Skip to main content

Malware & Ransomware

Drift Protocol Exploited for $285 Million in Novel Social Engineering Attack

Drift Protocol Exploited for $285 Million in Novel Social Engineering Attack

In a shocking turn of events, the Drift Protocol, a Solana-based decentralized exchange, was exploited for a staggering $285 million in a highly sophisticated social engineering attack involving durable nonces. This novel attack allowed malicious actors to swiftly gain control of the platform's administrative powers, resulting in a massive loss of funds.

Analyst 207
Engineer Pleads Guilty to Ransomware Extortion Plot Targeting Industrial Firm

Engineer Pleads Guilty to Ransomware Extortion Plot Targeting Industrial Firm

A former infrastructure engineer has pleaded guilty to a ransomware extortion plot that targeted his own employer, an industrial firm in New Jersey, by locking administrators out of 254 servers. This shocking breach of trust highlights the devastating consequences of insider threats in the digital age.

Analyst 207
Malware Resurfaces in Mobile Apps, Targets Crypto Wallets

Malware Resurfaces in Mobile Apps, Targets Crypto Wallets

Beware of a sneaky new malware hiding in plain sight on both app stores, designed to steal sensitive crypto wallet recovery phrases from unsuspecting users. This deceptive SparkCat variant masquerades as harmless apps, putting your digital assets at risk.

Analyst 207
Drift Protocol Exploited for $280 Million by North Korean Hackers

Drift Protocol Exploited for $280 Million by North Korean Hackers

In a shocking and sophisticated attack, North Korean hackers seized control of the Drift Protocol's Security Council, resulting in a staggering loss of at least $280 million. This brazen exploit raises serious questions about the security of even the most trusted blockchain platforms.

Analyst 207
Hackers Exploit React2Shell Flaw to Breach 766 Next.js Hosts

Hackers Exploit React2Shell Flaw to Breach 766 Next.js Hosts

In a massive credential harvesting operation, hackers exploited the React2Shell vulnerability to breach 766 Next.js hosts, scooping up sensitive database credentials, SSH private keys, and other valuable secrets. This single software flaw was turned into an automated threat, compromising hundreds of sites and putting their digital kingdoms at risk.

Analyst 207
Iowa AG Targets Change Healthcare Over Ransomware Lapses

Iowa AG Targets Change Healthcare Over Ransomware Lapses

Iowa's attorney general is taking a stand against UnitedHealth Group, seeking financial damages and major security overhauls after a devastating 2024 ransomware attack on its Change Healthcare unit. The bold move aims to hold the healthcare giant accountable and prevent similar cyberattacks in the future.

Analyst 207
GitHub Exposed to Infostealer Malware via Claude Code Leak

GitHub Exposed to Infostealer Malware via Claude Code Leak

A recent leak of Claude's source code has taken a dark turn, with hackers exploiting the situation to spread Vidar, a notorious infostealer malware, by creating fake GitHub repositories that masquerade as legitimate projects. This cleverly crafted bait is luring unsuspecting users into a trap that can have serious cybercrime consequences.

Analyst 207
Drift Protocol Compromised in $280 Million Heist

Drift Protocol Compromised in $280 Million Heist

In a shocking, high-stakes heist, a sophisticated threat actor exploited a vulnerability in Drift Protocol's governance, seizing control of its Security Council and making off with at least $280 million in a single, precision strike. This brazen breach serves as a stark reminder of the devastating consequences of compromised governance controls.

Analyst 207
Malware Infiltrates Leaked Claude Code Downloads

Malware Infiltrates Leaked Claude Code Downloads

Tens of thousands of people who downloaded the leaked Claude Code over the last week unknowingly installed credential-stealing malware, including Vidar stealer and GhostSocks, alongside the purported source code. This digital trap turned what seemed like open-source gold into a digital pickpocket, putting sensitive information at risk.

Analyst 207
Storm Infostealer Decrypts Credentials to Evade Detection

Storm Infostealer Decrypts Credentials to Evade Detection

Meet Storm, a sneaky new infostealer that's taking password theft to the next level by remotely decrypting stolen credentials, allowing hackers to slip past security defenses undetected. This game-changing tactic lets stolen passwords be used immediately, bypassing local security controls that would normally sound the alarm.

Analyst 207
GitHub Exploited in Sophisticated Malware Campaign

GitHub Exploited in Sophisticated Malware Campaign

Malicious actors have launched a sophisticated malware campaign that exploits GitHub as a covert command-and-control channel, using trusted platforms to evade detection and wreak havoc on unsuspecting organizations. This multi-stage threat employs LNK files, embedded decoders, and PowerShell to establish persistence and exfiltrate sensitive data.

Analyst 207
Akira Ransomware Executes Attacks in Under 60 Minutes

Akira Ransomware Executes Attacks in Under 60 Minutes

Akira ransomware has become alarmingly efficient, capable of executing a full-scale attack in under 60 minutes - leaving organizations with an incredibly tight window to detect and respond to threats. This lightning-fast strike highlights the urgent need for robust security measures to counter the rapidly evolving ransomware landscape.

