Threat Intelligence — Page 2

Chinese Sub-Crew 'CylindricalCanine' Fingered for DigiCert Break-In
Researchers link the April 2026 intrusion at the certificate giant to an offshoot of a Chinese cybercrime group best known for chasing gambling firms.

North Korean Job-Interview Scam Hides Malware Inside Flag Images
Fake coding tests planted a four-stage stealer on developers' machines, with the payload smuggled inside SVG picture files.

Ransomware Hits Naval Contractor, Lidl Discloses Data Breach, and Iran Tracks US Military Phones
A week of scattered but serious disclosures: a defence shipbuilder confirms a ransomware attack, a major supermarket chain notifies customers of stolen data, and new evidence suggests Iranian operatives tracked phones belonging to US military personnel.

Why Carders Are Hunting for 'Clean' Home Internet Connections
Fraudsters are paying premium prices for residential proxies that haven't been flagged, and pairing them with fake browser identities to slip past bank fraud checks.

GoSerpent: A New Espionage Tool Quietly Targeting Southeast Asian Governments
Kaspersky says the previously unseen malware has been hitting government and diplomatic offices across the region since late 2025, with signs pointing to long-term spying rather than smash-and-grab theft.

ACR Stealer Tricks Staff Into Typing the Attack Themselves
Microsoft says a fake-fix trick is pushing a data thief onto business PCs, walking off with passwords, session cookies and cloud files.

Malware Disguised as Font Files Targets Windows Users
A global phishing campaign uses fake font files to deploy credential-stealing malware.

New York Duo Charged With Laundering $43 Million From 'Pig Butchering' Investment Scams
Federal prosecutors say Zhuoying Chen and Haojie Zhang ran a 45-shell-company money mule network that moved victim funds from Queens and Brooklyn bank accounts to China.

Russian Spies Are Testing Australia's Unlocked Doors
Australia's top signals agency has joined two dozen allied governments to warn that hackers working for Russian intelligence are quietly breaking into poorly secured network devices across critical industries worldwide.

Fake QR code stickers on Christchurch parking meters are stealing payments
Scammers placed fraudulent stickers over real payment instructions to redirect drivers to copycat websites. The Christchurch City Council is urging residents not to scan any QR code found on a parking machine.

ClickLock: the Mac malware that locks up your screen until you type your password
A new macOS stealer, tracked by Group-IB, freezes everything on the screen except a password box. It has already hit around 100 machines in 33 countries.

Two Scattered Spider hackers get 5.5 years each for crippling London's transport network
Thalha Jubair and Owen Flowers pleaded guilty to the August 2024 attack on Transport for London, which cost the agency £29 million and briefly threatened chaos for 8.4 million passengers.

This Week's Cyber Mess: Fake Repos, Chrome Sync Stalking and a Ransomware Crew That Moves in a Day
A roundup of the week's smaller stories that share one uncomfortable theme: attacks that succeed because something looked close enough to trust.

ClickLock: The Mac Stealer That Won't Let You Work Until You Hand Over Your Password
A new macOS malware kills your apps in a loop every 210 milliseconds, holding your machine hostage until you type in your login password.

TELEPUZ: The New Malware Hiding Behind Fake 'Fix This' Website Pop-ups
A modular info-stealer is spreading through booby-trapped websites that trick visitors into pasting malicious commands into their own computers.