Skip to main content

Malware & Ransomware

Federal courthouse interior with defendant and blurred DOJ seal in background.

Russian Man Extradited for Malware Campaign Targeting Freelancers

A massive malware campaign targeting nearly 80,000 freelancers worldwide has led to the extradition of a Russian national, Searzhudin Tamirlanovich Aktulaev, who faces charges of conspiracy, computer damage, and identity theft. Aktulaev's alleged crimes, committed between 2016 and 2017, have finally caught up with him after an international arrest and extradition.

Analyst 207
Smartphone on cluttered coffee shop table with blank, out-of-focus screen.

Meta Ads Spread StreamRat Trojan with Near-Total Android Device Control

Meet StreamRat, a sneaky new Android banking trojan that's giving hackers near-total control over infected devices - and it's been spreading through paid social media ads on Meta. This sophisticated threat is a major red flag for Android users, especially in Spain where the campaign was focused.

Analyst 207
Network operations center with servers and equipment, focusing on a router on a rack.

BGP Hijack Targets Virtualizor Users with Persistent Root Access Malware

A recent BGP hijack attack targeted users of Virtualizor with malware that granted persistent root access, affecting a limited number of servers that received rerouted Softaculous update traffic during a 33-hour window. The attackers cleverly obtained a valid Let's Encrypt certificate, making the malicious server appear trustworthy to clients.

Analyst 207
Brazilian government building with people walking by, subtle server room in background.

Malicious Apache Modules Redirect Brazilian Government Traffic to Betting Sites

Brazilian government websites have been hijacked by malicious actors, redirecting traffic to betting sites in a sneaky campaign attributed to a Chinese-speaking cluster known as Gambling Goblin or Earth Berberoka. This multilingual scheme has been cleverly manipulating search engines and government systems since mid-2025.

Analyst 207
Developer workstation with laptop, terminal, and papers, showing a Git config file on screen in a bright office setting.

AI Coding Agents Exposed to Code Execution via Malicious Git Configs

Researchers have uncovered a shocking vulnerability in seven AI coding agents, where malicious Git configurations can trick the tools into running attacker-supplied code on a developer's machine. This flaw, linked to Git's core.fsmonitor setting, has already led to eight security flaws, with four still unpatched.

Analyst 207
Server room with rows of computer servers and networking equipment, featuring a single Apache web server in the foreground.

Malicious Apache Modules Empower Gambling Goblin's SEO Fraud Campaign

Meet Gambling Goblin, a Chinese-speaking cybercrime cluster that's been secretly hijacking Brazilian government and education websites to fuel a massive SEO fraud campaign since mid-2025. They're using sneaky Apache modules to disguise their malicious activity and stay under the radar.

Analyst 207
Brightly-lit IT support environment with a central computer workstation.

MSPs Face Ransomware Onslaught, Seek Integrated Protection

MSPs are under siege from ransomware attacks, with 143 reported victims in 2025 alone, and it's clear that a robust defense requires more than just backup or endpoint detection - a comprehensive, integrated protection approach is needed. To stay safe, MSPs must bring together prevention, detection, response, and recovery into a cohesive, measurable service that delivers six critical outcomes.

Analyst 207
Rows of server racks and network equipment fill a modern enterprise network operations center.

AI-Assisted Cyber Attacks Accelerate with Autonomous Agent Loops

In a recent ransomware attack, a human attacker used AI to breach an enterprise network in under 10 hours - compressing weeks of meticulous planning into a lightning-fast operation. This was achieved by leveraging autonomous agents that worked in parallel, methodically bypassing security layers to achieve a shared goal.

Analyst 207
Federal courthouse or government briefing room with podium and blank plaque.

Russian Hacker Charged Over Excel Malware Campaign Targeting Freelancers

A massive malware campaign, involving around 255 fake accounts and 80,000 targeted users, has led to charges against a Russian national, Searzhudin Tamirlanovich Aktulaev, who has been extradited and charged by the U.S. Department of Justice. The campaign, which spread malware through infected Excel attachments, allegedly ran from June 2016 to November 2017, targeting freelancers and others.

Analyst 207
A cluttered freelance workspace with a laptop and crumpled paper on a desk.

US Indicts Russian for Infecting 80,000 Freelancers with Malware

A massive phishing campaign infected 80,000 freelancers with malware, using 255 fake accounts to spread malicious Excel attachments with hidden macros that downloaded additional software onto victims' systems. The cleverly designed scam exploited a popular freelance employment platform's online messaging feature to spread its digital damage.

Analyst 207
Professionals in a briefing room with technology equipment in the background.

Authorities Disrupt Sality's P2P Network, Neutralize Malware Payloads

In a major win for national security, authorities have successfully dismantled the Sality malware's peer-to-peer network, crippling its ability to spread and cause harm. By cleverly turning the malware's own protocols against it, law enforcement and private partners isolated infected hosts and rendered the threat actor powerless.

Analyst 207
Law enforcement setting with server equipment, symbolizing disrupted botnet infrastructure.

Global Authorities Disrupt Sality Botnet Infrastructure

In a major win for cybersecurity, global authorities have joined forces to dismantle the notorious Sality botnet infrastructure, seizing key domains in the US and Europe. This coordinated crackdown, involving the US Department of Justice and international partners, has disrupted the malware's grip on thousands of infected computers.

Analyst 207
Law enforcement operation aftermath with organized network equipment in a clean, brightly-lit room.

CrowdStrike and Law Enforcement Disrupt 23-Year-Old Sality Botnet

In a major win for cybersecurity, CrowdStrike and international law enforcement agencies joined forces to dismantle the notorious Sality botnet, crippling its ability to communicate and operate by corrupting its core network. By targeting the botnet's peer list, they effectively isolated infected machines and brought the 23-year-old threat to a grinding halt.

Analyst 207
High-profile individual sits at desk with laptop, hands poised over keyboard.

FBI Warns of Sophisticated Phishing Campaign Targeting High-Profile Individuals

Beware of a sneaky phishing scam that's targeting high-profile individuals, using a clever tactic to gain long-term access to their cloud accounts without needing their passwords. This sophisticated attack convinces victims to grant a malicious app permission to their accounts, allowing hackers to stay logged in for good.

Analyst 207
Dimly lit server room with rows of equipment and a single isolated computer terminal in the foreground.

Attackers Exploit Artifactory Flaw in AI-Driven Campaigns

Cyber attackers are leveraging a newly exploited Artifactory flaw in highly sophisticated, AI-driven campaigns - but are these threats coming from automated bots or human culprits? The line between human and machine is blurring in the world of cybercrime.

Analyst 207
Cluttered office cubicle with desktop computer and suspicious email nearby.

Hackers Exploit Faronics Tool to Install ScreenConnect on Compromised Endpoints

Hackers are using clever phishing lures disguised as invoices and business files to trick victims into installing malicious software, with over 457 endpoints compromised in just a month. They exploited a legitimate endpoint-management tool to gain remote control and install additional remote-access software.

Analyst 207
Retail checkout terminal with card reader and receipt printer in busy shopping area.

Breeze Comet Exploits Brazilian Payment Systems in Hundreds of Fraudulent Transactions

Meet Breeze Comet, a financially motivated threat actor that's been wreaking havoc on Brazilian payment systems with hundreds of fraudulent transactions, exploiting customized malware and compromised websites to siphon off tens of thousands of dollars. Their tactics are evolving, and Latin American countries should beware of potential expansion.

Analyst 207
Server room with rows of equipment and one terminal with a blank screen, suggesting a breach.

Langflow vulnerability exploited to harvest OpenAI, AWS keys

Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

Analyst 207
Smartphone on cluttered desk in cafe with blurred webpage on screen.

Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Seeds

Researchers uncovered 13 malicious packages on Packagist that inject JavaScript into popular Vietnamese streaming sites, unleashing a two-pronged attack that includes mobile ad-fraud and spyware installation on unpatched iPhones. This sneaky malware can steal crypto seeds and wreak havoc on unsuspecting users.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with one server's panel slightly open.

Threat Actors Exploit API Key, Drain $600,000 in AI Credits

In a shocking security breach, threat actors made off with a whopping $600,000 in AI credits after exploiting a stolen API key from AI safety research group METR over just three weeks. The incident began with a researcher inadvertently leaving a public EC2 instance exposed, despite Google authentication, due to a fail-open flaw and a "vibe-coded" app storing a sensitive API key.

Analyst 207
Dimly lit industrial control room with unoccupied workstation and blurred laptop screen.

Cybersecurity Leaders Warn of AI Trust Gap

More than one in five organizations have fallen victim to AI-powered attacks, with 22% reporting a security incident in the past year where hackers used artificial intelligence to breach critical business platforms. This alarming trend highlights the urgent need for cybersecurity leaders to address the growing AI trust gap.

Analyst 207
Network operations room with rows of routers, technicians, and a large screen displaying internet infrastructure diagram.

Hackers exploit BGP hijacking to deliver malicious Virtualizor updates

Malicious actors hijacked internet traffic to deliver fake Virtualizor updates to a small number of users, exploiting a vulnerability in the Border Gateway Protocol (BGP) to divert update requests to their own servers. This sneaky move allowed them to push malicious updates to unsuspecting users.

Analyst 207
Developer workstation with laptop, coding materials, and papers scattered on a desk in a bright, modern office space.

Iranian Hackers Deploy Cross-Platform Malware via Coding Tests

Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

Analyst 207
Network equipment rack with cables and patch cords in a data center interior.

BGP Hijack Targets Softaculous Traffic, Delivers Malware

In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing the attacker to intercept and compromise Virtualizor installations.

Analyst 207