The group has long stolen email passwords by posing as people its targets know. At least one computer was infected, but the number of breached organizations has not been disclosed. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The attacks have been observed weaponizing the f… Reverse-proxy adversary-in-the-middle (AiTM) kits like Tycoon2FA, Sneaky2FA, and Evilginx relay credentials and session tokens in real time, bypassing most forms of MFA.
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. An analysis of the malware sample has found it to embed exploit logic for various command injectio… The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they can access. This is how humans, systems, and now AI, all connect to data, services, and each other securely. Thus, when the victim is prompted to paste and execute a malicious command – as is the case with ClickFix attacks – it executes the cached website content that’s already on the device.
⚡ Threat of the Week Citrix Warns of Newly Exploited NetScaler ADC and Gateway Flaw — Citrix released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. Kothamine uses a legitimate Tailscale tool to receive attackers’ commands through an encrypted connection with no malicious domain to block. Both are widely used information stealers designed to harvest browser credentials, cryptocurrency wallet data, and session tokens from infected endpoints.
Japanese Railway Operators Hit with Weekend Cyber Attacks
On each host, it installs Hermes Agent with instructions to follow operators’ Telegram commands. “The implant installs the framework unchanged, then overwrites its https://travelusanews.com/buy-qube-on-mexc-your-ultimate-buying-guide.html SOUL.md persona file,” ThreatDown said . Then somebody registered it and started serving malicious lures.
Remcos RAT recorded the largest single gain among the top three, rising by 59 samples to reach 196 total uploads, underscoring an intensifying wave of espionage and surveillance-driven campaigns. Who you are and where you live, work, and seek medical care could be revealed by data your car’s app shares with trackers. A new ClickFix campaign is tricking users with a fake Windows update that runs in their browser. The staged data has been found to include details of the botnet https://thefrontclimbingclub.com/terms-of-use and a separate campaign that d…
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
“Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker to initiate unauthorized withdrawals,” Bitget said in a post on X. “The payload lives in at least eight places at once, spread across files, the database, and shared memory, and every one of those places can rebuild all the others,” security researcher Gabriel Barbosa said . Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling .
FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees
Custom GPTs refer to a personalized version of ChatGPT that, as the name implies, allows users to define custom instructions, upload reference files, and enable specific skills to handle unique tasks without any coding. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. On September 24, 2026, the cryptocurrency exchange disclosed that threat actors stole $387.5 million from its hot and warm wallets through a series of unauthorized transfers, prompting it to halt all withdrawals temporarily. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway.
A week in security (September 28 – October
- At least one computer was infected, but the number of breached organizations has not been disclosed.
- As detailed in the weekly threat metrics published in the ANY.RUN malware analysis, DonutLoader climbed 16 samples to 140 uploads, reflecting its growing role as a delivery mechanism for secondary payloads, while Lumma stealer rose 27 samples to 126.
- Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.
- Its role is “deciding which victims are worth an operator’s time,” the company said.
- Xworm followed closely with 183 uploads and a gain of 16, continuing its reputation as a highly adaptable, modular RAT sold through malware-as-a-service channels.
It said this fits a malware-as-a-service model, in which each customer runs a separate copy. Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. “The malicious packages abuse the ‘Baileys’ WhatsApp open source project to add the victims to groups without their consent,” OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday. By 2023, it had already used fake conference and event invitations as bait, often exchanging messages with a target before sending a malicious link.
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. “Following successful exploitation, observed activity included deployment of JSP web shells and reverse shells, privilege escalation, persistent remote-access tooling, and memory-backed execution,” the tech giant said . In a subsequent analysis , Bitget said the attackers exploited the flaw to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system …
- Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again.
- Recent campaigns have shown AsyncRAT operators abusing trusted cloud infrastructure such as Cloudflare’s free-tier services and TryCloudflare tunnels to host payload delivery servers, making detection significantly harder for conventional security tools.
- “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,” Nozomi Networks said in a report published last week.
- Learn where to get relevant threat data for free and how…
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino.
Top 10 Malware Threats of the Week
Prior campaigns have weaponized shared conversations with AI chatbots and malicious Claude Artifacts to distribute stealer malware and remote access trojans (RATs). Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. “Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence,” security researcher Ashley Shen said .