Skip to main content

Malware & Ransomware

Government office in Central Asia with a laptop and papers on a desk, hinting at technology integration.

China-linked SilkParasite campaign targets Central Asia with custom RATs

Meet SilkParasite, a sneaky espionage operation linked to China that's been targeting government bodies in Central Asia with a custom arsenal of Remote Access Tools. This sophisticated campaign boasts seven unique RAT families, five of which have never been seen before, and hints at AI-assisted development.

Analyst 207
Compromised server room with interconnected devices and scattered cables.

Hackers Exploit 2,000 WordPress Sites in StopAndProtect Malware Campaign

This sneaky malware campaign, known as StopAndProtect, has already hacked nearly 2,000 WordPress sites, using a powerful toolkit that encrypts files, steals sensitive documents, and even lets attackers chat with their victims in real-time. The damage is widespread, with over 6,000 unique IP addresses affected worldwide.

Analyst 207
Hospital corridor with staff, medical device, and laptop, well-lit with daylight.

Medusa Ransomware Targets Over 500 Infrastructure Orgs, Expands Tactics

Medusa ransomware has hit a staggering 500+ critical infrastructure organizations, with healthcare being a prime target, as reported in a recent FBI advisory. The attacks are happening at an alarming rate, with exploitation windows as short as 24 hours or even less.

Analyst 207
Interior of network operations center with rows of computer workstations and networking equipment.

Hackers Actively Exploit Windows IKE Flaw

Hackers are actively exploiting a critical Windows flaw, known as CVE-2026-33824, that lets them execute code over a network, putting your system at risk. This vulnerability, found in the Windows Internet Key Exchange (IKE) Service Extensions, affects all supported Windows 10 and other Windows systems.

Analyst 207
Brightly-lit industrial control system terminal on a rack in a factory setting.

Clop Ransomware Operation Exploits Windchill Flaw with Custom Web Shell

The Clop ransomware operation has exploited a critical flaw in PTC Windchill and FlexPLM servers, deploying a custom web shell that allows for easy credential theft and massive data exfiltration. This sneaky move gives attackers a direct path to sensitive data, with no extra tools needed.

Analyst 207
Dimly lit server room with multiple computer servers, network equipment, and monitors.

Microsoft Uncovers 30+ Domains Linked to MacSync Stealer Infrastructure

Microsoft's investigation has uncovered a sneaky operation: over 30 domains are secretly linked to MacSync Stealer, a notorious macOS information stealer, and are actively siphoning off sensitive data. The company confirmed that data exfiltration is happening in real-time, not just sending out distress signals.

Analyst 207
Hospital corridor with staff, equipment, and furniture, conveying disruption and concern.

Medusa Ransomware Targets Over 500 US Critical Infrastructure Orgs

The Medusa ransomware gang has struck a staggering 500+ US critical infrastructure organizations across multiple sectors, including healthcare, defense, and finance, since June 2021. This alarming surge in attacks has prompted a joint warning from top US agencies, highlighting the urgent need for heightened cybersecurity measures.

Analyst 207
Dimly lit server room with laptop screen showing an email inbox.

Ransom Busters Emerges as New Player in Ransomware Extortion Economy

Meet Ransom Busters, a newcomer to the ransomware extortion economy that's shaking things up with its bold approach: offering to delete stolen data from ransomware groups' servers for a fee of $20,000 to $60,000. This third-party player claims to have been infiltrating ransomware-as-a-service operations for over three years.

Analyst 207
Brightly-lit cloud computing data center with rows of servers and technicians in the background, and a laptop screen on a…

Attackers Exploit MLflow Flaw to Steal Cloud Credentials

A newly discovered vulnerability in MLflow, CVE-2026-64849, with a near-perfect CVSS score of 9.3 is being exploited by attackers to infiltrate cloud metadata services and steal sensitive credentials. This critical flaw allows hackers to issue unauthorized requests and extract confidential data, putting your cloud security at risk.

Analyst 207
Hospital corridor with people walking, computer workstation, and door in background.

Medusa Ransomware Expands Reach with New Tactics, Hundreds More Victims

The Medusa ransomware gang is on the loose, exploiting unpatched software to target hundreds of victims across various sectors, with the Healthcare and Public Health industry being a frequent hit. Now, US agencies have issued an updated warning, detailing the group's latest tactics and partnerships.

Analyst 207
Server room with computer equipment and a monitor displaying lines of code in the foreground.

Clop Ransomware Gang Crafts Custom Web Shell for Windchill Attacks

The Clop ransomware gang has taken its attacks to the next level by crafting a custom Java web shell that specifically targets PTC Windchill and FlexPLM servers, allowing them to harvest sensitive data with ease. This tailored tool is a significant evolution of their mass-exploitation tactics, making it a major concern for businesses using these applications.

Analyst 207
Blurred laptop screen in a generic corporate workspace with subtle tech infrastructure.

TWINLOOT Exploits Microsoft Services to Steal Credentials

Meet TWINLOOT, a sneaky Python implant that hides its command-and-control infrastructure inside trusted Microsoft services, making it super hard to detect. It uses SharePoint Online and Microsoft Teams to operate undetected, even leveraging a victim's own Edge browser to blend in.

