Threat Intelligence — Page 24

US warns Russian spies are still hunting your WhatsApp and Signal accounts
CISA and the FBI say Russian intelligence officers are running fresh phishing campaigns to hijack accounts on messaging apps used by journalists, officials and activists.

TA558 Is Back, Targeting Hotels and Airlines With Fake Booking Emails
A criminal group that has quietly stolen travel-industry data since 2018 has dramatically ramped up its fake-reservation campaigns, now using compressed file tricks to sneak spying software onto victims' computers.

Alleged Scattered Spider member, 19, extradited to the US after airport arrest
Peter Stokes, a dual US-Estonian citizen picked up in Helsinki in April, is accused of helping the notorious hacking crew squeeze millions from big-name companies.

Opera's new Paste Protect tries to stop the copy-paste scam that's been draining wallets
The browser will now block dodgy commands before they reach your clipboard, targeting the ClickFix trick that has become criminals' favourite way to trick people into infecting their own computers.

FBI Dismantles NetNut Proxy and Popa Botnet Operations
The FBI seizes key domains of NetNut, disrupting a sprawling proxy service linked to cybercriminal activities.

Google and FBI Kneecap NetNut, Cutting Millions of Home Devices From Proxy Pool
Google's Threat Intelligence Group says a joint operation with the FBI and Lumen has stripped millions of infected home devices from NetNut, also tracked as Popa.

The USB Drop That Changed Pen Testing: Steve Stasiukonis's Credit Union Experiment, Revisited
Twenty years ago, a handful of booby-trapped thumb drives in a parking lot became one of the most-cited social-engineering case studies in security history. Here's what actually happened.

Small Gaps, Big Consequences: The Week's Breaches Ran on Trust, Not Zero-Days
Browsers, bots, AI sandboxes and email flows all failed the same way — quietly, and inside the rules.

ToddyCat's New Umbrij Malware Pulls Gmail Straight From Google's API
Kaspersky ties the China-nexus crew to a Gmail-siphoning tool that skips the browser and talks to Google directly.

ChocoPoC: The Fake Exploit Repos Turning Bug Hunters Into Victims
A Python-based infostealer is hiding inside GitHub proof-of-concept code marketed to vulnerability researchers, siphoning credentials, cookies, and files before dropping a remote shell.

ChocoPoC RAT Hides in Fake GitHub Exploits, Targets Security Researchers
A cluster of trojanized proof-of-concept repositories is pushing a Python-based RAT to the very people who go looking for them.

Scattered Spider Suspect, 19, Extradited From Finland to Chicago
Peter Stokes, a dual U.S.-Estonian citizen, faces conspiracy, intrusion and fraud charges tied to the loose-knit crew behind a string of high-profile enterprise breaches.

ScreenConnect Turned Loader: Trojanized Installers Push AsyncRAT via Spoofed Software Sites
A sprawling campaign is abusing a legitimate RMM binary to sideload AsyncRAT onto victims chasing free copies of OBS Studio, Bandicam, and other utilities.

VEIL#DROP: Blogger-Hosted Chain Drops PureLogs Stealer
Researchers flag a multi-stage delivery scheme abusing Google's Blogger platform to stage PureLogs, an infostealer sold in underground forums.

Ousaban Resurfaces in Iberia, Hiding Bank-Stealer Payloads Inside Images
A Brazilian trojan pivots to Spanish and Portuguese banking customers, using geofenced PDF lures and steganography to bury its real payload.