Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

Unit 42 uncovered CL-CRI-1171, a long-running pay-per-install campaign that used OfferLoader to distribute multiple payloads through YouTube gaming videos and SEO-poisoned download pages. The operation delivered Insomnia RAT, ARKTunnel, and Docro Hijacker while hiding behind rotational domains, trojanized installers, and gating checks that filtered out scanners and analysts. #OfferLoader #CL-CRI-1171 #InsomniaRAT…

Read More
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days

Proofpoint reported that multiple espionage-oriented threat actors rapidly adopted the BlueMoon exploit kit, which chains Chrome V8 and Windows vulnerabilities to deliver different payloads and backdoors. The activity affected US NGOs, US aerospace and defense-related organizations, Vietnamese manufacturing, and targets in Singapore and Indonesia, with notable payloads including GemStone and ShadowPad….

Read More

Zimperium’s zLabs uncovered Mantax Otax v2, a highly aggressive Android threat linked to Indonesian actors that combines spyware, data theft, remote surveillance, and ransomware in one campaign. It uses phishing and sideloaded APKs, then steals credentials and personal data, records screens and photos, and encrypts files on older Android devices while coordinating extortion through Firebase and a dynamic C2 infrastructure. #MantaxOtax #Firebase #Android

Read More
China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

NSA, CISA, and the FBI warn that China-based AI companies are running industrial-scale knowledge distillation campaigns to extract proprietary capabilities from U.S. frontier AI models, including Claude, GPT, Gemini, and Grok. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as major actors and describes evasive access methods such…

Read More
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures

MacSync Stealer is a macOS information-stealing MaaS operation that uses ClickFix lures, malvertising, and multi-stage native Mach-O loaders to evade Apple defenses. It exfiltrates credentials, Keychain data, cookies, SSH keys, and crypto wallets through HTTPS C2 infrastructure and cleans up traces with self-deleting temporary files. #MacSync #ClickFix #drivinguber.com #newsinweb.com #com.utils.Launcher

Read More
DNS Spotlight: 2026’s 5 Most Notorious Ransomware

The article analyzes network IoCs linked to five notorious ransomware families—LockBit, Cl0p, Akira, Medusa, and Qilin—using WHOIS, DNS, and traffic data to uncover additional infrastructure and related artifacts. It highlights 84 network IoCs, thousands of connected domains and IPs, and several potentially compromised or malicious assets, including answersite[.]com and Medusa-related subdomains. #LockBit #Cl0p #Akira #Medusa #Qilin #answersitecom

Read More
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Google Threat Intelligence Group reports that adversaries in Q2 2026 rapidly advanced from basic AI prompting to agentic workflows, using AI for mass credential harvesting, supply chain compromise, and attacks on proprietary AI assets. The report also details UNC6780’s open source supply chain operations, multiple nation-state and cybercrime groups abusing Gemini across the attack lifecycle, and Google’s mitigations against misuse. #UNC6780 #DUSTMAKER #Gemini #UNC6508 #UNC5792 #SANDWORMRELIC #BASINCASTLE #CALANQUEION #RAVINECASTLE #MIDNIGHTNEPTUNE #UNC6240 #OutsiderEnterprise

Read More
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Check Point Research found a covert cross-account command channel in ChatGPT that let an attacker run hidden tasks inside a victim’s session and receive the results across accounts. In a proof of concept, the technique was used to access data from a connected Gmail account and exfiltrate conversation content through shared internal Artifactory metadata. #ChatGPT #Gmail #JFrogArtifactory

Read More
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos linked two WebDAV-based infection chains to the Amatera stealer, including a “verification.google” DLL execution seen at a Ukrainian government organization and a parallel “pf.ch” chain delivered through ClearFake, Cloudflare Workers, and EtherHiding. The campaign used Amatera to steal credentials and cryptocurrency data while delivering secondary payloads such as ZigCryptoStealer,…

Read More
HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures

Fake tax-document and DocuSign lures are being used to deliver a custom HVNC backdoor to banking and financial organizations across Latin America. The malware provides hidden remote access, keystroke and browser-data theft, and Startup-folder persistence while disguising itself as Windows Update Assistant and using infrastructure tied to GHOSTnet GmbH and Azure…

Read More
Tracking BigBear 2.0 Evilginx2 Phishing Campaign | CloudSEK

CloudSEK’s TRIAD uncovered BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service platform that targeted Microsoft 365 and enabled MFA bypass through AiTM session theft. The operation exfiltrated 5,137 credential records across 3,331 victim IPs in 40+ countries, used Telegram-driven credential delivery and geo-matched residential proxies, and remained active while evidence of counter-forensic cleanup was observed. #BigBear20 #Evilginx2 #GeneralBoss #Microsoft365 #Telegram

Read More
Beyond Lazarus: Organization of DPRK cyber capabilities

The article explains how the DPRK has built cyber operations into a core state instrument for espionage, sanctions evasion, and revenue generation, backed by institutions such as the GRIB, NIA, and KWP. It also details the role of DPRK threat clusters and fake IT workers in funding weapons programs, with activity spanning cryptocurrency theft, laundering networks, and overseas relay infrastructure. #DPRK #GRIB #NIA #KWP #Lazarus #Kimsuky #Andariel #Reaper #Bybit #HuioneGroup

Read More
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 Labs uncovered a previously undocumented Linux toolkit using a trojanized HAProxy build and modified system daemons to target South Korean automotive and media organizations for long-term espionage. The campaign used the ted backdoor, CurlRAT, and an SSH keylogger to steal credentials, inject malicious web content, and maintain stealthy control, with infrastructure and tactics suggesting possible DPRK-linked actors such as APT37 and Kimsuky. #HAProxy #ted #CurlRAT #APT37 #Kimsuky #Rapid7 #SouthKorea

Read More