Summary: The content discusses the decline in activity of the Predator spyware group, indicating that sanctions and exposure have impacted their operations. Threat Actor: Predator spyware group | Predator spyware group Victim: Journalists, members of civil society, opposition politicians | Predator…
Tag: SPYWARE
FortiGuard Labs dissected MerkSpy, a spyware campaign exploiting CVE-2021-40444 in Microsoft Office to silently compromise Windows systems. The attack chain downloads and decodes a loader, injects MerkSpy into memory, and exfiltrates keystrokes, screenshots, a…
Summary: Polish prosecutors have seized Pegasus spyware systems from a government agency in Warsaw as part of an investigation into the alleged abuse of the surveillance tool by the previous Polish government to spy on opposition politicians. Threat Actor: Polish Government | Polish Government Victi…
Summary: The Security Service of Ukraine (SSU) has dismantled the infrastructure used by pro-Russia Ukraine residents to break into soldiers’ devices and deploy spyware. The infrastructure included bot farms and thousands of mobile numbers and Telegram accounts. Threat Actor: Russian intelligence se…
Group-IB highlights growing Apple-device targeting, noting the App Store as a frequent malware distributor and the potential risk from third-party stores under the EU DMA. The report introduces GoldPickaxe, an iOS Trojan derived from GoldDigger that harvests f…
ESET researchers uncovered five Android campaigns distributing AridSpy, a multistage spyware likely run by the Arid Viper APT group, with several campaigns still active as of publication. AridSpy downloads first- and second-stage payloads from a C2 server and …
Summary: This content discusses five cyber espionage campaigns targeting Android users in Egypt and Palestine, attributed to the Arid Viper hacking group. Threat Actor: Arid Viper | Arid Viper Victim: Android users in Egypt and Palestine | Android users in Egypt and Palestine Key Point : ESET resear…
Operation Celestial Force is a long-running espionage campaign operated by a Pakistani threat actor cluster dubbed Cosmic Leopard, leveraging GravityRAT on Android and Windows-based HeavyLift loaders, managed through GravityAdmin panels. The operation targets …
Malvertising campaigns are distributing trojanized PuTTY and WinSCP installers by abusing online ad networks and fake download sites, targeting Windows administrators. The attackers use typosquatting domains and deceptive ads to push ransomware and steal data,…
In the ever-evolving cybersecurity landscape, staying informed with the latest statistics and trends is not just beneficial—it’s imperative. The year 2024 is shaping up to be pivotal, with threats becoming more sophisticated and industries worldwide grappling with a digital environment that’s more i…
Summary: Independent journalists and opposition activists in Europe, who have faced threats from Russia or Belarus, have been targeted or infected with the Pegasus spyware. Threat Actor: NSO Group | NSO Group Victim: Independent journalists and opposition activists in Europe | Independent journalist…
Summary: Researchers have discovered a macOS version of the LightSpy spyware that has been active since January 2024, with threat actors using publicly available exploits to deliver the spyware and exfiltrate private information from devices. Threat Actor: LightSpy | LightSpy Victim: macOS users | m…
Summary: Sonatype has discovered a malicious PyPI package called ‘pytoileur’ that downloads and installs trojanized Windows binaries capable of surveillance, achieving persistence, and crypto-theft. This discovery led to an investigation into similar packages as part of a wider “Cool package” campai…
LightSpy macOS is part of a broader LightSpy surveillance framework targeting multiple platforms, with a modular core and plugins designed to exfiltrate a wide range of data and maintain control. The article analyzes the macOS implant chain, including initial …
A stalkerware company with poor security practices is exposing victims’ data as the software, designed for unauthorized device monitoring, leaked victims’ phone screenshots through a publicly accessible URL. The incident highlights the dangers of stalkerware, which not only facilitates illegal…