Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Categorie: malware

Frankrijk onderzoekt vermoedelijke poging tot ‘cyberkaping’ veerboot

post, december 17, 2025december 18, 2025

De Franse autoriteiten onderzoeken een vermoedelijke poging om op afstand de besturing van een veerboot over te nemen. Op een passagiersschip van de Italiaanse rederij GNV is malware, ongewenste software, aangetroffen. Het schip lag op dat moment afgemeerd in Sète, een havenstad in het zuiden van Frankrijk. De rederij zegt…

Continue Reading

Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks

post, november 18, 2025november 28, 2025

Suspected espionage-driven threat actors from Iran have been observed deploying backdoors like TWOSTROKE and DEEPROOT as part of continued attacks aimed at aerospace, aviation, and defense industries in the Middle East. The activity has been attributed by Google-owned Mandiant to a threat cluster tracked as UNC1549 (aka GalaxyGato, Nimbus Manticore, or Subtle…

Continue Reading

Chinese State-Sponsored Threat Actors Used Anthropic’s Claude To Automate Global Cyberattacks

post, november 14, 2025november 17, 2025

Anthropic has disclosed a large-scale cyber operation in which a China-aligned threat actor leveraged the Claude Code model to automate exploitation, credential harvesting, and data exfiltration across approximately 30 global targets. The incident represents one of the first documented cases in which an LLM with agentic capabilities was weaponized to…

Continue Reading

Hackers Breach Samsung Galaxy Phones Using A Single WhatsApp Image In Sophisticated Spyware Operation

post, november 8, 2025november 10, 2025

Security researchers at Palo Alto Networks Unit 42 have uncovered a sophisticated espionage campaign leveraging a zero-day vulnerability in select Samsung Galaxy Android devices. The flaw, tracked as CVE‑2025‑21042 (CVSS 8.8), is an out-of-bounds write defect in the libimagecodec.quram.so image-processing library, which could allow remote code execution. According to Unit…

Continue Reading

Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign

post, oktober 22, 2025oktober 23, 2025

The Iranian nation-state group known as MuddyWater has been attributed to a new campaign that has leveraged a compromised email account to distribute a backdoor called Phoenix to various organizations across the Middle East and North Africa (MENA) region, including over 100 government entities. The end goal of the campaign is to…

Continue Reading

Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth Malware

post, september 30, 2025oktober 3, 2025

Government and telecommunications organizations across Africa, the Middle East, and Asia have emerged as the target of a previously undocumented China-aligned nation-state actor dubbed Phantom Taurus over the past two-and-a-half years. “Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events, and military operations,” Palo Alto Networks Unit 42…

Continue Reading

Sophisticated Campaign Targets Microsoft Teams Users With Oyster Malware

post, september 28, 2025oktober 3, 2025

Cybersecurity researchers have uncovered a cyberattack method that illustrates the growing sophistication of modern malvertising campaigns. This new wave of attacks sees threat actors leverage SEO poisoning techniques and search engine advertisements to lure unsuspecting users into downloading fake Microsoft Teams installers. These deceptive downloads ultimately infect Windows systems with…

Continue Reading

Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs

post, september 15, 2025september 18, 2025

The China-aligned threat actor known as Mustang Panda has been observed using an updated version of a backdoor called TONESHELL and a previously undocumented USB worm called SnakeDisk. “The worm only executes on devices with Thailand-based IP addresses and drops the Yokai backdoor,” IBM X-Force researchers Golo Mühr and Joshua Chung said in an analysis published…

Continue Reading

The Kremlin’s Most Devious Hacking Group Is Using Russian ISPs to Plant Spyware

post, juli 31, 2025augustus 18, 2025

The Russian state hacker group known as Turla has carried out some of the most innovative hacking feats in the history of cyberespionage, hiding their malware’s communications in satellite connections or hijacking other hackers’ operations to cloak their own data extraction. When they’re operating on their home turf, however, it turns out they’ve tried…

Continue Reading

Over 70 Organizations Across Multiple Sectors Targeted by China-Linked Cyber Espionage Group

post, juni 9, 2025juni 10, 2025

The reconnaissance activity targeting American cybersecurity company SentinelOne was part of a broader set of partially-related intrusions into several targets between July 2024 and March 2025. “The victimology includes a South Asian government entity, a European media organization, and more than 70 organizations across a wide range of sectors,” SentinelOne…

Continue Reading
  • Previous
  • 1
  • 2
  • 3
  • 4
  • …
  • 6
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes