Intellexa’s Global Corporate Web

Predator is a modular, stealthy mercenary spyware developed by Cytrox and distributed via an Intellexa-linked corporate web, enabling full access to microphones, cameras, and all device data on Android and iPhone devices. The report maps Intellexa’s fragmented corporate infrastructure, documents delivery methods including “1-click” and ad-based (“Aladdin”) vectors, and details observed deployments across multiple countries alongside mitigations and ongoing investigations. #Predator #Intellexa

Read More
ThreatsDay Bulletin: AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories

This week highlighted the resurgence of Mirai-based IoT malware and the increasing sophistication of cybercriminal techniques such as AI-powered scams and stealthy malware targeting email servers. Governments and security companies are actively fighting back through regulation, upgrades, and takedowns. #ShadowV2 #Mirai #OpenFind…

Read More
Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix

Acronis TRU researchers uncovered a novel “JackFix” ClickFix campaign that hijacks the browser to display a convincing full‑screen fake Windows Update prompting victims to run malicious commands. The multistage attack (mshta → PowerShell downloader → final payloads) uses heavy obfuscation, UAC bombardment and a “spray and prey” downloader that executes up to eight payloads including Rhadamanthys and Vidar 2.0, and is detected and blocked by Acronis XDR at the PowerShell stage. #ClickFix #Rhadamanthys

Read More
China-Nexus Autumn Dragon APT Exploits WinRAR Flaw to Deploy Telegram C2 Backdoor

CyberArmor’s report reveals a sophisticated espionage campaign named “Autumn Dragon” targeting Southeast Asian governments and media, possibly linked to Chinese threat actors. The campaign employs a complex malware chain involving DLL sideloading, Telegram C2, and encrypted payloads to gather intelligence covertly. #AutumnDragon #ChinaNexus…

Read More
UNC2891 Money Mule Network Reveals Full Scope of ATM Fraud Operation

Cybersecurity researchers have uncovered a multi-year ATM fraud campaign by the UNC2891 threat group targeting Indonesian banks, utilizing advanced malware and social engineering tactics. The campaign involved cloned cards, money mule networks, and persistent system infiltration, highlighting the evolving nature of ATM-based cyber threats. #UNC2891 #STEELCORGI #CAKETAP #ATMrotection #BankA #BankB…

Read More
APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains

A China-linked threat actor known as APT24 has been using sophisticated malware called BADAUDIO to maintain persistent access to compromised networks through a campaign spanning nearly three years. The campaign includes supply chain attacks, web compromises, and spear-phishing, primarily targeting organizations in Taiwan and Southeast Asia. #APT24 #BADAUDIO…

Read More