Skip to main content

Tag: threat actors

261 articles

Dimly lit server room with rows of equipment and a single isolated computer terminal in the foreground.

Attackers Exploit Artifactory Flaw in AI-Driven Campaigns

Cyber attackers are leveraging a newly exploited Artifactory flaw in highly sophisticated, AI-driven campaigns - but are these threats coming from automated bots or human culprits? The line between human and machine is blurring in the world of cybercrime.

Analyst 207
A typical urban office setting with a blank laptop screen in the foreground.

ValleyRAT Exploits Adware to Evade Detection

Meet ValleyRAT, a sneaky backdoor that's been evading detection with the help of adware, infecting over 1500 users in China and India with a staggering 100,000 detections in 2026 alone. Its clever disguise was uncovered when researchers dug deeper into a suspicious installer initially labeled as ordinary adware.

Analyst 207
Office workspace with printer, computer, and paper supplies, under ordinary indoor lighting.

Hackers Actively Exploit PaperCut Flaw in Zero-Day Attacks

Hackers are on the attack, exploiting a vulnerability in PaperCut's print management software, with confirmed incidents reported by the company. PaperCut has sprung into action, releasing emergency patches to protect its customers from these zero-day attacks.

Analyst 207
A cluttered Cambodian office desk with a laptop and smartphone, laptop screen blank.

Spark RAT Campaign Targets Cambodia, Abuses OPSWAT Driver to Disable Security Tools

A new Spark RAT campaign is targeting Cambodia, using clever tactics like phishing emails and signed DLLs to disable security tools and sneak malicious payloads into victims' systems. The attackers are casting a wide net with diverse lure themes, trying to catch as many unsuspecting victims as possible.

Analyst 207
Web developer's laptop open to npm registry page in coffee shop with notes and empty browser windows nearby.

Hackers Exploit npm Mirrors to Host Phishing Pages

Hackers are exploiting npm mirrors to host phishing pages by uploading malicious HTML files to the npm registry, which are then mirrored and can be accessed directly in a browser. This clever tactic turns the trusted registry into a free web host for malware, allowing threat actors to spread phishing pages under the guise of legitimate content.

Analyst 207
Person in modern office looks concerned at blank smartphone screen.

Recruiter Scams Target Corporate Credentials on Mobile Devices

Beware of recruiter scams targeting your corporate credentials on mobile devices! A recent discovery by Zimperium uncovered a sneaky phishing campaign impersonating top employers and recruiters, including Amazon, Apple, and Louis Vuitton, to steal sensitive info.

Analyst 207
Cybersecurity professionals gather around a laptop and whiteboard in a brightly-lit office conference room.

ReliaQuest Exposes ShinyHunters' Social Engineering Tactics

ReliaQuest sets the record straight: claims of a ransomware attack or breach are completely false. The company recently thwarted a social engineering scheme by ShinyHunters, swiftly investigating and publicly rebutting the misinformation.

Analyst 207
Mac laptop on cluttered desk with suspicious Terminal window and Google search results page on screen.

Mac Malware Exploits Fake OpenAI Codex Ads

Beware of fake OpenAI Codex ads: hackers are using Google search results to trick Mac users into downloading malware by pasting a malicious Terminal command. This sneaky tactic unleashes a multi-stage malware infection, putting your device at risk.

Analyst 207
Network operations center with servers and technicians, laptop screen blank in foreground.

UAT-10147 Deploys AI-Powered SPECTRE Backdoor with EDR Bypass

Meet UAT-10147, a Chinese-speaking cybercrime group that's taking AI-powered attacks to the next level with its sophisticated SPECTRE backdoor, capable of bypassing EDR defenses. This group's arsenal includes a range of open-source tools and custom AI solutions that streamline and scale their malicious operations.

Analyst 207
Laptop screen shows a WordPress backend dashboard with a compromised website's source code on a messy desk.

MaaS Operators Combine ErrTraffic, ClickFix to Evade Endpoint Security

Cyber attackers have launched a sneaky campaign that combines ErrTraffic and ClickFix to outsmart endpoint security, starting with compromised WordPress sites that inject obfuscated JavaScript to evade detection. This clever tactic uses the Ethereum blockchain to stay one step ahead of security tools.

Analyst 207
Dimly lit server room with laptop screen showing an email inbox.

Ransom Busters Emerges as New Player in Ransomware Extortion Economy

Meet Ransom Busters, a newcomer to the ransomware extortion economy that's shaking things up with its bold approach: offering to delete stolen data from ransomware groups' servers for a fee of $20,000 to $60,000. This third-party player claims to have been infiltrating ransomware-as-a-service operations for over three years.

Analyst 207
Laptop screen shows coding interface with blurred script, set against office backdrop.

Iranian Hackers Evolve Cavern C2 with Google Apps Script Evasion

Meet the sneaky new tactic Iranian hackers are using to evade detection: blending malicious traffic with everyday services like Google Apps Script. By leveraging DNS A-record responses, they're able to switch between direct HTTPS channels and Google Apps Script relays, making it harder to track their moves.

