Threat Intelligence — Page 13

OXLOADER Drops CastleStealer via Poisoned Google Ads, Researchers Say
Elastic Security Labs links the malvertising chain to a likely Russian-speaking, financially motivated operator.

Weekly Threat Roundup: EDR Killers, Browser Bugs, and an Android Trojan With Too Many Hands
Another week of recycled tradecraft — abused integrations, poisoned WordPress, and ransomware crews still gunning for endpoint sensors.

ShinyHunters Doesn't Need Malware. That's the Point.
The group's latest breaches are a reminder that stolen credentials and patience beat zero-days most days of the week.

AryStinger Quietly Conscripts 4,300 Old Routers Into a Recon Proxy Fabric
Researchers say the malware skips the usual DDoS playbook and instead builds infrastructure for pre-breach reconnaissance.

INTERPOL Flags Sharp Rise in Phishing, Ransomware and AI Scams Across Asia-Pacific
A new INTERPOL assessment maps a region where cybercrime is outpacing defensive capacity, with phishing leading the volume charts and ransomware crews exploiting the gap.

FortiBleed Campaign Hits 86,644 FortiGate Boxes; CISA Pushes Customers to Lock Down
Russian-speaking operators are working through internet-exposed Fortinet appliances at scale. CISA wants admins moving now.

The Popa Botnet: When Your $40 Streaming Box Moonlights as a Residential Proxy
Researchers tie a four-year-old Android TV box botnet to NetNut, the residential proxy arm of NASDAQ-listed Alarum Technologies. The company disputes the framing.

Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks: A Week the Internet Worked As Designed
Shady extensions, weaponised Claude conversations, fileless macOS intrusions and cloud agents turned into shells dominated the criminal feeds this week.

Windows Clipper Worm Phones Home Over Tor, Swaps Crypto Wallets via ActiveX
Microsoft says the campaign, active since February, uses USB-borne LNK files and Windows Script Host to drop a bundled Tor proxy that talks to a .onion C2.

ClickFix Campaign Turns Google Ads, GitLab, and Claude Into a Six-Wave Trust Machine
Attackers chained legitimate infrastructure across seven weeks to push malicious PowerShell commands to developers. Session tokens, SSH keys, and cloud credentials were the prize.

Fortibleed: How 75,000 FortiGate Firewalls Ended Up on an Attacker's Credential List
Configuration files. Legacy SHA-256 hashes. Automation at scale. The Fortibleed campaign is a slow-burn credential harvest that perimeter defenders are still catching up to.

Clipper Crew Buys Sponsored Posts on News Sites to Push Trojanized Crypto Tools
An untracked actor is laundering credibility through paid press placements, a phishing-grade WordPress hub, and seeded GitHub and SourceForge repos to deliver clipboard hijackers.

Three New Loaders Ride the ClickFix Wave: BabaDeda, Lorem Ipsum, and Potemkin
Separate research teams have pinned three distinct loader families on the same social-engineering pattern, with education and finance taking the brunt of the April 2026 activity.

Rokarolla Android Trojan Hits 217 Banking and Crypto Apps
Researchers at Zimperium's zLabs catalogued 137 remote commands in the new malware, including PIN capture and clipboard hijacking against crypto wallets.

UNC6508 Spent a Year Inside US and Canadian Research Networks via Trojanized REDCap
A China-linked espionage group hijacked REDCap's own upgrade process to plant persistent malware across academic, medical, and defense-adjacent research environments.