Active infrastructure for Candiru spyware linked to Hungary, Saudi Arabia

Researchers have uncovered new infrastructure used by Candiru’s DevilsTongue spyware, highlighting active clusters in Hungary, Saudi Arabia, and Indonesia. The report discusses the spyware’s deployment methods and mentions the recent acquisition of Candiru’s assets by Integrity Partners, raising concerns about potential continued threats. #Candiru #DevilsTongue #IntegrityPartners #Espionage #Cyberattacks…

Read More
RedHook: A New Android Banking Trojan Targeting Users in Vietnam

RedHook is a new Android banking trojan targeting Vietnamese users through phishing sites impersonating financial and government institutions, utilizing advanced techniques like WebSocket communication, keylogging, and screen capture via Android’s MediaProjection API. The malware’s low VirusTotal detection and Chinese-language artifacts suggest a Chinese-speaking threat actor behind the campaign. #RedHook #AndroidBankingTrojan #VietnamPhishing

Read More