Threat Intelligence — Page 23

TrojPix: Academic Research Shows Air-Gapped PCs Can Leak Data Through Screen Pixels
Researchers at Shandong University describe a covert channel that turns a monitor cable into a radio transmitter, but the technique still needs malware on the target first.

QuimaRAT: A New Rent-a-Malware Kit That Hits Windows, Mac and Linux
Researchers at LevelBlue say the Java-based remote access tool is being sold as a subscription, starting at $150 a month, and works across all three major desktop systems.

North Korean hackers flood open-source repositories with 108 booby-trapped packages
The Contagious Interview crew is back, seeding npm, Packagist, Go and Chrome with malware aimed at developers.

Google and FBI cut off NetNut, a two-million-device botnet hidden inside smart TVs
The residential proxy service let hundreds of criminal and spy groups route attacks through ordinary homes.

Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

Three Quick Hits: Canadian Hacker Jailed, Open-Source Flaws Dropped, ATM Jackpotters Sentenced
A week's worth of security stories that deserve a second look — from an Anonymous-linked arrest in Canada to cash-machine criminals facing US prison time.

Armored Likho: the newly-named hacking crew hitting power grids and government offices
Russian security firm Kaspersky says the group mixes espionage against big institutions with money-driven attacks on ordinary people.

A Spyware Investigator Got Spied On: Pegasus Hit an EU Lawmaker Probing Pegasus
Forensic analysis of Stelios Kouloglou's phone shows repeated Pegasus infections while he sat on the European Parliament's own spyware inquiry.

PamStealer: Fake Maccy App Hides Mac Password-Grabbing Script
Researchers say the AppleScript malware poses as a popular clipboard tool, tricks users into typing their Mac password, then quietly ships browser data and crypto wallets to its operators.

Google and FBI Shut Down NetNut, a Criminal Anonymity Network Built on Millions of Hijacked Home Devices
NetNut rented out access to infected home and business routers so criminals and foreign spies could hide their tracks. A joint operation has disrupted it.

Iran, Russia, and China Have Been Quietly Attacking Water Systems — and the Door Was Usually Left Unlocked
A new threat-intelligence report finds three governments targeting water and wastewater infrastructure, not primarily to poison anyone, but to cause fear, probe weaknesses, and pre-position for future conflict. The tools they're using are embarrassingly basic.

Chinese Cyber Group Targets Southeast Asian Utilities with New Backdoor
Critical infrastructure providers in Southeast Asia are facing targeted cyber intrusions from a China-linked group using a novel backdoor tool.

Fake Guest Photos Are Handing Hackers Long-Term Access to Hotel Networks
Two separate campaigns are targeting hotel front desks and booking teams with booby-trapped zip files dressed up as guest photographs — and the goal isn't a quick smash-and-grab. It's a quiet, lasting foothold.

Before the Crowds Arrive: Why Event Security Has to Start Online
From the FIFA World Cup to America's 250th birthday celebrations, the biggest gatherings of 2025 face threats that begin weeks before the first ticket is scanned — and most of those early warning signs appear on the internet, not at the gate.

ClickFix: Emerging Favorite for Cybercriminals in Malware Delivery
New research highlights how ClickFix, a social engineering tactic, is dominating the malware delivery landscape across various systems.