Threat Intelligence — Page 18

Russian Crew Hides Starland Backdoor Inside Fake Zoom and WebEx Installers
UAT-11795 is spiking popular software downloads with a credential-and-crypto stealer, and US users are the main target.

How a Spanish Cybercrime Gang Stole €140 Million and Almost Got Away With It
Spanish police, working with partners across Europe and beyond, dismantled a fraud network that used fake boss emails, phony investment sites, and nearly a thousand bank accounts to steal the equivalent of $161 million from ordinary people and businesses.

A Botnet Author Asked an AI for Malware. The AI Left the Warning Label On.
Researchers found TuxBot v3 Evolution, a new IoT botnet whose creator appears to have copy-pasted AI-generated code, safety disclaimer and all.

OkoBot Malware Hijacks Ledger and Trezor Apps to Steal Crypto Recovery Phrases
A Windows malware framework active since April 2025 waits for victims to open their hardware wallet software, then fakes a prompt for the 24 words that unlock everything.

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week
Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

US Charges Three Russians for Running 'Bulletproof' Hosting That Powered Ransomware and Phishing Attacks on 42 American Organisations
A grand jury indictment unsealed this week names Aleksandr Volosovik, Kirill Zatolokin, and Yulia Pankova as the operators behind two companies that rented out hidden, hard-to-shut-down internet infrastructure to criminals worldwide.

When 80,000 fans log on at once: the cybersecurity headache facing 2026 World Cup stadiums
Tens of thousands of personal phones on one network, payment terminals, body cameras on referees, and sensors inside match balls. Stadium IT teams face a security puzzle that has no clean solution.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

EU, UK and France Sanction Russia Over Coordinated Hacking and Sabotage Campaign Across Europe
France summoned Russia's ambassador on Monday after European governments accused the FSB, Russia's main intelligence service, of running a campaign to spy on and disrupt critical infrastructure across more than a dozen countries.

Spanish police dismantle €140 million fraud ring that drained company bank accounts
Four arrests across Spain, Portugal and Panama close down a laundering network that pushed nearly €100 million through 800 bank accounts, much of it stolen through fake CEO emails.

Fake GitHub Pages Impersonate 292 Real Brands to Push Password-Stealing Malware
A Russian-speaking crew built hundreds of lookalike project pages for security tools, wallets and dev software. One click on 'Download Secure Content' handed over browser passwords, crypto wallets and chat sessions.

Ransomware Gang Claims Bosch and Synopsys Hacks. Synopsys Says It Sees Nothing.
A criminal group called D1R says it stole sensitive data from two major companies and will publish it unless it gets paid. One of those companies is pushing back.

LabubaRAT: New Rust Malware Poses as NVIDIA Software to Sneak Onto Windows PCs
Researchers at Blackpoint Cyber say the newly named tool gives attackers a quiet, reusable way back into infected machines.

ClickFix: The Fake Error Pop-Up That Tricks You Into Hacking Yourself
A scam that launched in 2024 has grown into a thriving criminal marketplace. Researchers say standard antivirus tools are missing it almost entirely, and they have built a new detection method to fill the gap.

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon
Researchers at JFrog say 148 malicious packages used the npm registry as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into a two-week attack campaign in May.