Analyst 207
Blurred office interior with rows of workstations and a single laptop screen on a desk.

Wesco Probes Data Exfiltration After ExfilSquad Leak Claim

Wesco is investigating a cybersecurity incident involving its cloud CRM environment after a third-party group, ExfilSquad, claimed to have exfiltrated company data. The company says it has contained the issue, found no evidence of sensitive data being compromised, and continues to operate as usual.

Analyst 207
Cluttered desk with laptop, papers, and empty pizza boxes in a dimly lit room.

Google Exposes Redact Extortion Group's Ties to BlackFile Rebrand

Google's Threat Intelligence Group uncovered a clever rebranding scheme by the notorious extortion group formerly known as BlackFile, which has now resurfaced under the name Redact, after allegedly being hijacked by a rogue affiliate. The group had claimed retirement, but clearly wasn't done causing trouble, raking in around $10.69 million in Bitcoin transactions.

Analyst 207
A quiet office setting with a desk, chair, laptop, and papers, and a window showing natural daylight in the background.

Trust Eroded in Quiet Places

Beware of PDFs that seem harmless - they can now silently install malware on your device, thanks to a sneaky new phishing campaign that uses ClickOnce files to deploy Rust-based backdoors. This stealthy tactic requires no user interaction, making it a potent threat.

Analyst 207
Server room interior with rows of equipment and a blurred database server in the foreground.

Hackers Embed khunt Toolkit in Oracle Database via SQL Injection

Security researchers have uncovered a rare and stealthy attack where hackers embedded the Khunt toolkit in an Oracle database using a SQL injection technique, highlighting a seldom-documented threat in the wild. The attack started with a simple vulnerability in an autocomplete search feature that allowed malicious input to slip through.

Analyst 207
Software development workspace with laptop, papers, and notes, overlooking cityscape through large window.

TeamPCP's Origins Exposed in Long-Running Open-Source Attacks

Meet TeamPCP, a threat actor with a stealthy history of open-source attacks that dates back to 2020, and has evolved at an alarming rate to compromise over 1,000 software packages. Their rapid adaptation has experts sounding the alarm, with one researcher calling it the scariest thing about this campaign.

Analyst 207
Laptop on a desk in a brightly-lit office setting with a person's hand nearby.

Kali365 Exploits Microsoft Authentication in US Firms

Meet Kali365, a sneaky device-code phishing kit that's exploiting Microsoft authentication to infiltrate US firms, with over 80 public sessions compromised weekly. By masquerading as trusted services, Kali365 tricks victims into handing over access to their Microsoft 365 email, documents, and cloud resources.

Analyst 207
Brightly-lit server rack with rows of out-of-focus servers and cables against a neutral background.

Cloud Platforms Expose Phishers to Easy MFA Bypass Tactics

Reputable cloud platforms have unwittingly become a phishing haven, with threat actors exploiting their trusted reputations, generous free tiers, and instant onboarding to launch attacks - all thanks to lenient security measures that rarely require verification. This has made it alarmingly easy for phishers to bypass multi-factor authentication and wreak havoc.

Analyst 207
Well-lit security storefront with slightly askew camera panel.

ShinyHunters Breach Famous Physical Security Brand

The notorious hacking group ShinyHunters has breached the most iconic brand in physical security, sending shockwaves through the industry. This high-profile hack has left many wondering about the vulnerability of even the most trusted names in security.

Analyst 207
Modern computer workstation with security software dashboard and office background.

Ransomware Groups Master EDR Kill Techniques

Ransomware groups have mastered the art of disabling endpoint detection and response (EDR) tools, making it standard practice to shut them down before encryption begins. This sinister tactic has significantly shortened defenders' response time, leaving them with limited opportunities to detect and contain attacks.

Analyst 207
Dimly lit movie theater or cluttered home workspace with laptop and movie-watching paraphernalia.

Scammers Exploit 'Odyssey' Release with Rapid-Fire Pirated Movie Scams

Scammers wasted no time in exploiting the release of Christopher Nolan's highly anticipated film, The Odyssey, using rapid-fire pirated movie scams to target unsuspecting users just hours after its debut. These scams cleverily avoided software vulnerabilities, instead relying on fake browser warnings and malicious downloads to compromise victims' devices.

Analyst 207
Damaged server equipment in a data center with concerned technicians in the background.

JADEPUFFER Evolves to Target AI Models with Ransomware

JADEPUFFER's latest move is a game-changer: they're now using ransomware to destroy AI models, leaving encrypted artifacts irretrievable. This devastating attack can cost victims up to $500,000 or more in training and computing losses.

Analyst 207
Laptop screen displays GitHub repository page amidst cluttered home office workspace.

FakeGit Campaign Exploits GitHub Repos to Spread SmartLoader Malware

Malicious actors have unleashed a massive campaign, using 7,600 fake GitHub repositories to spread the notorious SmartLoader malware, tricking victims into downloading malicious files disguised as popular tools like Gmail and Docker. The operation's convincing fake artifacts and manipulated repository metrics made it a highly effective and long-running threat.

Analyst 207