Analyst 207
Threat Actors Exploit Vacant Homes to Intercept Mail for Fraud

Threat Actors Exploit Vacant Homes to Intercept Mail for Fraud

Threat actors are exploiting vacant homes as postal drop points to intercept and manipulate mail, converting a traditional weakness into a powerful tool for fraud. This emerging hybrid scam combines physical-world tactics with digital deception, allowing criminals to fabricate identities and wreak havoc on unsuspecting victims.

Analyst 207
Fake ISO Installers Spread RATs, Crypto Miners in Global Campaign

Fake ISO Installers Spread RATs, Crypto Miners in Global Campaign

Beware of fake ISO installers that masquerade as legitimate software, but secretly unleash a malicious payload of RATs, crypto miners, and CPA fraud on unsuspecting victims. For over two years, a financially motivated operation, codenamed REF1695, has been quietly spreading malware through these Trojan horses.

Analyst 207
Google Exposes Sophisticated iPhone Hacking Tool Likely Tied to US Government

Google Exposes Sophisticated iPhone Hacking Tool Likely Tied to US Government

Imagine a single website visit being all it takes to secretly install malware on your iPhone, bypassing every defense along the way - that's the alarming reality uncovered by Google's security researchers. They've discovered a sophisticated hacking tool, dubbed Coruna, that exploits 23 iOS vulnerabilities to silently compromise devices.

Analyst 207
WhatsApp Exposes Italian Users to Spyware via Fake iOS App

WhatsApp Exposes Italian Users to Spyware via Fake iOS App

WhatsApp has alerted around 200 users, mostly in Italy, about a sneaky spyware attack that hit them after they downloaded a fake version of the app for iOS. This alarming incident raises a crucial question: how can you trust that the app on your phone is genuine?

Analyst 207
F5 BIG-IP Instances Vulnerable to Ongoing RCE Attacks

F5 BIG-IP Instances Vulnerable to Ongoing RCE Attacks

With over 14,000 F5 BIG-IP Access Policy Manager instances exposed online, a critical vulnerability is putting countless systems at risk of remote code execution attacks. Attackers are actively exploiting this flaw, making it crucial for organizations to take immediate action to protect themselves.

Analyst 207
CrystalRAT Malware Emerges with Advanced RAT and Data Theft Capabilities

CrystalRAT Malware Emerges with Advanced RAT and Data Theft Capabilities

Meet CrystalRAT, a powerful malware-as-a-service that's being sold on Telegram, capable of giving outsiders remote control of your computer, stealing sensitive files, recording every keystroke, and even hijacking your clipboard. This malicious tool is a nightmare come true, and its emergence poses a serious threat to online security.

Analyst 207
CERT-UA Warns of AGEWHEEZE Malware Spread via Impersonation Campaign

CERT-UA Warns of AGEWHEEZE Malware Spread via Impersonation Campaign

Beware of scammers impersonating Ukraine's cyber emergency team, CERT-UA, in a massive phishing campaign that sent nearly one million emails with a malicious payload. The attackers used a clever tactic, disguising their malware, known as AGEWHEEZE, as a legitimate warning from a trusted source.

Analyst 207
Smartphone with cracked screen surrounded by eerie circuit boards and wires, with a looming hacker figure in the background.

Google Play Infected by NoVoice Android Malware

Millions of Android users may have unknowingly downloaded malware from Google Play, with over 50 apps infected by the NoVoice Android malware family, which has already racked up at least 2.3 million installs. This shocking discovery highlights the vulnerability of mobile ecosystems to malicious code that can slip past store vetting.

Analyst 207
Venom Stealer Platform Automates Data Theft with ClickFix Tactics

Venom Stealer Platform Automates Data Theft with ClickFix Tactics

Imagine a silent thief lurking in the shadows of your digital life, quietly siphoning off sensitive info - and now, cybercriminals can easily access this capability with Venom Stealer, a new malware-as-a-service tool that automates data theft with alarming ease. This menacing platform is poised to revolutionize cybercrime, making it simpler than ever for attackers to steal credentials, cookies, and cryptocurrency assets.

Analyst 207
Smartphone lies on shattered Windows desktop screen amidst binary code fragments, surrounded by a vulnerable cityscape at…

Microsoft Flags WhatsApp-Delivered VBS Malware Bypassing Windows UAC

Beware of WhatsApp attachments from familiar numbers - they might be malicious VBS files designed to quietly hijack your Windows system. A sneaky new campaign uses decades-old scripting language to bypass Windows UAC and give attackers remote access.

Analyst 207
Horabot Malware Targets Latin America, Europe in Sophisticated Phishing Drive

Horabot Malware Targets Latin America, Europe in Sophisticated Phishing Drive

Beware of the sneaky Horabot malware that's targeting businesses and users in Latin America and Europe with cleverly disguised PDF attachments that deliver a devastating banking trojan. This sophisticated phishing campaign, linked to a notorious Brazilian cybercrime group, could be the ultimate cyber threat to your financial security.

Analyst 207
Phantom Stealer Emerges as Sophisticated Stealer-as-a-Service Tool

Phantom Stealer Emerges as Sophisticated Stealer-as-a-Service Tool

Imagine your entire online life being stolen and sold for just a few hundred dollars - that's the harsh reality with Phantom Stealer, a powerful and stealthy tool that's making it easy for cybercriminals to get their hands on your sensitive information. This sophisticated .NET-based stealer can harvest everything from login credentials to payment card details, putting your digital identity at risk.

Analyst 207