Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

LogoKit update – The phishing kit leveraging Open Redirect Vulnerabilities

August 1, 2022October 13, 2025 Securonix

Threat actors repurpose Open Redirect vulnerabilities to bypass spam filters and deliver the LogoKit phishing content using trusted domains such as Snapchat and Google. LogoKit dynamically generates landing pages, steals credentials, and leverages compromised …

Read More
Threat Research

Cisco Talos shares insights related to recent cyber attack on Cisco

August 1, 2022October 16, 2025 Securonix

Cisco Talos and CSIRT describe a May 2022 compromise in which a Cisco employee’s Google account credentials (synced from a personal browser) enabled initial VPN access after MFA bypass via vishing and MFA fatigue. The investigation links the actors to an initi…

Read More
Threat Research

Novel News on Cuba Ransomware: Greetings From Tropical Scorpius

August 1, 2022October 15, 2025 Securonix

Unit 42 analyzes Tropical Scorpius (UNC2596) activity, detailing Cuba Ransomware’s evolution with new tools like ROMCOM RAT, KerberCache, and a kernel driver to defeat defenses, plus its connection to the Industrial Spy marketplace. The report covers ransomwar…

Read More
Threat Research

Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities

August 1, 2022October 16, 2025 Securonix

SmokeLoader (Dofoil) continues to leverage aging vulnerabilities to deliver its payload via a crafted phishing email chain, decrypt an embedded OLE stream, and drop a final DLL payload that is associated with zgRAT. The campaign demonstrates how attackers rely…

Read More
Threat Research

Andariel deploys DTrack and Maui ransomware

August 1, 2022October 13, 2025 Securonix

Two sentences summarizing: This analysis confirms a Maui ransomware incident in 2022 attributed to Andariel, who deployed a DTrack variant about ten hours earlier on the same target. The operation appears global in scope, with a Japanese victim and overlaps to…

Read More
Threat Research

New HiddenAds malware affects 1M+ users and hides on the Google Play Store | McAfee Blog

July 29, 2022October 15, 2025 McAfee

Authored by Dexter Shin McAfee’s Mobile Research Team has identified new malware on the Google Play Store. Most of them…
The post New HiddenAds malware affects 1M+ users and hides on the Google Play Store appeared first on McAfee Blog….

Read More
Threat Research

Pivoting on a SharpExt to profile Kimsuky panels for great good

July 29, 2022October 16, 2025 Securonix

SharpExt is a browser-extension malware used by Kimsuky to steal emails and attachments, as detailed by Volexity and related researchers. The campaign maps to older activity, leverages a large network of domains for delivery and C2, and targets US, Europe, and…

Read More
Threat Research

A new botnet Orchard Generates DGA Domains with Bitcoin Transaction Information

July 29, 2022October 15, 2025 Securonix

Orchard is a botnet family that uses DGA technology to generate C2 domains, incorporating Bitcoin wallet transaction data as inputs to the DGA to increase unpredictability. It has evolved across three versions since 2021, combining hardcoded DuckDNS domains wi…

Read More
Threat Research

BumbleBee Roasts Its Way to Domain Admin

July 29, 2022October 16, 2025 Securonix

An April 2022 intrusion saw BumbleBee act as the initial access loader, enabling multi-stage payloads and outbound C2 communication within a Windows environment. The operation featured credential dumping, Kerberoasting, privilege escalation tooling, and Cobalt…

Read More
Threat Research

Adversary Quest 2022: 4 CATAPULT SPIDER eCrime Challenges | CrowdStrike

July 28, 2022October 16, 2025 Securonix

Researchers analyze CrowdStrike’s Adversary Quest 2022 CATAPULT SPIDER track, which centers on a Dogecoin-driven ransomware campaign leveraging CHM phishing, encoded PowerShell, and a Dogecoin-based C2. The storyline uncovers multi-stage payloads, a vulnerable…

Read More
Threat Research

Flying in the clouds: APT31 renews its attacks on Russian companies through cloud storage

July 28, 2022October 16, 2025 Securonix

APT31 renewed its attacks on Russian media and energy companies by leveraging a malicious document that loads a VMProtect-packed payload, linking the activity to the APT31 toolkit. The campaign uses cloud storage services (notably Yandex.Disk) as C2 to blend i…

Read More
Threat Research

GwisinLocker ransomware targets South Korean industrial and pharma firms

July 28, 2022October 16, 2025 Securonix

GwisinLocker.Linux is a Linux-based ransomware variant linked to the Gwisin threat actor, targeting South Korean industrial and pharmaceutical firms. It encrypts files using per-file AES keys (with RSA-wrapped keys), stores keys in .mcrgnx0 files, appends .mcr…

Read More
Threat Research

Word File Provided as External Link When Replying to Attacker’s Email (Kimsuky) – ASEC BLOG

July 27, 2022October 14, 2025 Securonix

ASEC has observed ongoing distribution of North Korea–related Word files used in Kimsuky campaigns, including variants that rely on mshta. Attackers impersonate Korean organizations to trigger a follow-up email with a link to download a malicious Word document…

Read More
Threat Research

Attackers leveraging Dark Utilities “C2aaS” platform in malware campaigns

July 27, 2022October 15, 2025 Securonix

Dark Utilities is a C2-as-a-Service platform released in early 2022 that provides remote access, DDoS, and cryptocurrency mining capabilities, with payloads for Windows, Linux, and Python hosted on IPFS to resist takedowns. Since launch, malware samples have r…

Read More
Threat Research

ROADSWEEP Ransomware – Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations

July 27, 2022October 15, 2025 Securonix

ROADSWEEP encrypts files across discovered drives using RC4 and marks them with a .lck extension, then performs a wipe with a self-delete to cover its tracks. The activity is part of a broader campaign involving ZEROCLEAR and CHIMNEYSWEEP, tied to a politicall…

Read More

Posts pagination

Previous 1 … 509 510 511 … 535 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.