Analyst 207
Cluttered software development workspace with laptop, coding materials, and RubyGems packages in a bright, neutral-colored…

Typosquatting Campaign Targets RubyGems Users with Windows Stealer

Beware of a sneaky typosquatting campaign targeting RubyGems users: 16 malicious packages were used to spread a Windows stealer that harvests sensitive data, including browser credentials, cryptocurrency wallets, and Telegram info. This malware can strike when you least expect it, putting your online security at risk.

Analyst 207
Empty office interior with cubicles, private offices, and scattered papers, lit by soft daylight through windows.

Ransomware Attacks Singly Target Mid-Market Firms

Ransomware attacks are hitting mid-market firms with alarming frequency, and the threat is only escalating as AI-powered tools rapidly uncover new vulnerabilities at an overwhelming pace. Mid-market companies, with revenues between $10m and $1bn, now account for nearly three-quarters of ransomware attack victims.

Analyst 207
Cluttered office workstation with laptop and monitor on desk.

Ransomware gangs exploit Windows Task Host flaw

Ransomware gangs are exploiting a high-severity flaw in Windows Task Host, a core component that could allow them to escalate privileges and wreak havoc on your system. This vulnerability, already patched by Microsoft, poses significant risks to users, especially those with basic user permissions.

Analyst 207
Public Wi-Fi access point in a hotel lobby with a blurred laptop screen nearby.

Hackers Exploit Public Wi-Fi DNS to Harvest Credentials

Beware of hackers lurking on public Wi-Fi networks at hotels, conference centers, and other hotspots, who are using a sneaky trick to steal your login credentials by hijacking the network's DNS settings. By changing just one setting, they can redirect you to fake login pages that look legit - and that's all they need to get their hands on your sensitive info.

Analyst 207
A brightly-lit financial sector setting with a sense of unease, featuring a blurred laptop screen and empty whiteboard in…

BlackFile Targets Financial Firms in Ongoing Extortion Campaign

Financial firms are under attack by a relentless extortion group called BlackFile, which has been targeting the sector with alarming persistence since the start of the year. This threat actor has also set its sights on other industries, including med tech, with no signs of slowing down.

Analyst 207
Laptop screen shows coding interface with blurred script, set against office backdrop.

Iranian Hackers Evolve Cavern C2 with Google Apps Script Evasion

Meet the sneaky new tactic Iranian hackers are using to evade detection: blending malicious traffic with everyday services like Google Apps Script. By leveraging DNS A-record responses, they're able to switch between direct HTTPS channels and Google Apps Script relays, making it harder to track their moves.

Analyst 207
Smartphone on a plain surface with blurred cityscape in background.

UNISOC Modem Flaw Enables Remote Code Execution

A newly discovered flaw in UNISOC modem firmware can be exploited to execute arbitrary code with kernel privileges, allowing hackers to gain deep access to Android devices. Simply making a video call to a vulnerable phone can trigger the attack.

Analyst 207
Server room interior with technicians in background and highlighted server components.

China APT Exploits VMware Flaw in Targeted Attacks

A recent investigation revealed that a suspected China-nexus APT group is actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310, to execute arbitrary code and deploy a backdoor, with ransomware seemingly used as a smokescreen to distract from the underlying intrusion. The attackers' true intentions appear to go beyond mere ransomware deployment.

Analyst 207
Smartphone on cluttered office desk with cityscape background through window.

Unisoc Exploit Chain Grants Attackers Full Android Kernel Access

Security researchers have uncovered a two-stage exploit chain that can give attackers full access to the Android kernel on devices using Unisoc modem firmware, and alarmingly, the vendor has remained unresponsive to disclosure efforts. This chain can be triggered by a simple malformed video call, putting countless devices at risk.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with concerned businesspeople in the background.

Clop Ransomware Targets GE, Philips in Data Theft Attacks

Major companies like Philips, General Electric, and Shell are investigating claims by the Clop ransomware gang that their systems were breached, with Philips confirming a contained breach of an internal server that didn't affect customers. The incidents are a stark reminder of the growing threat of ransomware attacks on businesses.

Analyst 207
Person sits at desk with laptop and papers in a neutral setting.

Apple Alerts 110 Countries to Mercenary Spyware Threats

Apple just sounded the alarm for users in 110 countries, warning them they've been targeted by highly sophisticated mercenary spyware attacks that are among the most advanced digital threats out there. This latest alert is part of a multi-year effort to protect users, with notifications now sent to customers in over 150 countries.

Analyst 207
Modern computer workstation with laptop and peripherals near a window.

Mustang Panda Upgrades CoolClient Backdoor with Signed Windows Rootkit

Meet the upgraded CoolClient backdoor, now armed with a signed Windows rootkit that lets it hide in plain sight, and a closer look reveals it's linked to the notorious HoneyMyte threat group, aka Mustang Panda. This sneaky malware has been targeting victims in Myanmar, Mongolia, Pakistan, and more.

Analyst 207