New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps

A new Android spyware campaign called ClayRat is actively targeting users in Russia by impersonating popular apps and using malicious links and websites. The malware can exfiltrate sensitive data, control device functions, and propagate itself through contacts, making it a significant surveillance threat. #ClayRat #AndroidSpyware #C2Servers…

Read More
Hackers Extorting Salesforce After Stealing Data From Dozens of Customers

A group claiming ties to known hacking collectives has announced the theft of data from dozens of Salesforce customers, threatening to leak sensitive records unless paid a ransom. The hackers, including members of Lapsus$, Scattered Spider, and ShinyHunters, targeted major organizations like Disney, Toyota, and Google. #Lapsus$ #ScatteredSpider #ShinyHunters #SalesforceDataLeakage #ExtortionCampaign…

Read More
Threat Research | Weekly Recap [05 Oct 2025]

Cybersecurity Threat Research ‘Weekly’ Recap. The update covers ongoing abuse across Messaging & Social Platforms, including WhatsApp/Android trojans, fake groups targeting seniors, SMS smishing, and AI-generated clone sites harvesting PII. It also highlights ransomware and extortion trends (Yurei, FunkLocker, BQTLock), notable APTs and long-term intrusions (Phantom Taurus, Confucius, Goffee, Lunar Spider, Scattered Lapsus$ Hunters, Lazarus), malware distribution & infrastructure abuse (WordPress malvertising, Detour Dog, WARMCOOKIE, Rhadamanthys, ClickFix, XiebroC2), Linux threats (Koske, FlipSwitch), and threat intel/detection tooling guidance (YARA hunting, intel ops best practices).

Read More
Cybersecurity News | Daily Recap [04 Oct 2025]

Daily Recap, The article covers extortion and ransomware activities (Scattered Spider/LAPSUS$ threaten Salesforce, Toyota, Disney, Google; Cl0p-Oracle extortion linked to patched vulnerabilities and FIN11) alongside data breach incidents (Discord third-party breach; Renault UK; Shamir Medical Center). It also highlights actor activity and evolving malware campaigns (Detour Dog with Strela Stealer; Rhadamanthys MaaS; Confucius Group’s AnonDoor), plus notable vulnerabilities and privacy issues (Palo Alto Network scans; Splunk flaws; DrayTek CVE-2025-10547; ALPR surveillance debates) and industry responses (Signal SPQR; Oneleet funding). #ScatteredSpider #LAPSUS$ #Cl0p #FIN11 #DiscordData #RenaultUK #ShamirAttack #DetourDog #StrelaStealer #Rhadamanthys #AnonDoor #ConfuciusGroup #PaloAlto #Splunk #DrayTek #ALPR #FlockRaven #Signal #SPQR #Oneleet

Read More
Cybersecurity News | Daily Recap [04 Oct 2025]

Daily Recap, The day’s recap covers extortion campaigns tied to Oracle data theft, notable APT activity like Confucius shifting to AnonDoor, and new ransomware incidents impacting brands such as Asahi, with ongoing vulnerability disclosures including Meteobridge, Festo, and DrayTek. It also highlights privacy/legal actions, defense updates, and smishing infrastructure trends shaping the threat landscape. #Clop #FIN11 #ShinyHunters #Lapsus$ #CrimsonCollective #RedHat #Oracle #Asahi #Meteobridge #Festo #DrayTek #Confucius #AnonDoor #CavalryWerewolf #FoalShell #StallionRAT

Read More
European parliamentarians implore EU leadership to stop funding spyware

European members of parliament are questioning why the EU is funding spyware companies like Intellexa Alliance and Cy4Gate, which have been linked to unlawful surveillance and targeting civil society. This funding raises concerns about transparency, governance, and the impact on democracy, rights, and rule of law. #SpywareFunding #EUBudget #CivilSocietySurveillance…

Read More
Scam Facebook groups send malicious Android malware to seniors

Attackers created fake Facebook groups targeting active seniors to distribute Android malware posing as event registration apps, sometimes asking for sign-up fees to phish card details. The primary malware observed was the Datzbro trojan (and occasionally the Zombinder dropper), delivered via links or messages and capable of audio/video recording, overlay phishing,…

Read More
New spyware campaigns target privacy-conscious Android users in the UAE

ESET researchers discovered two undocumented Android spyware families—Android/Spy.ProSpy and Android/Spy.ToSpy—that impersonate Signal and ToTok to trick users into manually installing malicious APKs from deceptive websites, with confirmed targeting of users in the United Arab Emirates. Both families persist on devices and exfiltrate sensitive data (including ToTok .ttkmbackup files) to active C2 servers, and known samples/domains and hashes have been shared. #Android/Spy.ProSpy #Android/Spy.ToSpy

Read More
Researchers uncover spyware targeting messaging app users in the UAE

Cybersecurity researchers have uncovered new Android spyware campaigns, ProSpy and ToSpy, concealed within fake messaging apps targeting users in the United Arab Emirates. These campaigns utilize fake websites and app stores to install persistent spyware capable of stealing sensitive data, with ongoing operations linked to command-and-control servers. #ProSpy #ToSpy #ESET #UAE…

Read More