New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack post, juni 6, 2025 A critical infrastructure entity within Ukraine was targeted by a previously unseen data wiper malware named PathWiper, according to new findings from Cisco Talos. “The attack was instrumented via a legitimate endpoint administration framework, indicating that the attackers likely had access to the administrative console, that was then used to… Continue Reading
Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets post, mei 27, 2025mei 28, 2025 Cybersecurity researchers have disclosed a new malicious campaign that uses a fake website advertising antivirus software from Bitdefender to dupe victims into downloading a remote access trojan called Venom RAT. The campaign indicates a “clear intent to target individuals for financial gain by compromising their credentials, crypto wallets, and potentially… Continue Reading
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations post, mei 21, 2025mei 22, 2025 The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to disseminate known tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with threat actors deploying the LummaC2 information stealer (infostealer) malware. LummaC2 malware is able to infiltrate victim… Continue Reading
Android Spyware Disguised as Alpine Quest App Targets Russian Military Devices post, april 23, 2025april 24, 2025 Cybersecurity researchers have revealed that Russian military personnel are the target of a new malicious campaign that distributes Android spyware under the guise of the Alpine Quest mapping software. “The attackers hide this trojan inside modified Alpine Quest mapping software and distribute it in various ways, including through one of… Continue Reading
Gamaredon Deploys Android Spyware “BoneSpy” and “PlainGnome” in Former Soviet States post, december 12, 2024december 13, 2024 The Russia-linked state-sponsored threat actor tracked as Gamaredon has been attributed to two new Android spyware tools called BoneSpy and PlainGnome, marking the first time the adversary has been discovered using mobile-only malware families in its attack campaigns. “BoneSpy and PlainGnome target former Soviet states and focus on Russian-speaking victims,” Lookout said in an analysis…. Continue Reading
ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms post, december 11, 2024februari 24, 2025 Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the threat actors are continuing to refine the tool after resurfacing a year ago. “Zloader 2.9.4.0 adds notable improvements including a custom DNS tunnel protocol for C2 communications and… Continue Reading
US arrests Scattered Spider suspect linked to telecom hacks post, december 5, 2024februari 24, 2025 U.S. authorities have arrested a 19-year-old teenager linked to the notorious Scattered Spider cybercrime gang who is now charged with breaching a U.S. financial institution and two unnamed telecommunications firms. Remington Goy Ogletree (also known online as “remi”) breached the three companies’ networks using credentials stolen in text and voice… Continue Reading
Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations post, november 15, 2024februari 24, 2025 Cybersecurity researchers have shed light on a new remote access trojan and information stealer used by Iranian state-sponsored actors to conduct reconnaissance of compromised endpoints and execute malicious commands. Cybersecurity company Check Point has codenamed the malware WezRat, stating it has been detected in the wild since at least September 1,… Continue Reading
Iran’s APT34 Abuses MS Exchange to Spy on Gulf Gov’ts post, oktober 17, 2024juli 3, 2025 A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies. An Iranian threat actor has been ramping up its espionage against Gulf-state government entities, particularly those within the United Arab Emirates (UAE). APT34 (aka Earth Simnavaz, OilRig, MuddyWater, Crambus, Europium, Hazel Sandstorm)… Continue Reading
North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks post, oktober 3, 2024juli 3, 2025 Threat actors with ties to North Korea have been observed delivering a previously undocumented backdoor and remote access trojan (RAT) called VeilShell as part of a campaign targeting Cambodia and likely other Southeast Asian countries. The activity, dubbed SHROUDED#SLEEP by Securonix, is believed to be the handiwork of APT37, which is also known… Continue Reading