Skip to main content

Malware & Ransomware

Italian financial police officers gather around a table with seized devices and paperwork in a bright, modern briefing room.

Italy Disrupts CINEMAGOAL Piracy App

In a major crackdown on piracy, Italian financial police have dismantled a sophisticated operation built around the CINEMAGOAL app, seizing material and launching an investigation to track down those involved and quantify the illicit gains. The CINEMAGOAL app had been evading security blocks and enhancing viewing quality to stay one step ahead of authorities.

Analyst 207
Cluttered desk with laptop showing PHP project, surrounded by coffee cups and coding notes in a modern office.

Malicious Laravel-Lang Packages Deliver Cross-Platform Credential Stealer

A massive wave of malicious Laravel-Lang packages, with over 700 versions released in just two days, has been used to spread a sneaky cross-platform credential stealer. Security researchers warn that multiple PHP packages from the Laravel-Lang organization were compromised, hinting at a large-scale breach of the organization's release process.

Analyst 207
A Drupal website's backend system on a minimalist desk with code on a laptop screen.

Drupal Core SQL Injection Flaw Actively Exploited

Drupal has confirmed that exploit attempts for a critical SQL injection flaw, CVE-2026-9082, are being actively detected in the wild, posing a significant risk of privilege escalation and remote code execution. This vulnerability affects all supported Drupal Core versions and can lead to full site compromise if not addressed promptly.

Analyst 207
Smartphone on a table displays a messaging app chat interface with many subscribers.

Russian Hacker Exploits Jailbroken AI in Crypto Fraud Scheme

A solo Russian hacker, known as bandcampro, has orchestrated a massive crypto fraud scheme, reaching 17,000 subscribers on Telegram with AI-generated content that convincingly mimicked popular conspiracy styles. This alarming development marks a turning point in cybercrime conspiracies, with AI-powered threats on the rise.

Analyst 207
Law enforcement officials gather at a modern facility with a large glass wall, symbolizing a coordinated international…

Authorities Disrupt First VPN Service Used by 25 Ransomware Groups

In a major win for cybersecurity, an international coalition led by France and the Netherlands has disrupted a notorious VPN service used by 25 ransomware groups, taking a significant blow to cybercrime operations. The takedown was made possible through a collaborative effort involving 16 countries and key partners like Europol and Eurojust.

Analyst 207
Government office workstation with papers and supplies, email inbox blurred on screen.

Ghostwriter Exploits Ukraine Government with Prometheus Phishing Malware

Malicious actors known as Ghostwriter have launched a cunning phishing campaign targeting Ukraine's government, using emails that appear to come from trusted sources and contain links to a seemingly harmless learning platform, Prometheus. These emails contain a hidden threat that can download malware onto victims' devices.

Analyst 207
Modern tech facility with laptop workstation and blank screen.

Iran-nexus APT Expands Espionage Ops with New RAT Variants

Unit 42 researchers have uncovered a sophisticated espionage campaign by an Iran-linked threat group, dubbed Screening Serpens, which has deployed six new remote access Trojan (RAT) variants to target entities across the US, Israel, and the Middle East. These variants, part of two distinct malware families, signal a significant expansion of the group's cyber spying operations.

Analyst 207
Person sitting at desk with laptop, papers, and office supplies, with files spilling from nearby cabinet.

Cloud Atlas Expands Arsenal with New Tools, Payloads

Cloud Atlas is beefing up its toolkit with fresh tools and payloads, including a blast from the past - the notorious CVE-2018-0802 Microsoft Office Equation Editor vulnerability. The group is also reviving its use of ZIP archives with malicious LNK shortcuts that trigger PowerShell scripts, keeping security experts on high alert.

Analyst 207
Rows of computer servers and networking equipment in a server room or network operations center.

Drupal Sites Targeted in SQL Injection Attacks

Drupal sites are under attack as SQL injection exploits are now being detected in the wild, taking advantage of a vulnerability that can be triggered without authentication. This critical flaw, CVE-2026-9082, allows attackers to execute arbitrary SQL and potentially run remote code, putting sites that use PostgreSQL at risk.

Analyst 207
Developer workstation with laptop, papers, and office supplies, cityscape visible through window.

Cyber Thieves Exploit SEO to Spread Infostealers via Fake AI Sites

Cyber thieves are using clever SEO tricks to spread infostealers through fake AI sites, targeting enterprise users and developer workstations with a potent mix of imitation and in-memory malware. This brief but potent campaign has been meticulously planned, with malicious domains deployed as early as March 2026.

Analyst 207

Canada Arrests Kimwolf DDoS Botnet Operator in US-Led Crackdown

In a major cybercrime crackdown, a 23-year-old Canadian man, Jacob Butler, has been arrested and charged with operating the notorious Kimwolf DDoS botnet, which targeted vulnerable devices like digital photo frames and web cameras. If convicted, Butler faces up to 10 years in prison for aiding and abetting computer intrusion.

Analyst 207
Law enforcement officials stand near a podium with emblem in a government building.

US Charges Suspected Kimwolf Botnet Admin in Global Crackdown

In a major global crackdown, 23-year-old Jacob Butler, aka "Dort", has been arrested in Ottawa and charged with running the notorious KimWolf botnet, which infected nearly 2 million devices and fueled some of the largest DDoS attacks on record. Butler now faces extradition to the US and serious consequences for his alleged role in the massive cyber operation.

Analyst 207
Law enforcement scene with Ontario Provincial Police emblem, daylight through tall windows.

