U.S. Sentences Samourai Wallet Founders for 7M Crypto Money Laundering Scheme

The U.S. Justice Department has sentenced the co-founders of Samourai Wallet for laundering over $237 million using the platform’s cryptocurrency-mixing features. The case highlights how criminal actors exploited the platform to mask funds involved in drug trafficking, darknet operations, and various illegal activities. #SamouraiWallet #CryptocurrencyMixing…

Read More
The Gentlemen Ransomware

The Gentlemen emerged around July 2025 as an advanced Ransomware-as-a-Service group using dual‑extortion to encrypt and exfiltrate data, publishing dozens of victims on a darknet leak site within months. Their cross‑platform lockers (Windows/Linux/ESXi), modular features (self‑restart, run‑on‑boot, WMI/PowerShell propagation), and affiliate support make them a rapidly evolving threat. #TheGentlemen #XChaCha20

Read More
Threat Intelligence Automation

Automated threat intelligence enables machine-speed detection, enrichment, and response to indicators of compromise, reducing mean time to detect and respond while freeing analysts from repetitive tasks. Recorded Future’s Intelligence Cloud delivers this capability through continuous data collection, ML-driven risk scoring, and integrations with SIEM, SOAR, and EDR to enable real-time defensive actions. #RecordedFuture #InsiktGroup

Read More
Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows

Cybersecurity experts have identified the Tsundere botnet, actively targeting Windows systems since mid-2025, with sophisticated mechanisms including WebSocket communication on the Ethereum blockchain. The malware spreads through fake MSI installers and PowerShell scripts, leveraging gaming-related lures and maintaining persistence via registry modifications. #TsundereBotnet #EthereumBlockchain…

Read More
Cooking up trouble: How TamperedChef uses signed apps to deliver stealthy payloads

Acronis TRU tracked a global malvertising and SEO-driven campaign named “TamperedChef” that distributes digitally signed fake installers which persist via scheduled tasks and execute heavily obfuscated JavaScript backdoors with remote code execution and HTTPS-based C2. The operators use U.S.-registered shell companies to acquire and rotate code-signing certificates, short-lived domain registrations, and malvertising/SEO to hide infrastructure and quickly recover after takedowns. #TamperedChef #Obfuscator_io

Read More
ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves

Recent cybersecurity incidents reveal a rise in international espionage, targeted hacking campaigns, and vulnerabilities in widely used systems and devices. These stories highlight the ongoing efforts of governments, cybercriminals, and security researchers to adapt and respond to new online threats. #LinkedInEspionage #OracleVulnerability…

Read More
Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

Cyble and BOCRA have signed an MoU to enhance Botswana’s cybersecurity defenses through advanced threat intelligence and capacity building initiatives. This collaboration aims to improve incident response, reduce cyber risks, and develop a skilled cybersecurity workforce in Botswana. #DarkWebMonitoring #BotswanaCybersecurity…

Read More
Blockchain and Node.js abused by Tsundere: an emerging botnet

Kaspersky GReAT discovered the Tsundere botnet in mid-2025, a Node.js-based botnet that installs via MSI or PowerShell, uses npm components (ws, ethers, pm2) for persistence, and retrieves WebSocket C2 addresses from an Ethereum smart contract. The botnet is linked to prior October 2024 typosquatting npm supply-chain activity and to a Russian-speaking actor potentially known as “koneko”, with shared infrastructure tied to the 123 Stealer panel. #Tsundere #123Stealer

Read More