Threat Intelligence — Page 10

The USB Drop That Changed Pen Testing: Steve Stasiukonis's Credit Union Experiment, Revisited
Twenty years ago, a handful of booby-trapped thumb drives in a parking lot became one of the most-cited social-engineering case studies in security history. Here's what actually happened.

Small Gaps, Big Consequences: The Week's Breaches Ran on Trust, Not Zero-Days
Browsers, bots, AI sandboxes and email flows all failed the same way — quietly, and inside the rules.

ToddyCat's New Umbrij Malware Pulls Gmail Straight From Google's API
Kaspersky ties the China-nexus crew to a Gmail-siphoning tool that skips the browser and talks to Google directly.

ChocoPoC: The Fake Exploit Repos Turning Bug Hunters Into Victims
A Python-based infostealer is hiding inside GitHub proof-of-concept code marketed to vulnerability researchers, siphoning credentials, cookies, and files before dropping a remote shell.

ChocoPoC RAT Hides in Fake GitHub Exploits, Targets Security Researchers
A cluster of trojanized proof-of-concept repositories is pushing a Python-based RAT to the very people who go looking for them.

Scattered Spider Suspect, 19, Extradited From Finland to Chicago
Peter Stokes, a dual U.S.-Estonian citizen, faces conspiracy, intrusion and fraud charges tied to the loose-knit crew behind a string of high-profile enterprise breaches.

ScreenConnect Turned Loader: Trojanized Installers Push AsyncRAT via Spoofed Software Sites
A sprawling campaign is abusing a legitimate RMM binary to sideload AsyncRAT onto victims chasing free copies of OBS Studio, Bandicam, and other utilities.

VEIL#DROP: Blogger-Hosted Chain Drops PureLogs Stealer
Researchers flag a multi-stage delivery scheme abusing Google's Blogger platform to stage PureLogs, an infostealer sold in underground forums.

Ousaban Resurfaces in Iberia, Hiding Bank-Stealer Payloads Inside Images
A Brazilian trojan pivots to Spanish and Portuguese banking customers, using geofenced PDF lures and steganography to bury its real payload.

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate
Unit 42 documents a pre-positioning tactic where actors register non-existent domains that chatbots keep suggesting, then wait for the traffic to arrive.

ClickFix Grows a Back Office: API-Served Payloads and a New AMSI Bypass
Researchers pulled roughly 3,000 live payloads from ClickFix infrastructure and found a polymorphic delivery pipeline built to defeat Windows script scanning.

RustDuck: A Rust-Based DDoS Botnet Quietly Building Out Since February
XLab researchers say the two-stage loader is iterating faster than its install base is growing — and that's the interesting part.

Silent Swap: Unsigned Installers Drop Fake Chromium Extensions That Hijack Crypto Transactions
McAfee Labs documents a clipper campaign using .NET and Golang loaders to sideload a malicious browser extension that rewrites wallet addresses at send time.

BEC Isn't an Email Problem. It's a Supply Chain.
Underground forums show Business Email Compromise as a multi-stage operation — account access, target research, and mules — not a clever phishing lure.

FIFA 2026 Fraud Infrastructure Was Pre-Staged Months Before Kickoff, Researchers Say
A Check Point exposure report documents pre-positioned phishing kits, lookalike domains and multilingual scam pages built well ahead of the June 11 opening match.