Botmaster 'Dort' Arrested in Canada, Charged in US Over Kimwolf Botnet

A 23-year-old Canadian man, known online as "Dort," has been arrested and charged for masterminding the massive Kimwolf botnet, which was linked to record-breaking DDoS attacks of nearly 30 Terabits per second. The suspect, Jacob Butler, is now in custody awaiting an initial court hearing.

Analyst 207
Formal law enforcement setting with podium and documents in daylight.

Canada Arrests Suspect Tied to Kimwolf Botnet Operation

In a major breakthrough, Canadian authorities have arrested 23-year-old Jacob Butler, aka "Dort", for his alleged role as a key administrator of the notorious Kimwolf botnet operation, which infected over 2 million Android TV devices worldwide. The arrest marks a significant step in the fight against one of the most widespread distributed-denial-of-service (DDoS) botnets on record.

Analyst 207
Dimly lit network closet with server racks and a lone workstation.

Linux Malware Showboat Targets Telecom with SOCKS5 Proxy Backdoor

Meet Showboat, a sneaky Linux malware that's targeting telecom systems with its powerful SOCKS5 proxy backdoor, allowing hackers to spawn remote shells, transfer files, and carry out covert operations. This modular menace can quietly infiltrate and take control, making it a major threat to Linux systems.

Analyst 207
Cramped network closet with equipment and cables, and a single laptop in the foreground.

Chinese hackers infiltrate telcos with Showboat, JFMBackdoor malware

Chinese-aligned hackers have been secretly infiltrating telecommunications providers across Asia Pacific and the Middle East since mid-2022, using sneaky malware like Showboat and JFMBackdoor to stay under the radar. They even used a clever "hide" command to conceal their digital footprints on infected machines.

Analyst 207
Dimly lit underground forum with individuals around a table surrounded by computer equipment and screens.

Crypto Drainers Evolve Into Sophisticated Service Platforms

Meet the modern Drainer-as-a-Service model, where affiliates supply victims through phishing links and fake websites, while the service handles the technical heavy lifting, including signatures, approvals, and token transfers, with operators taking a 20% commission from successful scams. This sophisticated platform is a far cry from ad-hoc phishing, with a business model that's both lucrative and alarmingly efficient.

Analyst 207
Law enforcement officials stand in front of seized servers in a briefing room.

Law Enforcement Disrupts First VPN Service Tied to Ransomware Attacks

In a major cybercrime crackdown, law enforcement agencies have dismantled a notorious VPN service used by ransomware attackers, seizing 33 servers and taking its domains offline in a coordinated operation across 27 countries. The takedown of First VPN, a so-called "no-logs" provider, has dealt a significant blow to threat actors behind ransomware and data theft campaigns.

Analyst 207
Modern tech lab with computer workstations and equipment, featuring a prominent blank laptop screen.

Microsoft Disrupts Zero-Day Attacks with Defender Patch Rollout

Microsoft is taking swift action to protect its users from zero-day attacks with an emergency patch rollout for its Defender software, ensuring that even the most vulnerable systems are safeguarded. The update addresses two critical vulnerabilities that were being actively exploited by hackers.

Analyst 207
Brightly-lit network operations room with equipment racks and cables, laptop screen blurred in foreground.

Hackers Exploit SonicWall VPN Flaw to Bypass MFA

In a shocking exploit, hackers have successfully bypassed multi-factor authentication on SonicWall VPN devices, breaching security in as little as 30 minutes. ReliaQuest researchers detected the first in-the-wild exploitation of CVE-2024-12802, warning of a swift and stealthy threat.

Analyst 207
Law enforcement briefing room with laptop, papers, and blurred emblem on the wall.

Ukraine Cracks Down on Infostealer Operator Linked to 28,000 Stolen Accounts

Ukrainian cyberpolice, in collaboration with US law enforcement, have cracked down on an 18-year-old suspect behind a massive infostealer malware campaign that compromised 28,000 accounts, with over 5,800 used for fraudulent activities. The suspect allegedly ran the operation, selling stolen session data from a California online store between 2024 and 2025.

Analyst 207
Person holding smartphone with blank screen in crowded transit platform.

Android Malware Campaign Silently Invoices Users via Fake Apps

Malware hidden in nearly 250 fake Android apps has been silently invoicing users for premium services, with victims largely unaware of the charges. The sneaky campaign, dubbed Premium Deception, targeted subscribers in several countries, including Malaysia, Thailand, Romania, and Croatia, over a 10-month period.

Analyst 207
Rows of servers and equipment in a data center, some partially disassembled.

Microsoft Disrupts Malware-Signing Service Used in Ransomware Attacks

Microsoft swooped in to shut down a notorious malware-signing service, seizing the website signspace.cloud and taking down hundreds of virtual machines used to fuel ransomware attacks. This bold move, dubbed OpFauxSign, crippled a key operation run by the threat actor Fox Tempest, which had been using Microsoft's own system against them since May 2025.

Analyst 207
Software development workspace with laptop, notes, and monitor displaying lines of code in a neutral-colored room with…

Mini Shai-Hulud Worm Targets AntV Ecosystem with Coordinated npm Package Attack

In a shocking one-hour surge, 639 malicious versions were pushed across 323 unique npm packages, crippling the AntV ecosystem with a massive coordinated attack linked to the Mini Shai-Hulud worm. This brazen move was designed not only to spread chaos but also to slow down analysis and detection efforts.

Analyst 207