Skip to main content

Malware & Ransomware

Empty Russian office network room with rows of computer servers and networking equipment.

PhantomCore Exploits TrueConf Flaws to Breach Russian Networks

Researchers Daniil Grigoryan and Georgy Khandozhko revealed that PhantomCore attackers exploited a chain of three TrueConf Server vulnerabilities, including insufficient access control and file reading flaws, to breach Russian networks. This sophisticated attack highlights the importance of addressing these critical vulnerabilities to protect against potential threats.

Analyst 207
Researcher examines smartphone with fake CAPTCHA webpage, surrounded by investigation documents.

Cybersecurity Researchers Expose Global SMS, Crypto Fraud Ring

Beware of fake CAPTCHAs that can drain your wallet! A cunning SMS scam routes victims to bogus web pages, tricking them into sending costly texts to over 50 international destinations.

Analyst 207
Person interacting with a blurred payment terminal in a retail setting.

BlackFile Group Launches Vishing Attacks on Retail, Hospitality Firms

Retail and hospitality firms are under siege from a financially motivated threat group, known as BlackFile Group, that's launching vishing attacks to extort money, with a campaign that has been quietly escalating since February 2026. This persistent threat uses no custom malware, making it a stealthy and formidable foe.

Analyst 207
Laptop screen displays Microsoft Teams conversation in bright office setting.

Microsoft Teams Used to Deploy Sophisticated Snow Malware

Cyber attackers have cleverly used Microsoft Teams to deploy a sophisticated malware suite, dubbed Snow, by tricking victims into installing a fake anti-spam patch that ultimately led to prolonged access, credential theft, and domain compromise. They started by creating a sense of urgency through email bombing, then followed up with a direct message on Microsoft Teams.

Analyst 207
Industrial control system interface on a computer screen with blurred machinery in the background.

Researchers Uncover 'fast16' Malware Targeting Engineering Software Years Before Stuxnet

Researchers have uncovered a long-forgotten malware, fast16, that was designed to sabotage engineering software, beating even the infamous Stuxnet by at least five years. This ancient cyber threat, dating back to 2005, was engineered to spread rapidly and produce inaccurate calculations across entire facilities.

Analyst 207
Person at desk looks at laptop with Microsoft Teams on screen, background webpage blurred.

Google Exposes Microsoft Teams Phishing Campaign Using Custom Snow Malware

Beware of scammers posing as helpdesk heroes! They'll flood your inbox with spam, then reach out on Microsoft Teams with a fake fix that actually steals your password using custom Snow malware.

Analyst 207
Rows of networking gear on racks in a federal network operations center with a hint of concern.

CISA Warns of Persistent Cisco Backdoor on Federal Networks

The Cybersecurity and Infrastructure Security Agency (CISA) has detected a sneaky backdoor, dubbed Firestarter, lurking on federal networks, which may not have been fully eliminated by Cisco's recent patches. Federal agencies are now on high alert, urged to hunt for this stealthy malware that could compromise their networks.

Analyst 207
Cisco firewall device on a network equipment rack in a dimly lit data center.

Firestarter Malware Evades Cisco Firewall Updates, Persists Across Reboots

A custom backdoor called Firestarter has been discovered evading Cisco firewall updates and persisting across reboots, posing a significant threat to cybersecurity. This sophisticated malware is attributed to a threat actor linked to cyberespionage campaigns, including the notorious ArcaneDoor operation.

Analyst 207
Retail customer service desk with blurred computer screen nearby in daytime setting.

BlackFile Targets Retail with Vishing Extortion Tactics

Meet BlackFile, a financially motivated group that's been wreaking havoc on retail and hospitality organizations with a clever vishing extortion tactic, posing as IT support staff to steal data since February 2026. They're using spoofed VoIP numbers and fake Caller ID names to pull off their scams.

Analyst 207
Network equipment and security appliances in a brightly lit industrial control room.

CISA Exposes Persistent FIRESTARTER Backdoor in Cisco Devices

CISA and NCSC have uncovered a sneaky FIRESTARTER backdoor lurking in Cisco devices, allowing hackers to regain control even after patches are applied. This persistent threat can leave devices vulnerable to re-entry, putting your entire network at risk.

Analyst 207
Network operations center with computer workstations and equipment showing subtle signs of a security breach.

CISA Uncovers Firestarter Backdoor in Federal Network

The Firestarter backdoor was a masterfully crafted threat that allowed attackers to maintain secret access to compromised networks even after they'd been updated, essentially giving them a backdoor key to re-enter without having to exploit new vulnerabilities. This sneaky tactic left victims vulnerable to repeat attacks, highlighting the need for robust cybersecurity measures.

Analyst 207
NASA employees work at desks with laptops and computers in a well-lit office setting.

NASA Targeted in Chinese Phishing Scheme for U.S. Defense Software

For years, unsuspecting NASA employees and collaborators were duped into sharing sensitive US defense software with a Chinese national masquerading as a colleague, in a brazen phishing scheme that went undetected for years. The scam funneled top-secret aerospace and defense tech to the imposter, violating US export control laws in the process.

Analyst 207
Laptop screen shows an open email message in a brightly-lit office setting.

Zimbra Servers Targeted in Ongoing XSS Attacks

Beware of sneaky phishing emails that can hijack your Zimbra server with just a glance - no clicks or downloads required. A single malicious email can trigger a cross-site scripting attack, thanks to a recently patched vulnerability, CVE-2025-48700.

Analyst 207
Person holding smartphone with scattered papers in foreground, standing in blurred city or coffee shop background.

Malicious Apps Expose Crypto Investors to Seed Phrase Theft on App Store

Beware of malicious apps on the App Store that masquerade as popular cryptocurrency wallets, aiming to steal your crypto seed phrase and drain your funds. These fake apps, uncovered by Kaspersky researchers, can trick you into revealing sensitive information with just a few taps.

Analyst 207
Laptop screen shows blurred PDF as trojanized document is opened in quiet workspace.

Tropic Trooper Exploits SumatraPDF to Deploy AdaptixC2

Meet Tropic Trooper, a notorious cyber threat group that's been wreaking havoc since 2011, and learn how they've cleverly exploited SumatraPDF to deploy their AdaptixC2 malware. Their latest tactic involves using GitHub as a command-and-control platform to target Chinese-speaking individuals in Taiwan, as well as users in South Korea and Japan.

Analyst 207
A researcher examines computer equipment in a dimly lit, cluttered forensics lab.

Researchers Uncover Pre-Stuxnet Cyber-Sabotage Malware

Meet fast16, a stealthy cyber-sabotage malware that went undetected until now, marking a new era in covert statecraft. Discovered by SentinelOne researchers, this silent threat has been hiding in plain sight since 2016.

Analyst 207
Control room of a water treatment plant with a computer workstation in the foreground and blurred equipment in the…

New Malware ZionSiphon Targets Water Plants, Falls Flat

A new piece of malware called ZionSiphon, reportedly targeting Israeli water facilities, has been found to be surprisingly inept, with experts describing it as broken and showing little understanding of its supposed targets. The malware's code includes strings referencing the Israeli water sector and politically charged messaging, but its overall incompetence has downplayed initial alarm.

Analyst 207
Close-up of Cisco network security device with outer casing removed, revealing internal components on a laboratory bench.

Hackers Exploit Cisco Firewalls with Persistent Backdoor

A custom implant called Firestarter can infiltrate Cisco network security devices, evading patches and routine reboots by manipulating device boot configuration to restore itself. Only a hard reboot, physically disconnecting the device from its power supply, can clear the persistence mechanism from memory.

Analyst 207
Living room with router and smart device on coffee table near window.

Chinese Hackers Exploit IoT Devices to Obscure Nation-State Attacks

Chinese hackers are sneaking nation-state attacks under the radar by hijacking everyday IoT devices, such as home routers and smart cameras, to hide their digital footprints. This stealthy tactic allows them to evade accountability and strike from the shadows.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit server room.

Trigona Ransomware Exploits Custom Tool for Swift Data Exfiltration

Trigona ransomware attackers have unleashed a custom-built, command-line tool that turbocharges data theft, allowing them to siphon off sensitive information with lightning speed and razor-sharp efficiency. This potent tool is the latest weapon in their arsenal, enabling faster and more efficient data exfiltration from compromised environments.

Analyst 207
Laptop screen displays Microsoft Teams chat invitation on office desk with papers and chair in background.

Threat Actors Exploit Microsoft Teams for SNOW Malware Deployment

Cyber attackers are exploiting Microsoft Teams by impersonating IT helpdesk staff, tricking victims into accepting chats from unfamiliar accounts and deploying SNOW malware. They start by flooding inboxes with urgent emails, then pose as IT support over Teams, offering to fix the problem.

Analyst 207
Cluttered office desk with computer, papers, and open smartphone showing an email inbox.

UNC6692 Exposes Custom Malware Suite via Social Engineering

In a clever social engineering ploy, UNC6692 launched a massive email campaign in late December 2025, flooding targets with messages to create a sense of urgency and distraction, before following up with a convincing Microsoft Teams message that pushed a malicious link. The attackers then cleverly disguised their malware as a legitimate "Mailbox Repair and Sync Utility" patch, hosted on an Amazon S3 page.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit data center with a single laptop in the foreground.

AI Targets Cloud Environments With Autonomous Attacks

Imagine a future where AI launches devastating cloud attacks with minimal human intervention - a threat that's no longer theoretical, but a harsh reality as demonstrated by a recent state-sponsored espionage campaign where AI executed 80-90% of the attack autonomously. Palo Alto Networks' Unit 42 has taken this threat to the next level by building a proof-of-concept AI model called Zealot that can execute end-to-end cloud attacks.

Analyst 207
Government agency office interior with subtle computer equipment hints.

Eset Exposes Chinese Hackers' Careless Backdoor Tactics

Chinese hackers have been caught off guard by their own carelessness, leaving behind a digital trail that exposed their previously undetected backdoor tactics. Researchers uncovered over 9,000 messages revealing the attackers' testing systems and habits, leading to the identification of a Chinese nation-state actor dubbed GopherWhisper.

Analyst 207