A threat actor exploited the CVE-2025-32432 flaw in Craft CMS to deploy malware, including a cryptominer and proxyware, for cryptojacking and proxyjacking activities. This ongoing campaign is linked to the Mimo intrusion set, which has a history of exploiting vulnerabilities for financial gain. #CVE-2025-32432 #Mimo #cryptomining #proxyware…
Tag: THREAT HUNTING
The Silent Ransom Group (SRG) is intensifying its cyber attacks against U.S. law firms in 2025, using social engineering tactics such as callback phishing and fake IT support calls to gain unauthorized remote access and exfiltrate sensitive data. Victims face ransom demands under threats of public exposure, emphasizing the critical need for enhanced employee training and strict IT authentication protocols. #SilentRansomGroup #CallbackPhishing #WinSCP #Rclone
The article analyzes the Mimo intrusion set exploiting CVE-2025-32432 in the Craft CMS to deploy a loader, crypto miner, and residential proxyware. It also identifies key attacker infrastructure, malware components, and possible operator attribution linked to TikTok profiles. #Mimo #CVE202532432 #XMRig #IPRoyal #MinusRansomware
Microsoft has detailed the activities of the Russia-linked espionage group “Void Blizzard,” which has targeted government and defense organizations across Europe and North America. The group uses sophisticated phishing tactics and cloud abuse to steal sensitive data, posing significant risks to NATO and Ukraine. #VoidBlizzard #Evilginx #RussiaCyberEspionage #MicrosoftThreatIntel…
Void Blizzard is a Russia-affiliated threat actor conducting targeted espionage primarily against NATO member states, Ukraine, and critical sectors in Europe and North America using stolen credentials and spear phishing. The group exploits cloud services like Exchange Online and Microsoft Graph to exfiltrate large volumes of emails and files, with recent tactics including man-in-the-middle phishing campaigns using fake Microsoft Entra portals. #VoidBlizzard #LAUNDRYBEAR #Evilginx #MicrosoftEntra
InvisibleFerret is a Python-based backdoor malware used by North Korean threat actors like the Lazarus Group, targeting Windows and Linux systems through social engineering disguised as recruitment schemes. This article explains how to detect and mitigate InvisibleFerret on Linux endpoints using Wazuh’s custom detection rules, CDB lists, and Active Response automation….
ReversingLabs researchers uncovered a new malicious campaign leveraging ML models serialized in the Pickle format to distribute infostealer malware via PyPI packages masquerading as Alibaba AI Labs SDKs. This campaign highlights the emerging threat of malware embedded in ML file formats, emphasizing the need for advanced detection tools tailored to AI/ML software supply chains. #nullifAI #Pickle #PyPI #ReversingLabs
This article discusses techniques for log file analysis, emphasizing the importance of data filtering, detection, and domain knowledge for incident response and threat hunting. It highlights the challenges of managing large-scale log data and explores tools and formats like Parquet, Spark, and ClickHouse for efficient analysis. #Zeek #Parquet
Nation-state threat actors are targeting Commvault applications hosted in Microsoft Azure as part of a broader campaign against SaaS cloud platforms. CISA recommends organizations implement security best practices such as credential rotation and log monitoring to defend against these attacks. #CVE20253928 #AzureThreats…
A zero-day vulnerability in Commvault’s SaaS solutions has been exploited by threat actors, potentially as part of a broader campaign targeting cloud applications. Organizations are urged to enhance their monitoring and security practices to prevent further compromises. #CVE20253928 #AzureThreatActors…
The U.S. CISA has announced that Commvault is experiencing cyber threats targeting their Azure-hosted applications, possibly compromising client secrets in their Microsoft 365 backup service. This incident is linked to a zero-day vulnerability (CVE-2025-3928) exploited by sophisticated threat actors, prompting increased security measures. #CVE20253928 #Commvault #MicrosoftAzure…
Elastic Security Labs discovered a new malware family named DOUBLELOADER, often seen with RHADAMANTHYS infostealer, employing the open-source obfuscator ALCATRAZ to evade analysis. The post details multiple obfuscation techniques used by ALCATRAZ and demonstrates methods and tools to deobfuscate and analyze such protected malware. #DOUBLELOADER #RHADAMANTHYS #ALCATRAZ
Rapid7 uncovered an ongoing malware campaign using trojanized NSIS installers disguised as popular apps to deploy the Winos v4.0 malware, which runs entirely in memory to evade detection. The modular infection chain, dubbed Catena, involves multi-stage payloads, reflective DLL injection, and sophisticated persistence mechanisms, with strong links to the Silver Fox APT targeting Chinese-speaking environments. #WinosV4 #CatenaLoader #SilverFoxAPT
This advisory details a Russian GRU unit 26165 cyber espionage campaign targeting Western logistics and technology companies involved in support to Ukraine, employing known tactics such as spearphishing, credential spraying, and exploitation of vulnerabilities. The actors also conducted large-scale surveillance of IP cameras near Ukraine and NATO borders to track aid…
Trend Micro researchers uncovered new fake CAPTCHA campaigns leveraging disguised MP3 and HTML files that trick Windows users into running malicious scripts via the Run dialog, leading to data theft and remote access through malware like Lumma Stealer, Emmental, Rhadamanthys, AsyncRAT, and XWorm. These sophisticated attacks use phishing, SEO poisoning, and…