ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

This week’s ThreatsDay Bulletin highlights how cyber attackers continuously adapt by modifying familiar tools and tactics, making the threat landscape more dynamic. Key incidents include a large international scam ring, emerging modular info stealers, and increased exploitation of vulnerabilities like React2Shell. #Eurojust #SantaStealer #React2Shell…

Read More
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App

Kimsuky, a North Korean threat actor, has launched a campaign distributing Android malware called DocSwap through phishing sites and QR codes, mimicking logistics services like CJ Logistics. The malware features RAT capabilities, credential theft, and can perform extensive device monitoring, underlining sophisticated social engineering tactics. #Kimsuky #DocSwap #CJLogistics #AndroidMalware #RAT…

Read More
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts

Amazon’s AWS GuardDuty team has identified a crypto-mining campaign that exploits compromised IAM credentials to target EC2 and ECS services, employing persistent methods to hinder incident response. The threat actor used a malicious Docker image and automated scripts to maximize mining operations, causing financial and resource exhaustion for AWS customers. #CryptoMining #IAMCompromise

Read More
Ink Dragon’s Global Mesh: How Chinese Spies Turn Compromised Government Servers into C2 Relay Nodes

A Chinese cyber-espionage group called Ink Dragon is transforming compromised servers into active communication nodes using sophisticated relay architecture. Their expansion into European government targets highlights the evolving threat landscape and the importance of patching vulnerabilities. #INKDRAGON #ShadowPad…

Read More
BlindEagle Targets Colombian Government Agency with Caminho and DCRAT

Zscaler ThreatLabz attributes a spear-phishing campaign targeting a Colombian government agency to the BlindEagle actor, which used a compromised internal email account, an SVG-smuggled fake judicial portal, nested JavaScript and PowerShell, steganography, the Caminho downloader, and DCRAT as the final RAT. The attack chain involved in-memory execution, Discord-hosted artifacts, process hollowing, and an AES-encrypted DCRAT configuration tied to a certificate-based C2 authentication. #BlindEagle #DCRAT

Read More
New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails

Operation ForumTroll is a sophisticated phishing campaign targeting individuals in Russia, utilizing zero-day Chrome vulnerabilities to deliver backdoors and spyware. The campaign features personalized emails and uses strategically aged domains to avoid detection, with ongoing threats observed since 2022. #OperationForumTroll #LeetAgent #Dante #Tuoni…

Read More
Russia-linked hackers breach critical infrastructure organizations via edge devices

A Russia-linked hacker group has been exploiting vulnerabilities in edge devices of critical infrastructure sectors since 2021, focusing on credential harvesting and lateral movement. The campaign is linked to Russia’s GRU and aims mainly at energy, telecommunications, and cloud organizations in North America, Europe, and the Middle East. #Sandworm #GRU…

Read More

Jewelbug, also known as Ink Dragon, is a highly sophisticated threat group targeting government entities across Europe, Asia, and Africa since March 2023. They utilize advanced malware tools like FINALDRAFT and ShadowPad to conduct stealthy intrusions, lateral movements, and data exfiltration, forming a resilient, multi-layered infrastructure. #Jewelbug #InkDragon #FINALDRAFT #ShadowPad #CobaltStrike…

Read More
Inside Ink Dragon: Revealing the Relay Network and Inner Workings of a Stealthy Offensive Operation

Check Point Research attributes a sustained espionage campaign to the Chinese-aligned cluster Ink Dragon that exploits ASP.NET ViewState deserialization and ToolShell SharePoint vulnerabilities to gain initial access and then deploys ShadowPad IIS listener modules and FinalDraft implants to build a distributed relay and cloud-backed C2 fabric. The operator harvests credentials (LSASS dumps, IIS worker accounts), uses RDP/SMB lateral movement, DLL sideloading, debugger-based loaders, scheduled tasks/services for persistence, and turns victims into active C2 relay nodes. #InkDragon #ShadowPad

Read More
The APT35 Dump Episode 4: Leaking The Backstage Pass To An Iranian Intelligence Operation – DomainTools Investigations | DTI

Episode 4 of the Charming Kitten / APT35 leak shows Iranian cyber operations run like a bureaucratic procurement system, with spreadsheets linking domain registrations, VPS rentals, ProtonMail identities, and Cryptomus payments that tie requests, invoices, and live infrastructure together. The same administrative apparatus mapped in the ledgers also supported Moses Staff’s leak-and-defacement campaigns—domains such as moses-staff.io, linked ProtonMail addresses, IP allocations, and bitcoin wallets were documented—exposing operational hygiene failures and reusable supply-chain patterns. #APT35 #MosesStaff

Read More