Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader

North Korean threat actors involved in the Contagious Interview operation have expanded their software supply chain attacks by deploying a new malware loader named XORIndex in the npm ecosystem, alongside the ongoing HexEval Loader campaign. These loaders deliver multi-stage malware including BeaverTail and InvisibleFerret backdoors, targeting developers and cryptocurrency holders with sophisticated obfuscation and data exfiltration techniques. #XORIndex #HexEvalLoader #ContagiousInterview #BeaverTail #InvisibleFerret

Read More
GLOBAL GROUP: Emerging Ransomware-as-a-Service, Supporting AI Driven Negotiation and Mobile Control Panel for Their Affiliates

GLOBAL GROUP is a newly observed ransomware-as-a-service (RaaS) operation, likely a rebranding of the Black Lock RaaS, targeting multiple sectors across the US, Europe, Australia, and Brazil with advanced malware and AI-powered ransom negotiations. The group relies heavily on Initial Access Brokers to gain network entry and deploy ransomware rapidly, emphasizing high-value targets and seven-figure ransom demands. #GLOBALGROUP #BlackLock #Mamona #Ramp4u #InitialAccessBroker

Read More
Ransom! McKenzie Commercia

The ransomware incident involves the threat actor Akira, who has claimed access to 42 GB of sensitive corporate data belonging to McKenzie Commercial, including employee personal information, financial records, and confidential documents, and has facilitated easy data download via torrent technology. The impacted country is the United States.

Read More
Knight Knox Manchester Property Investment Firm Allegedly Targeted by Qilin Ransomware

The Qilin ransomware group has claimed responsibility for a major cyberattack on Knight Knox, a key UK property investment firm. The attack involved the exfiltration of 100 GB of data, including sensitive client and financial information, highlighting the increasing threat of ransomware targeted at valuable business data. #QilinGroup #KnightKnox #Ransomware #DataBreach…

Read More
India Takes a Quantum Leap in Cybersecurity with MeitY’s Strategic Whitepaper

India’s Ministry of Electronics and Information Technology, along with CERT-In and SISA, has released a whitepaper on preparing for the quantum cybersecurity revolution. The document emphasizes the need for organizations to adopt quantum-resistant algorithms to safeguard digital infrastructure against emerging threats from quantum computing. #QuantumComputing #CyberReadiness…

Read More
Malicious Inno Setup Loader Deploys RedLine Stealer

Cybercriminals are increasingly abusing legitimate Inno Setup installers by embedding malicious payloads using Pascal scripting to evade detection and deliver information-stealing malware such as RedLine Stealer. This campaign employs sophisticated evasion techniques including debugger checks, sandbox avoidance, DLL sideloading, and command obfuscation to persist on infected systems and steal sensitive data. #InnoSetup #HijackLoader #RedLineStealer

Read More
Ransom! McKenzie Commercia

The ransomware claim from the threat actor Qilin targeted fuld.com, a US-based financial research and analytics firm founded in 1978 with headquarters in Boston, Massachusetts. The attack disrupted their operations and compromised sensitive strategic information. #United States

Read More