SOE-phisticated Persistence: Inside Flax Typhoon’s ArcGIS Compromise

A China-backed APT (Flax Typhoon) maintained year-long access to an ArcGIS environment by converting a legitimate Java Server Object Extension (SOE) into a hardcoded-key gated web shell and embedding it in backups to survive recovery. The intruders also deployed a renamed SoftEther VPN executable as a service for persistent C2 and lateral access. #FlaxTyphoon #ArcGIS

Read More
The ClickFix Factory: First Exposure of IUAM ClickFix Generator

Attackers are commoditizing the ClickFix social-engineering technique into phishing kits like the IUAM ClickFix Generator to automate creation of spoofed browser-verification pages that trick victims into manually executing malware. Observed campaigns delivered DeerStealer and Odyssey infostealer using clipboard-injection and OS-detection features from hosted phishing pages. #IUAM_ClickFix_Generator #DeerStealer #Odyssey…

Read More
Akira Ransomware Attack Hits Cerenade Technology, Harbor Diesel & Equipment, J. Lorber Company

The Akira ransomware group has claimed to breach multiple organizations, exfiltrating sensitive data and threatening its release. Victims include Cerenade Technology, Harbor Diesel & Equipment, and J. Lorber Company, with compromised data spanning personal, financial, and corporate information. #AkiraRansomware #DataLeakage #CyberThreats…

Read More
Electronics giant Avnet confirms breach, says stolen data unreadable

Avnet experienced a data breach involving the theft of 7 to 12TB of data stored on an external cloud service, although most of it remains unreadable without proprietary tools. The company quickly responded by rotating secrets in its Azure/Databricks environments and reports that the breach was limited to a single system in the EMEA region. #Avnet #Cyberattack #DarkWeb #DataLeak #EMEARegion

Read More