

  • Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools

    Phishing Attacks Using AI-Powered Platforms to Misleads Users and Evades Security Tools Phishing campaigns have long relied on social engineering to dupe unsuspecting users, but recent developments have elevated these attacks to a new level of sophistication. Attackers now harness advanced content-generation platforms to craft highly personalized emails and webpages, blending genuine corporate branding with…

  • Threat Actors Selling New Undetectable RAT as ’ScreenConnect FUD Alternative’

    Threat Actors Selling New Undetectable RAT as ’ScreenConnect FUD Alternative’ A threat actor has been observed advertising a new Remote Access Trojan (RAT) on underground forums, marketing it as a fully undetectable (FUD) alternative to the legitimate remote access tool, ScreenConnect. The malware is being sold with a suite of advanced features designed to bypass…

  • New Phishing Attack Targets Facebook Users to Steal Login Credentials

    New Phishing Attack Targets Facebook Users to Steal Login Credentials A sophisticated phishing campaign has recently emerged, targeting Facebook users with carefully crafted emails designed to harvest login credentials. Attackers leverage the platform’s own external URL warning system to cloak malicious links, presenting URLs that appear legitimate while redirecting victims to counterfeit Facebook login pages.…

  • Global Spyware Markets to Identify New Entities Entering The Market

    Global Spyware Markets to Identify New Entities Entering The Market The global spyware market continues its alarming expansion, with new research revealing the emergence of 130 additional entities spanning 46 countries between 1992 and 2024. This shadowy ecosystem of surveillance technologies has grown from 435 documented entities in the initial assessment to 561 organizations, fundamentally…

  • Splunk Releases Guide to Detect Remote Employment Fraud Within Your Organization

    Splunk Releases Guide to Detect Remote Employment Fraud Within Your Organization Detecting remote employment fraud has become a critical priority for organizations striving to secure their digital onboarding processes and safeguard sensitive systems. In recent months, threat actors posing as legitimate hires have leveraged sophisticated tactics to bypass pre-hire screenings and embed themselves within corporate…

  • Raven Stealer Attacking Google Chrome Users to Steal Sensitive Data

    Raven Stealer Attacking Google Chrome Users to Steal Sensitive Data Raven Stealer has emerged as a potent information‐stealing threat targeting users of Chromium‐based browsers, most notably Google Chrome. First observed in mid-2025, this lightweight malware distinguishes itself through a modular architecture and stealthy design, allowing it to harvest sensitive information without alerting victims. Delivered predominantly…

  • Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT

    Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT Python developers face a growing threat from typosquatted packages in the Python Package Index (PyPI), with malicious actors increasingly targeting this trusted repository to distribute sophisticated malware. Recent discoveries have exposed a concerning trend where threat actors create packages that closely mimic legitimate libraries, using…

  • SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks

    SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks SmokeLoader, first seen on criminal forums in 2011, has evolved into a highly modular malware loader designed to deliver a variety of second-stage payloads, including trojans, ransomware, and credential stealers. After Operation Endgame disrupted numerous campaigns in mid-2024, the loader reemerged…

  • New Maranhão Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials

    New Maranhão Stealer Via Pirated Software Leveraging Cloud-Hosted Platforms to Steal Login Credentials Since May 2025, a novel credential stealer dubbed Maranhão Stealer has emerged as a significant threat to users of pirated gaming software. Distributed through deceptive websites hosting cracked launchers and cheats, the malware leverages cloud-hosted platforms to deliver trojanized installers that appear…

  • AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack

    AISURU Botnet With 300,000 Hijacked Routers Behind The Recent Massive 11.5 Tbps DDoS Attack Since early 2025, the cybersecurity community has witnessed an unprecedented surge in distributed denial-of-service (DDoS) bandwidth, culminating in a record-shattering 11.5 Tbps assault attributed to a botnet named AISURU. Emerging from XLab’s continuous monitoring of global DDoS incidents, this botnet leveraged…

  • New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm

    New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm Emerging in early September 2025, the Yurei ransomware has swiftly drawn attention for its novel combination of Go-based execution and ChaCha20 encryption. First documented on September 5 when a Sri Lankan food manufacturer fell victim, the threat actor behind Yurei adopted a double-extortion model:…

  • DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments

    DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments DarkCloud Stealer has recently emerged as a potent threat targeting financial organizations through convincing phishing campaigns. Adversaries employ weaponized RAR attachments masquerading as legitimate documents to deliver a multi-stage JavaScript-based payload. Upon opening the archive, victims execute a VBE script that leverages Windows Script Host to…

  • New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

    New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts In recent months, security teams have observed a significant increase in sophisticated phishing campaigns leveraging a newly discovered Phishing-as-a-Service (PhaaS) platform dubbed VoidProxy. The operation, first detected in August 2025, combines multiple anti-analysis techniques and adversary-in-the-middle (AitM) capabilities to target Microsoft 365 and Google accounts…

  • New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT

    New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT Cybersecurity researchers have uncovered a sophisticated malware campaign that exploits SVG (Scalable Vector Graphics) files and email attachments to distribute dangerous Remote Access Trojans, specifically XWorm and Remcos RAT. This emerging threat represents a significant evolution in attack methodologies, as threat actors…

  • Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints

    Buterat Backdoor Attacking Enterprises to Establish Persistence and Control Endpoints A sophisticated backdoor malware known as Backdoor.WIN32.Buterat has emerged as a significant threat to enterprise networks, demonstrating advanced persistence techniques and stealth capabilities that enable attackers to maintain long-term unauthorized access to compromised systems. The malware has been identified targeting government and corporate environments through…

  • New Malvertising Campaign Leverages GitHub Repository to Deliver Malware

    New Malvertising Campaign Leverages GitHub Repository to Deliver Malware A sophisticated malvertising campaign has emerged, exploiting GitHub repositories through dangling commits to distribute malware via fake GitHub Desktop clients. This novel attack vector represents a significant evolution in cybercriminal tactics, leveraging the trust and legitimacy associated with GitHub’s platform to deceive unsuspecting users into downloading…

  • EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections

    EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections A sophisticated malware campaign has emerged that leverages artificial intelligence to create deceptively legitimate applications, marking a significant evolution in cyberthreat tactics. The EvilAI malware family represents a new breed of threats that combines AI-generated code with traditional trojan techniques to infiltrate systems…

  • U.S. Authorities Investigating Malicious Email Targeting Trade Talks with China

    U.S. Authorities Investigating Malicious Email Targeting Trade Talks with China U.S. federal authorities have launched an investigation into a sophisticated malware campaign that targeted sensitive trade negotiations between Washington and Beijing. The attack, which surfaced in July 2025, involved fraudulent emails purportedly sent by Representative John Moolenaar, chairman of the House Select Committee on Strategic…