Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Categorie: malware

New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack

post, juni 6, 2025

A critical infrastructure entity within Ukraine was targeted by a previously unseen data wiper malware named PathWiper, according to new findings from Cisco Talos. “The attack was instrumented via a legitimate endpoint administration framework, indicating that the attackers likely had access to the administrative console, that was then used to…

Continue Reading

Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets

post, mei 27, 2025mei 28, 2025

Cybersecurity researchers have disclosed a new malicious campaign that uses a fake website advertising antivirus software from Bitdefender to dupe victims into downloading a remote access trojan called Venom RAT. The campaign indicates a “clear intent to target individuals for financial gain by compromising their credentials, crypto wallets, and potentially…

Continue Reading

Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations

post, mei 21, 2025mei 22, 2025

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to disseminate known tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with threat actors deploying the LummaC2 information stealer (infostealer) malware. LummaC2 malware is able to infiltrate victim…

Continue Reading

Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices

post, april 23, 2025april 24, 2025

Cybersecurity researchers have revealed that Russian military personnel are the target of a new malicious campaign that distributes Android spyware under the guise of the Alpine Quest mapping software. “The attackers hide this trojan inside modified Alpine Quest mapping software and distribute it in various ways, including through one of…

Continue Reading

Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States

post, december 12, 2024december 13, 2024

The Russia-linked state-sponsored threat actor tracked as Gamaredon has been attributed to two new Android spyware tools called BoneSpy and PlainGnome, marking the first time the adversary has been discovered using mobile-only malware families in its attack campaigns. “BoneSpy and PlainGnome target former Soviet states and focus on Russian-speaking victims,” Lookout said in an analysis….

Continue Reading

ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms

post, december 11, 2024februari 24, 2025

Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after resurfacing a year ago. “Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and…

Continue Reading

US arrests Scattered Spider suspect linked to telecom hacks

post, december 5, 2024februari 24, 2025

U.S. authorities have arrested a 19-year-old teenager linked to the notorious Scattered Spider cybercrime gang who is now charged with breaching a U.S. financial institution and two unnamed telecommunications firms. Remington Goy Ogletree (also known online as “remi”) breached the three companies’ networks using credentials stolen in text and voice…

Continue Reading

Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations

post, november 15, 2024februari 24, 2025

Cybersecurity researchers have shed light on a new remote access trojan and information stealer used by Iranian state-sponsored actors to conduct reconnaissance of compromised endpoints and execute malicious commands. Cybersecurity company Check Point has codenamed the malware WezRat, stating it has been detected in the wild since at least September 1,…

Continue Reading

Iran’s APT34 Abuses MS Exchange to Spy on Gulf Gov’ts

post, oktober 17, 2024juli 3, 2025

A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE). APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm)…

Continue Reading

North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks

post, oktober 3, 2024juli 3, 2025

Threat actors with ties to North Korea have been observed delivering a previously undocumented backdoor and remote access trojan (RAT) called VeilShell as part of a campaign targeting Cambodia and likely other Southeast Asian countries. The activity, dubbed SHROUDED#SLEEP by Securonix, is believed to be the handiwork of APT37, which is also known…

Continue Reading
  • Previous
  • 1
  • …
  • 3
  • 4
  • 5
  • 6
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes