Skip to main content

Malware & Ransomware

Dark cityscape with skyscraper vulnerability and shadowy figure holding damaged smartphone and laptop.

Zero-Day Exploits Proliferate as Breakout Times Shrink

Imagine a research preview that can teach itself to find and exploit the very flaws security teams scramble to patch - that's now a harsh reality, as an advanced language model has autonomously discovered and exploited zero-day vulnerabilities in every major operating system and browser. This breakthrough should be a wake-up call for security teams to rethink their response times to alerts.

Analyst 207
Shadowy figure hunched over laptop with fake website, surrounded by disarray and handcuffs.

FBI Disrupts W3LL Phishing Operation Linked to $20m in Fraud

The FBI has successfully dismantled a massive phishing operation built around the notorious W3LL phishing kit, which was linked to a staggering $20 million in fraud attempts. By taking down this operation, the bureau has disrupted a key tool used by cybercriminals to carry out their scams.

Analyst 207
Cracked smartphone surrounded by screens displaying distorted code with a looming figure in a dimly lit cityscape at dusk.

APT37 Exploits Facebook for RokRAT Malware Delivery

North Korean hackers APT37 have cleverly turned Facebook friend requests into a sneaky way to deliver RokRAT malware, exploiting our natural tendency to trust social connections. By accepting a friend request, victims unwittingly open the door to a remote access trojan that can compromise their device.

Analyst 207
Cracked smartphone screen with eerie glow, amidst tangled wires and broken keyboard key, set against a blurred Latin…

Kaspersky Uncovers JanelaRAT Malware Targeting Latin American Users

Kaspersky's Global Research and Analysis Team has uncovered a sophisticated malware campaign, dubbed JanelaRAT, that's specifically targeting users in Latin America with financial threats. This evolved malware has been detailed in a recent report, revealing its updated functionality and infection chain.

Analyst 207
Person sitting at desk with paperwork, laptop, and phone showing suspicious transaction notification.

Authorities Disrupt $12m Crypto Scam Targeting 20,000 Victims

A single click can be costly: over 20,000 crypto users across three countries fell victim to a $12 million approval phishing scam, tricked into handing over full access to their wallets. Thankfully, authorities swooped in, seizing the lost funds in a major cross-border crackdown dubbed Operation Atlantic.

Analyst 207
Moss-covered stone sphere sits on worn wood, moss unraveling, with blurred figure of hooded person typing in background.

Marimo Flaw Exploited for Credential Theft in Active Attacks

A critical vulnerability in Marimo is being actively exploited by attackers to steal sensitive credentials, and it requires no prior authentication to run code remotely. This flaw has severe consequences for organizations using Marimo, making it essential to take immediate action.

Analyst 207
Dark laptop screen with eerie glow, cracked CPU chip, tangled wires, and silhouette of person holding mysterious device.

CPUID Compromised, Trojanized Software Deploys STX RAT

For one day in April, unsuspecting users who visited CPUID.com, a trusted site for hardware-monitoring tools, unknowingly downloaded trojanized software that deployed a malicious remote access trojan called STX RAT. The compromised software, including CPU-Z and HWMonitor, turned a trusted resource into a malware delivery vehicle.

Analyst 207
Ancient jackal head sculpture looms over darkened tech HQ, with shattered laptop in foreground.

Anubis Ransomware Gang Targets Signature Healthcare in 2TB Data Heist

In a chilling 2TB data heist, the Anubis ransomware gang has struck Signature Healthcare in Massachusetts, stealing sensitive patient information despite claiming they didn't encrypt the hospital's systems. As the healthcare system scrambles to cope, patients are feeling the impact, with ambulance patients being diverted and clinicians forced to go old-school with paper records.

Analyst 207
Dark industrial landscape with a damaged control panel and eerie laptop glow.

Iranian Hackers Target Thousands of US Industrial Devices

Thousands of US industrial devices, including programmable logic controllers made by Rockwell Automation, have been targeted by Iranian-linked hackers, raising concerns about the vulnerability of critical infrastructure networks. This cyber campaign highlights the alarming risk to the networks we rely on every day.

Analyst 207
Laptop screen displays warning symbol amidst dim cityscape, with distorted padlock and cascading binary code.

CPUID Website Compromised, Serves Malware via HWMonitor Downloads

For six hours, unsuspecting visitors to the CPUID website were put at risk of having their passwords stolen when malicious malware was served in place of the HWMonitor tool they were trying to download. This alarming security breach highlights the vulnerability even trusted sites can have, leaving users to wonder if their sensitive information is safe.

Analyst 207

Ransomware Gangs Consolidate Power with Surge in Attacks

Alarming new data from cybersecurity firm Check Point reveals that just three ransomware gangs - Qilin, Akira, and Dragonforce - accounted for a staggering 40% of all ransomware incidents in March, with a whopping 269 attacks attributed to these groups alone. This concentration of power raises serious concerns about the growing threat of ransomware attacks.

Analyst 207
Shadowy figure lurking near laptop and payroll document, with Canadian coin on desk.

Microsoft Warns of Payroll Pirate Attacks on Canadian Employees

Beware of payroll pirate attacks: a financially motivated threat actor has been hijacking Canadian employees' accounts to steal their salary payments, leaving them with a nasty surprise on payday. Microsoft is sounding the alarm on this emerging threat, dubbed Storm-2755.

