Cyberactoren uit Iran zetten malware in tegen dissidenten, activisten en journalisten post, september 15, 2026september 16, 2026 Uit recent onderzoek van de Britse inlichtingen- en veiligheidsdiensten en de AIVD blijkt dat Iraanse cyberactoren specifieke malware inzetten. Het doel hiervan is om gevoelige informatie te verzamelen over critici van het Iraanse regime die in het Westen verblijven, waaronder dissidenten, activisten en journalisten. Daarom waarschuwt de AIVD opnieuw voor… Continue Reading
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection post, september 11, 2026september 15, 2026 Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group),… Continue Reading
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis post, september 1, 2026september 4, 2026 Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that’s been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model’s… Continue Reading
Sandworm hackers target IT pros with trojanized WireGuard VPN client post, augustus 11, 2026augustus 17, 2026 Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of… Continue Reading
Russia State-Sponsored Hackers Turn Hotel and Conference Wi-Fi Networks Into Malware Delivery Systems post, augustus 4, 2026augustus 17, 2026 Russian state backed hackers are compromising public Wi-Fi infrastructure at hotels, conference centres and other shared venues to intercept travellers’ internet traffic, distribute remote-access malware and steal access to corporate cloud accounts, according to new research from Microsoft. The campaign, which Microsoft calls CaptiveCrunch, has been attributed to Storm-2945, an… Continue Reading
New DOUBLECUP ClickFix service hides malware in browser cache images post, augustus 3, 2026augustus 17, 2026 A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June… Continue Reading
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware post, juli 31, 2026augustus 17, 2026 Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is… Continue Reading
Russian State-Backed Threat Actor Exploits Zimbra Zero-Day To Steal Emails & Authentication Data post, juli 24, 2026juli 27, 2026 A Russian state-supported hacking group has been exploiting a previously unknown vulnerability in Zimbra Collaboration Suite to silently steal emails, passwords, two-factor authentication codes and corporate address books from government and commercial organizations across Western countries. The campaign, attributed to a threat group primarily known as Laundry Bear, has been… Continue Reading
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses post, april 30, 2026mei 1, 2026 The recent wave of ClickFix attacks has introduced several new ways to compromise users, establishing itself as a technique that is likely here to stay. We have observed Lazarus Group using this method to distribute a range of malware, from well-known families to more unusual variants such as PyLangGhostRAT, a… Continue Reading
Mystery Around Venezuelan Cyberattack Deepens, with New Discovery of “Highly Destructive” Wiper post, april 24, 2026april 29, 2026 The mystery around a cyberattack that struck Venezuela’s state-owned oil company in December is growing, following an announcement by researchers this week that they had discovered a “highly destructive” wiper program that appears to have been designed to target the oil company and may have been used in the December… Continue Reading