Threat Intelligence — Page 14

Anonymized Infrastructure Now Touches 94% of Incidents, and Most SOCs Are Still Playing Catch-Up
Survey data points to a persistent gap between IP enrichment volume and the analyst's ability to answer a simple question: who's actually on the other end?

SprySOCKS Crosses Over: Windows Variants Surface With Driver-Level Hiding
Two undocumented Windows builds of the China-linked backdoor — tagged WIN_DRV and WIN_PLUS — extend a toolset previously seen only on Linux.

ScarCruft Dresses Up NarwhalRAT in a Microsoft Account Security Alert
APT37's spear-phish leans on the oldest trick in the identity playbook: tell the user their account is at risk, then hand them the payload.

China-Nexus Crew Burrowed Into REDCap, Turned Google Workspace Rules Into an Exfil Pipe
A 13-plus-month intrusion across medical, academic, and defense research networks abused victim-side mail forwarding instead of dropping noisy C2.

Contagious Interview Pivots to Dev-Review Lures in Two Fresh Campaigns
The North Korea-linked cluster is back with phishing pretexts aimed at developers — recruiter pitches and code-review requests that drop malware on engineers' workstations.

Trusted Plugin Scripts Weaponized in Admin-Aware WordPress Supply-Chain Hit
Tampered JavaScript served from PushEngage, OptinMonster and TrustPulse fingerprinted logged-in admins before silently provisioning rogue accounts and a stealth plugin.

152 Chrome 'Wallpaper' Extensions Quietly Push Adware to 105K Browsers
A 38-account publisher cluster on the Chrome Web Store funnels new-tab traffic through three backends — and it looks a lot less like art and a lot more like an ad-fraud pipeline.

Threat Actor 'Misere' Claims Breach of French Government Messaging Platform Tchap
Around 73,000 sovereign-platform accounts may be compromised. Attribution remains unclear, and the actor is not yet tied to a known cluster.

FBI and Google Tear Down 'Outsider Enterprise' Phishing Platform Behind $1.9 Billion in Losses
Nine thousand phishing sites. Nearly four million stolen credit cards. One takedown.

Facebook Impersonation Scams Sweep MENA, Pushing Fake Subsidies and 'Free Data' Lures
Group-IB ties the campaign to a broader fraud network using cloned political figures, fake government programs and browser-push alerts to harvest credentials and payment data.

Outsider Enterprise: the phishing-as-a-service mill that wasn't really 'AI-powered'
FBI, Google and Black Lotus Labs took down a Chinese PhaaS operation running close to a million phishing URLs. The 'AI' part is doing a lot of heavy lifting.

Insider Threat, Low Sophistication: Ex-IT Staffer Gets 21 Months for Iowa School District Intrusions
No APT, no zero-day — just a disgruntled former admin with credentials that should have been revoked. The case is a textbook reminder that the highest-impact intrusions often start at HR offboarding.

AUR Supply-Chain Hit: 400+ Arch Packages Backdoored With Rust Stealer, Optional eBPF Rootkit
Build scripts in hijacked Arch User Repository packages dropped a credential harvester — and an eBPF rootkit when root was available.

Velvet Ant Lived Inside PAM and OpenSSH for Nearly Ten Years
A China-nexus crew skipped the endpoints defenders actually watch and backdoored the Linux login stack itself, where IR runbooks rarely reach.

Over 400 AUR Packages Backdoored With Rust-Based Credential Stealer
Attackers rewrote build scripts in Arch's community repo to drop a secret-harvesting binary — with an eBPF rootkit waiting if it gets root.