Analyst 207
Laptop on cluttered desk displays ominous warning icon on dashboard amidst eerie blue glow, with locked door and small gap…

Compromised Plugin Update Injects Backdoor into WordPress Sites

A widely used WordPress plugin, Smart Slider 3 Pro, was compromised when hackers hijacked its update system to push a poisoned version containing a backdoor, putting over 800,000 active installations at risk. This alarming breach raises critical questions about trust and security in the mechanisms we rely on to protect our online presence.

Analyst 207
Dark hospital corridor with hacker in shadows, surrounded by code, amidst broken medical equipment and a tangled stethoscope.

AI Tools Accelerate Healthcare Cyber Threats, Experts Warn

As AI tools become more advanced, experts warn that they can also supercharge healthcare cyber threats, autonomously identifying and exploiting software flaws at unprecedented speeds. This could lead to a dramatic surge in attacks on hospitals, clinics, and patients, making the threat landscape more treacherous than ever.

Analyst 207
Lone figure in hoodie types frantically on laptop beside shattered mask.

German Police Unmask REvil Leader in Cyber Crackdown

In a major cyber crackdown, German police have unmasked the leader of the notorious REvil gang, dealing a significant blow to the ransomware group, but also highlighting the ever-shifting threat landscape. As one threat subsides, new ones emerge, leaving defenders to prioritize scarce resources against an array of evolving threats.

Analyst 207
Dark laptop screen with ghostly university and Taiwan map images, surrounded by scattered papers.

LucidRook Malware Targets NGOs, Universities in Taiwan

A sneaky new malware called LucidRook has set its sights on non-governmental organizations and universities in Taiwan, using spear-phishing to catch its victims off guard. This Lua-based threat is the latest cyber attacker to target these vulnerable sectors.

Analyst 207
Shadowy figure looms behind a login page on a laptop screen, poised to submit credentials.

VENOM Phishing Attacks Target C-Suite Microsoft Logins

A new phishing-as-a-service platform called VENOM is making it alarmingly easy for hackers to target senior executives, specifically seeking their Microsoft logins. This compact toolkit is putting the keys to the corner office within reach of any motivated adversary, leaving security teams scrambling to respond.

Analyst 207
Ominous cityscape with giant cracked smartphone screen looming over skyscrapers, a concerned figure stands in foreground.

EngageLab SDK Flaw Compromises 50M Android Users

A security flaw in the EngageLab SDK has put a whopping 50 million Android users at risk, allowing apps on the same device to bypass Android's security sandbox and gain unauthorized access to sensitive information. This vulnerability, now patched, exposed cryptocurrency wallet users and others to potential data breaches.

Analyst 207
Dimly lit hospital corridor with a laptop screen displaying a ransom note and blurred medical file.

Ransomware Attack Cripples Dutch Healthcare IT Firm ChipSoft

A ransomware attack on Dutch healthcare IT firm ChipSoft has left patients and clinicians scrambling, as clinical portals and scheduling tools went dark, disrupting critical care management systems. The devastating cyber incident forced ChipSoft to take its website and digital services offline, leaving many wondering who's left holding the chart.

Analyst 207
Handcuffs and laptop with cryptocurrency dashboard on a desk, with scattered papers and broken globe nearby.

Law Enforcement Disrupts $45 Million Global Cryptocurrency Scam

In a major breakthrough, law enforcement agencies in the US, UK, and Canada joined forces to disrupt a massive $45 million global cryptocurrency scam, freezing $12 million in stolen funds and identifying over 20,000 linked wallet addresses. This significant action not only recovered funds for victims but also shed light on the darker side of digital cash and the challenges of accountability in the crypto world.

Analyst 207
Dark cityscape at dusk with a lone figure near a cracked wall, shattered smartphone in foreground.

Mythos Model Unleashes Zero-Day Exploit Capabilities for Mass Use

The game has changed: a new AI model called Mythos can now uncover devastating zero-day flaws in software and chain them together to create powerful exploits, putting this potent capability in the hands of anyone with an internet connection. This development blurs the lines between nation-state hackers and amateur cyber attackers, raising urgent questions about the future of cybersecurity.

Analyst 207
Person in a hoodie surrounded by screens with helpdesk software, face obscured, in a dark room with cityscape visible…

Phishing Gang Targets Dozens of Corporations in Helpdesk Scam Spree

Beware of the person on the other end of the line - a new phishing gang is impersonating IT helpdesks to scam dozens of major corporations, leaving investigators racing to keep up. Google is sounding the alarm on this latest extortion tactic, which uses clever social engineering to catch victims off guard.

Analyst 207
Dimly lit office scene with a hooded figure in shadows, laptop casting eerie glow, Taiwanese map pin on cluttered desk.

UAT-10362 Launches LucidRook Malware in Taiwanese NGO Spear-Phishing Attacks

A mysterious threat cluster, UAT-10362, has launched a targeted spear-phishing attack on Taiwanese NGOs and universities, deploying a newly discovered malware called LucidRook. This sophisticated attack raises urgent concerns for Taiwanese civil-society groups, highlighting the need for heightened vigilance and robust defenses.

Analyst 207

New Trojan STX RAT Targets Finance Sector with Sophisticated Stealth Methods

Meet STX RAT, a sneaky new remote access trojan that's got its sights set on the finance sector, using advanced stealth methods and command-and-control capabilities to evade detection. This latest threat is a wake-up call for defenders, testing their readiness to respond to increasingly sophisticated attacks.

Analyst 207