Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Cyble – Redeemer Ransomware Back Action

July 1, 2022October 16, 2025 Securonix

Cyble Research Labs analyzes Redeemer 2.0, a ransomware variant distributed via an affiliate program that shares 20% of victims’ Monero ransom with affiliates and uses a builder to tailor campaigns. Redeemer 2.0 adds an affiliate toolkit, GUI-based decrypter, …

Read More
Threat Research

From the Front Lines | 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts

June 30, 2022October 14, 2025 Securonix

Over the last month a crimeware group best known as 8220 Gang has expanded their botnet to roughly 30,000 hosts globally through Linux vulnerabilities and poorly secured configurations. The infection script, IRC botnet, and updated PwnRig cryptocurrency miner …

Read More
Threat Research

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems | CISA

June 30, 2022October 15, 2025 Securonix

Cyber threat actors, including state-sponsored APT groups, continue to exploit CVE-2021-44228 (Log4Shell) in unpatched VMware Horizon and Unified Access Gateway (UAG) servers to gain initial access and move laterally within organizations. They deploy loader ma…

Read More
Threat Research

GeckoSpy: Pegasus Spyware Used against Thailand’s Pro-Democracy Movement – The Citizen Lab

June 29, 2022October 16, 2025 Securonix

Pegasus spyware was used against Thailand’s pro-democracy movement, with at least 30 civil society victims infected between October 2020 and November 2021, triggering Apple security notifications in November 2021 and a collaborative forensic investigation. The…

Read More
Threat Research

Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive

June 28, 2022October 14, 2025 Securonix

Researchers document Cloaked Ursa (APT29) campaigns that weaponize trusted cloud storage services to hide malware delivery, notably Dropbox and Google Drive. The campaigns deploy EnvyScout HTML droppers to fetch Agenda.iso payloads and use Google Drive-based e…

Read More
Threat Research

Shortcut-based (LNK) attacks delivering malicious code on the rise

June 28, 2022October 16, 2025 Securonix

Resecurity reports attackers are increasingly using tools to generate malicious shortcut files (.LNK) for payload delivery, with MLNK Builder 4.2 adding AV evasion and icon masquerading. Campaigns by APT groups and cybercriminals—including Bumblebee Loader and…

Read More
Threat Research

Digium Phones Under Attack: Insight Into the Web Shell Implant

June 28, 2022October 16, 2025 Securonix

Unit 42 describes a campaign targeting Elastix/Digium phones where a PHP web shell is implanted to exfiltrate data and fetch additional payloads. The activity links to a Rest Phone Apps RCE (CVE-2021-45461) and is mitigated by Palo Alto Networks WildFire and T…

Read More
Threat Research

PSA: Sudden Increase In Attacks On Modern WPBakery Page Builder Addons Vulnerability

June 27, 2022October 13, 2025 Securonix

Two sentences: Wordfence reports a surge of attacks targeting Kaswara Modern WPBakery Page Builder Addons exploiting CVE-2021-24284 to upload PHP files and take over sites; the plugin is closed with no patch available, leaving all versions affected. Wordfence …

Read More
Threat Research

Confucius:隐藏在CloudFlare下的垂钓者

June 24, 2022October 14, 2025 Securonix

Confucius, an Indian APT group, has targeted Pakistan’s government and military since 2021 using spearphishing attachments and counterfeit government portals to deliver multi-stage loaders. The operation leverages QuasarRAT and bespoke C++/C# backdoors, delive…

Read More
Threat Research

Climbing Mount Everest: Black-Byte Bytes Back?

June 24, 2022October 13, 2025 Securonix

NCC Group analyzes Everest ransomware operations and argues a link to Black-Byte, detailing how Everest-related activity deployed during an incident response used TTPs such as RDP-based lateral movement, credential dumping, and C2 via remote tools. The report …

Read More
Threat Research

ApolloRat: Evasive Malware Compiled Using Nuitka – Cyble

June 24, 2022October 13, 2025 Securonix

ApolloRAT is a Python-based Remote Access Trojan that uses Discord as its C&C server. Cyble researchers note that the RAT is compiled with Nuitka to increase evasion and that threat actors are selling it for a low price on Telegram and their site. #ApolloRAT #…

Read More
Threat Research

Transparent Tribe begins targeting education sector in latest campaign

June 24, 2022October 14, 2025 Securonix

Cisco Talos reports a new campaign by the Transparent Tribe APT targeting Indian educational institutions, deploying CrimsonRAT to establish long-term access into victim networks. The operation also implicates a Pakistani hosting provider, Zain Hosting, as par…

Read More
Threat Research

OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow

June 23, 2022October 16, 2025 Securonix

OrBit is a new undetected Linux threat that hijacks the execution flow by loading a malicious shared object and infects all running and upcoming processes. It provides remote SSH backdoor, harvests credentials, logs TTY commands, and persists via two methods (…

Read More
Threat Research

When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors

June 23, 2022October 14, 2025 Securonix

Unit 42 analyzes Brute Ratel C4 (BRc4) activity tied to a Roshan_CV ISO, showing how a red-teaming tool can evade modern defenses and operate with nation-state-like tradecraft. The post covers the tool’s packaging, delivery via a LNK lure, in-memory execution,…

Read More
Threat Research

North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector | CISA

June 22, 2022October 16, 2025 Securonix

This joint Cybersecurity Advisory explains that Maui ransomware has been used by North Korean state-sponsored actors since May 2021 to target Healthcare and Public Health sector organizations, detailing TTPs and IOCs. It urges mitigations and reporting, and wa…

Read More

Posts pagination

Previous 1 … 513 514 515 … 535 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.