Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Tag: INITIAL ACCESS

Threat Research

DEV-0139 launches targeted attacks against the cryptocurrency industry | Microsoft Security Blog

November 28, 2022October 17, 2025 Securonix

Citrine Sleet (formerly DEV-0139) targeted cryptocurrency investment companies, leveraging social pretexting on Telegram and a weaponized Excel document to deliver a backdoor via DLL proxying. The campaign shows sophisticated industry knowledge, multiple deliv…

Read More
Threat Research

Lazarus APT uses fake cryptocurrency apps to spread AppleJeus Malware

November 25, 2022October 16, 2025 Securonix

North Korea-linked Lazarus APT ran a campaign distributing fake cryptocurrency apps under the BloxHolder brand to push the AppleJeus malware and gain initial access to crypto users. The operation, active June–October 2022, used a cloned HaasOnline site and mul…

Read More
Threat Research

Erbium Stealer Malware Report – CYFIRMA

November 24, 2022October 13, 2025 Securonix

Erbium Stealer is an information-stealing malware distributed as MaaS, observed by CYFIRMA in Aug-2022 and advertised on Russian-speaking forums. It decrypts obfuscated code, drops a DLL in %temp%, loads it via LoadLibraryA, and communicates with a C2 panel an…

Read More
Threat Research

求职陷阱:Lazarus组织以日本瑞穗銀行等招聘信息为诱饵的攻击活动分析

November 23, 2022October 13, 2025 Securonix

Lazarus is analyzed as a financially focused APT group with suspected Northeast Asian origins, noted for multi-stage VHD-based attacks that bypass common defenses and target financial institutions and crypto exchanges. The operation includes spearphishing bait…

Read More
Threat Research

Cyble – Redline Stealer Being Distributed Via Fake Express VPN Sites

November 23, 2022October 20, 2025 Securonix

CRIL from Cyble analyzed phishing campaigns that impersonate ExpressVPN to distribute the Redline Stealer, delivered through fake ExpressVPN sites. Attackers use shortened URLs with valid SSL to lure users, download a malicious ZIP, and then the payload is inj…

Read More
Threat Research

Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin

November 22, 2022October 17, 2025 Securonix

ESET researchers analyzed Dolphin, a previously unreported backdoor used by ScarCruft (APT37) that operatives deploy on select targets to exfiltrate files, log keystrokes, take screenshots, and steal browser credentials, using Google Drive for C2. The Dolphin …

Read More
Threat Research

Cyble – Aviation Industry Facing Ransomware Headwinds

November 22, 2022October 16, 2025 Securonix

The aviation sector in Southeast Asia faced multiple ransomware incidents targeting airlines in Malaysia, Thailand, Portugal, and Kuwait, linked to several threat actors including Daixin Team, ALPHVM (BlackCat), Ragnar Locker, and LockBit. The report outlines …

Read More
Threat Research

Emotet Strikes Again – LNK File Leads to Domain Wide Ransomware

November 21, 2022October 14, 2025 TheDFIR

An Emotet-driven intrusion led to domain-wide deployment of Quantum ransomware after eight days, leveraging Cobalt Strike for discovery and lateral movement and remote-access tools for persistence. The operation included initial access via LNK, PowerShell-base…

Read More
Threat Research

THREAT ALERT: Aggressive Qakbot Campaign and the Black Basta Ransomware Group Targeting U.S. Companies

November 16, 2022October 16, 2025 Securonix

Cybereason’s Global SOC is tracking a wide Black Basta ransomware campaign that leverages QakBot (QakBot) to gain entry and move laterally in U.S.-based organizations. The campaign ties QakBot infections to rapid deployment of Black Basta, including DNS disrup…

Read More
Threat Research

Fielding Threats: Cyber, Influence, and Physical Threats to the 2022 FIFA World Cup in Qatar | Recorded Future

November 15, 2022October 17, 2025 Securonix

Recorded Future’s Insikt Group analyzes the threat landscape around the 2022 FIFA World Cup in Qatar, covering state-sponsored cyber operations, cybercrime, influence operations, and physical security threats. The assessment finds no imminent disruptive cyber …

Read More
Threat Research

#StopRansomware: Hive Ransomware | CISA

November 15, 2022October 16, 2025 Securonix

Hive ransomware operates as a ransomware-as-a-service (RaaS) that has victimized thousands across sectors like Healthcare and Public Health, encrypting data and threatening leaks. The advisory inventories Hive’s TTPs, IOCs, and mitigations, including initial a…

Read More
Threat Research

WatchDog Continues to Target East Asian CSPs

November 14, 2022October 16, 2025 Securonix

Researchers at Cado Labs report the re-emergence of WatchDog, a threat actor known for cryptojacking cloud resources. The new campaign targets East Asian Cloud Service Providers using a shell script and a Monero wallet, revealing defense evasion, competitive m…

Read More
Threat Research

ARCrypter Ransomware Expands Its Operations From Latin America to the World

November 11, 2022October 15, 2025 Securonix

ARCrypter is a previously unknown ransomware family that emerged in Latin America (notably Chile, with Invima involvement) and has expanded to victims in China and Canada, featuring a two-stage dropper and payload and a ransom note delivered before encryption.…

Read More
Threat Research

Venus Ransomware | Zeoticus Spin-off Shows Sophistication Isn’t Necessary for Success

November 11, 2022October 13, 2025 Securonix

Venus ransomware, also known as Goodgame, operates as a standalone legacy package with links to Zeoticus and has been encrypting files globally since August 2022. It relies on publicly exposed RDP and common attack techniques rather than sophisticated malware,…

Read More
Threat Research

Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries

November 9, 2022October 13, 2025 Securonix

Symantec links a state-sponsored activity to Billbug (aka Thrip/Lotus Blossom), targeting a certificate authority and government/defense agencies across Asia since March 2022. The operation employs dual-use tools and backdoors (Hannotog and Sagerunex), uses St…

Read More

Posts pagination

Previous 1 … 212 213 214 … 224 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.