Skip to main content

Malware & Ransomware

A blurred figure in a suit sits or stands with their back to the camera in a government building interior with a judge's…

Karakurt Ransomware Operative Sentenced for Extortion Role

Meet Deniss Zolotarjovs, a Latvian national who helped his ransomware gang extort dozens of companies - and even a government entity with a crippled 911 system - by leveraging stolen sensitive data, including children's health information. He's now facing 8.5 years in prison for his role in the Karakurt extortion operation.

Analyst 207
Brightly lit computer workstation with generic gaming peripherals and cables against a neutral background.

ScarCruft Expands Malware Arsenal with Multi-Platform BirdCall Backdoor

ScarCruft hackers have launched a sneaky attack on a popular video game platform, infecting both Windows and Android users with a new backdoor called BirdCall. The multi-platform threat has been targeting ethnic Koreans in China since late 2024, allowing hackers to gain unauthorized access.

Analyst 207
Smartphone on a cluttered gaming desk with blurred Android game interface.

North Korean Hackers Infiltrate Android Games to Spy on Defectors

Security researchers at Eset stumbled upon a sneaky plot by North Korean hackers, who infiltrated popular Android games to spy on defectors by hiding a backdoor called BirdCall in the apps. The malicious code was cleverly disguised in game files available for download on a regional gaming platform's official website.

Analyst 207
People play games at computers in a crowded internet cafe with a potentially infected system in the background.

ScarCruft hackers deploy BirdCall malware via gaming platform.

North Korean hackers APT37, also known as ScarCruft, have cleverly expanded their BirdCall malware to target Android devices, adapting their Windows backdoor to spy on mobile users. They even used a popular gaming platform to sneak the malware onto unsuspecting devices.

Analyst 207
Laptop workstation in a brightly-lit hospital corridor with medical equipment and computers in the background.

Microsoft Exposes Large-Scale Phishing Campaign Targeting 35,000 Users Worldwide

A massive phishing campaign targeting over 35,000 users worldwide has been uncovered, using sophisticated email templates that convincingly masquerade as legitimate internal communications. The highly convincing lures successfully hit organizations across 26 countries, with a staggering 92% of targets based in the US.

Analyst 207
Dimly lit, abandoned cryptocurrency trading room with scattered papers and broken equipment.

Grinex Shutdown Won't Curb Russian Sanctions Evasion

The shutdown of Grinex, a Kyrgyzstan-registered cryptocurrency exchange, highlights the cat-and-mouse game of sanctions evasion, where experts warn that the ecosystem's fragmentation will only make it harder to track illicit activity. As Kaitlin Martin, a senior intelligence analyst at Chainalysis, notes, a fractured ecosystem makes it increasingly difficult to target evasive maneuvers.

Analyst 207
Data storage room with rows of file cabinets and servers, and an open laptop in the foreground.

Ransomware Gang Exposes Alleged Liberty Mutual Data Trove

A massive 108-gigabyte data trove allegedly stolen from Liberty Mutual has been exposed by ransomware gang Everest Group, containing sensitive policyholder information including names, addresses, and financial details. The group claims to have published the data after the insurance company failed to respond to its demands.

Analyst 207
Brightly-lit industrial server room with a generic controller on the wall.

Hackers Exploit Weaver E-cology Bug in Targeted Attacks

Hackers are taking advantage of a critical bug in Weaver E-cology, using an exposed debug API endpoint to execute system commands on vulnerable servers without needing login credentials. This security flaw, tracked as CVE-2026-22679, affects Weaver E-cology 10.0 builds prior to March 12.

Analyst 207
Rows of servers and network equipment in a data center appear vulnerable with some areas blurred or out of focus.

AI-Driven Attacks Infiltrate Cloud Environments

Stay ahead of the threats: as AI-driven attacks infiltrate cloud environments, it's crucial to adopt a proactive, holistic approach to risk reduction and protect your critical assets and data. Google Cloud and XM Cyber warn that understanding how attackers move laterally throughout your network is key to safeguarding against emerging AI-driven threats.

Analyst 207
Cloud-based email service dashboard on laptop screen with blurred interface, surrounded by a brightly-lit institutional…

Phishing Attacks Exploit Amazon SES to Evade Detection

Kaspersky researchers have uncovered a surge in phishing attacks that cleverly exploit Amazon's trusted email service to evade detection. By using valid Amazon SES credentials, attackers can send convincing phishing messages that slip past standard security checks.

Analyst 207
Hospital corridor with staff and patients, calm yet concerned atmosphere.

Ransomware Breach Exposes Sensitive Data at Sandhills Medical Foundation

Sandhills Medical Foundation suffered a devastating ransomware attack on May 8, 2025, putting sensitive data at risk. It took nearly 11 months for affected individuals to be notified in April 2026, sparking an investigation into the breach.

Analyst 207
Well-lit IT workstation with computer screens and equipment in a small business network operations area.

Phishing Campaign Exploits Legitimate RMM Tools to Hit 80+ Orgs

A sneaky phishing campaign has infiltrated over 80 organizations, mostly in the US, by exploiting legitimate remote monitoring and management (RMM) tools like SimpleHelp and ScreenConnect. The attackers cleverly used customized versions of these tools, already installed by the victims, to bypass defenses and gain unauthorized access.

