Threat Intelligence — Page 17

FlutterShell: A macOS Backdoor Wrapped in Flutter, Dropped by Ad Clicks
Unit 42 traces a malvertising operation to the same crew behind JSCoreRunner, this time hiding a backdoor inside Flutter-built Mac apps.

TA4922 Broadens European Targeting With ValleyRAT, Atlas RAT Loadouts
A China-nexus cluster tracked as TA4922 is hitting orgs in the UK, Germany, Italy, and South Africa, mixing known RATs with newer tooling.

Five-Month Outlook Intrusion at Global Stock Exchange Exfiltrated via Dropbox, OneDrive
Threat hunters say the executive's mailbox was siphoned in small batches over consumer cloud channels — a pattern consistent with state-aligned espionage rather than financially motivated crime.

Disruption Week: Feds Yank Millions of Accounts in Crypto Fraud Sweep, Seize $3.8M
DOJ-led action against Southeast Asia 'pig butchering' rings hit infrastructure, not just wallets. The interesting question is what the platforms knew, and when.

DesckVB RAT Campaign Routes Phishing Lures Through Google's DoubleClick Domain
Attackers are bouncing victims off a Google-owned ad redirect before landing them on attacker infrastructure — a trick that buys cover from filters trained to trust doubleclick.net.

Feds Sound Alarm on Exposed Fuel Tank Gauges as Hackers Probe Critical Infrastructure
CISA, FBI, NSA and DOE say internet-facing ATG systems at fuel depots, hospitals and military sites are being scanned and hit. The fix is mostly operator hygiene.

Weedhack MaaS Hijacks Minecraft Players Through YouTube Lures
A malware-as-a-service operation impersonating Minecraft clients and mods has compromised thousands of systems since January, with YouTube tutorials serving as the primary funnel.

Gamaredon Keeps Riding the WinRAR Path-Traversal Bug Into Ukrainian Endpoints
CVE-2025-8088 is months old and patched. The Russian crew is still landing GammaPhish, GammaWorm, and GammaSteel with it.

SideCopy Hits Afghan Finance Ministry With Xeno RAT in Pashto-Lure Phish
A new spear-phishing run tracked to the Pakistan-aligned cluster pairs LNK-laced ZIPs with an open-source RAT, in what looks like a continuation of the group's South and Central Asia espionage focus.

Dutch Police Take Down C2 Infrastructure Behind 17-Million-Device Botnet
Authorities in the Netherlands seized command-and-control servers powering a botnet spanning infected computers, phones, and tablets — infrastructure allegedly rented out as a residential proxy network for criminal operations.

Operation Dragon Weave Drops AdaptixC2 on Czech, Taiwanese Targets
Spear-phishing campaign hits government, academia, and finance with ZIP-borne lures and an open-source C2 framework.

Dragos Buys Phosphorus to Close the xIoT Visibility Gap
The OT security firm absorbs an extended-IoT specialist, promising customers a unified platform that can actually see—and fix—the devices most asset inventories quietly ignore.

Malicious npm Package codexui-android Pulls 29K Weekly Downloads, Targets OpenAI Codex Tokens
A package posing as a remote web UI for OpenAI Codex is harvesting developer credentials. It's still live on npm and GitHub.

Dutch Police Pull the Plug on 17-Million-Device Botnet Run Through 200+ NL Servers
Politie and NCSC seized command infrastructure hosted on Dutch soil, dismantling a network that pulled in PCs, phones, tablets and IoT gear at scale.

Russia's Tech Embargo Run-Around: Shell Companies, Middlemen, and Embedded Spies
Western sanctions were supposed to starve Moscow's military-industrial base of critical components. Instead, Russian intelligence built a procurement machine to go get them anyway.