TraderTraitor is a North Korean state-sponsored cyber threat group targeting cryptocurrency and blockchain ecosystems through sophisticated social engineering, supply chain attacks, and cloud compromises. The group has been linked to massive crypto heists, including the $308 million DMM Bitcoin breach and the $1.5 billion Bybit hack. #TraderTraitor #LazarusGroup #DMMBitcoin #Bybit #JumpCloud

Read More
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data

A recently patched macOS vulnerability, CVE-2025-31199, can be exploited to bypass security checks and steal sensitive user information, including Apple Intelligence data. Microsoft security researchers have revealed that attackers can leverage Spotlight plugins to access private files and remotely linked device data. #CVE202531199 #Sploitlight #AppleIntelligence #Spotlight #macOSVulnerability

Read More
In Other News: k Google Cloud Build Flaw, Louis Vuitton Breach Update, Attack Surface Growth

Microsoft has ceased using Chinese engineers to protect sensitive U.S. defense systems amidst concerns over espionage and sabotage. Multiple organizations, including Louis Vuitton and European hospitals, face increasing cybersecurity threats due to data breaches and vulnerabilities. #Microsoft #LouisVuitton #CyberThreats…

Read More
#StopRansomware: Interlock

Interlock ransomware, first observed in September 2024, targets businesses and critical infrastructure across North America and Europe using a double extortion model that encrypts victim data and threatens to leak exfiltrated information. The actors use uncommon entry methods such as drive-by downloads and the ClickFix social engineering technique, employing various malware…

Read More
Beyond Mimo’lette: Tracking Mimo’s Expansion to Magento CMS and Docker

The Mimo threat actor has evolved from targeting Craft CMS to exploiting Magento ecommerce platforms via PHP-FPM vulnerabilities, employing advanced persistence and evasion techniques including the use of GSocket and memfd_create() syscall. Their operations now combine cryptomining and proxyjacking for dual monetization while also targeting Docker instances, demonstrating increasing sophistication and diversification. #Mimo #Magento #GSocket #memfd_create #IPRoyal

Read More
MITRE ATT&CK T1059: Command and Scripting Interpreter with Sample Procedures

This article discusses the widespread use of process injection (MITRE T1055) and command scripting techniques (MITRE T1059) by threat actors to evade detection, execute malicious payloads, and maintain persistence. It highlights real-world malware campaigns and exploits leveraging these tactics, emphasizing their sophistication and stealth capabilities. #MITRE T1055 #MITRE T1059…

Read More
NimDoor macOS Cryptocurrency Stealer

NimDoor is a sophisticated MacOS malware used by North Korean threat actors, likely Stardust Chollima, targeting cryptocurrency and Web3 organizations through advanced technical methods and social engineering. The malware employs unique persistence mechanisms, process injection, and encrypted communications to steal sensitive credentials and data. #NimDoor #StardustChollima #MacOSMalware #Cryptocurrency

Read More
In Other News: k Google Cloud Build Flaw, Louis Vuitton Breach Update, Attack Surface Growth

This cybersecurity roundup highlights recent threats including a Chinese-backed hack targeting a US legal firm and government concerns over Chinese engineers maintaining US defense systems. Key discussions include vulnerabilities in Symantec, cyberattacks on UK retailers, and Chinese espionage against Taiwan’s semiconductor sector. #ChinaThreatActor #SymantecVulnerability…

Read More