Analyst 207
Blurred computer screen in a bright office setting with a suspicious email message on screen.

Attackers Exploit Amazon SES to Bypass Email Security in Phishing Campaigns

Phishing campaigns are now using Amazon's Simple Email Service to make malicious messages look legit, bypassing standard email security checks and putting victims at risk of revealing sensitive data. By exploiting Amazon SES's trusted reputation and authentication features, attackers are making it harder to spot phishing emails.

Analyst 207
Cluttered IT workspace with Linux workstation and monitor displaying terminal output.

Cybercrime Groups Exploit AI for Rapid, High-Impact Attacks

Cybercrime groups are leveraging AI to launch lightning-fast, high-impact attacks, outpacing security patches and leaving devastating consequences in their wake. This week, a critical vulnerability in cPanel and WHM was exploited, leading to website wipes, botnet deployments, and ransomware attacks.

Analyst 207
Formal courthouse or government building interior with subtle seal emblem.

Cybersecurity Experts Imprisoned for Ransomware Extortion Scheme

Two American cybersecurity experts, Ryan Goldberg and Kevin Martin, have been sentenced to prison for their roles in a brazen 2023 ransomware campaign that targeted companies across the United States. Their crimes have brought to light the severe consequences of cyberattacks and the importance of protecting businesses from such threats.

Analyst 207
Person sitting at desk in dimly lit office, looking at laptop screen with phishing email, surrounded by papers and…

Silver Fox Targets India, Russia with ABCDoor Malware via Tax Phishing

Meet Silver Fox, a China-based cybercrime group that's using tax phishing scams to deliver a sneaky new malware called ABCDoor, targeting India and Russia with cleverly crafted emails that masquerade as official tax notices. The group's tactics involve PDFs with links to infected archives, tricking victims into downloading the malware.

Analyst 207
Dimly lit teenage bedroom with laptop on messy desk, cityscape visible through window.

AI-Assisted Attacks Surge as Barrier to Entry Drops

A 17-year-old with no coding experience was recently arrested for hacking into Kaikatsu Club and stealing 7 million users' personal data - his motive? To fund his Pokémon card habit. This shocking case highlights a disturbing trend: nontechnical individuals are now using AI-powered tools to launch devastating cyberattacks.

Analyst 207
Linux workstation setup on a clean surface with technical books and notes in a quiet office.

CISA Warns of Active Linux Exploit

A newly discovered Linux kernel bug, dubbed "Copy Fail," allows unprivileged users to gain root privileges on unpatched systems, prompting urgent warnings from CISA and researchers. If your Linux system was built between 2017 and the recent patch, you're at risk - and need to act fast to protect yourself.

Analyst 207
Law enforcement officers from multiple countries stand united in a daytime scene, conveying authority and cooperation in a…

Global Crackdown Targets Crypto Scam Centers, Arrests 276

In a major global crackdown, authorities have arrested 276 suspects and shut down nine cryptocurrency scam centers, dealing a significant blow to fraudsters targeting Americans from abroad. This coordinated effort, led by Dubai Police and involving the FBI and China's Ministry of Public Security, sends a clear message: scammers can't hide from the law, no matter where they are in the world.

Analyst 207
Smartphone displaying a blurred Telegram app screen on a neutral surface with a cityscape in the background.

Telegram Abused for Crypto Scams and Android Malware Delivery

Researchers uncovered a massive scam operation, dubbed FEMITBOT, that uses Telegram's Mini Apps to spread fake crypto platforms, brand impersonations, and Android malware, with a single API string tying it all together. Victims are lured in with a convincing, app-like interface that tricks them into divulging sensitive info.

Analyst 207
Linux web hosting control panel setup in a server room with out-of-focus laptop screen nearby.

cPanel flaw fuels mass Sorry ransomware attacks

A critical flaw in cPanel, tracked as CVE-2026-41940, has been exploited in a massive ransomware campaign, compromising at least 44,000 IP addresses. This alarming attack has already been used in the wild as a zero-day, with threat actors accessing control panels and wreaking havoc on web hosting systems.

Analyst 207
Person's hand reaching for laptop keyboard on a desk in a brightly-lit office setting.

North Korea Exploits Fake Meetings to Fuel Crypto Heists

North Korea is using fake video meetings to trick people into crypto scams, fueling a growing concern in the world of cryptocurrency. This clever tactic is just one of the many evolving methods threat actors are using to steal money.

Analyst 207
Hospital corridor with people walking, laptop on administrator's desk near large windows.

Ransomware Defenses Hold, But New AI Threats Emerge

While ransomware defenses have shown significant improvement, experts warn that complacency is a luxury we can't afford, especially with hospital systems remaining prime targets. New AI threats are emerging, demanding our attention and action.

Analyst 207
Concerned person checks laptop in small workspace, conveying vulnerability.

Vietnamese Hackers Exploit Google AppSheet in 30,000-Account Facebook Phishing Spree

A massive phishing operation, dubbed AccountDumpling, has compromised around 30,000 Facebook accounts using a clever tactic: sending malicious emails from a legitimate Google AppSheet address to bypass spam filters. This sophisticated scam was more than just a simple phishing kit - it was a constantly evolving operation with real-time control panels and a lucrative criminal enterprise.

Analyst 207