Threat Intelligence — Page 25

Phantom Squatting: When Attackers Camp on the Domains LLMs Hallucinate
Unit 42 documents a pre-positioning tactic where actors register non-existent domains that chatbots keep suggesting, then wait for the traffic to arrive.

ClickFix Grows a Back Office: API-Served Payloads and a New AMSI Bypass
Researchers pulled roughly 3,000 live payloads from ClickFix infrastructure and found a polymorphic delivery pipeline built to defeat Windows script scanning.

RustDuck: A Rust-Based DDoS Botnet Quietly Building Out Since February
XLab researchers say the two-stage loader is iterating faster than its install base is growing — and that's the interesting part.

Silent Swap: Unsigned Installers Drop Fake Chromium Extensions That Hijack Crypto Transactions
McAfee Labs documents a clipper campaign using .NET and Golang loaders to sideload a malicious browser extension that rewrites wallet addresses at send time.

BEC Isn't an Email Problem. It's a Supply Chain.
Underground forums show Business Email Compromise as a multi-stage operation — account access, target research, and mules — not a clever phishing lure.

FIFA 2026 Fraud Infrastructure Was Pre-Staged Months Before Kickoff, Researchers Say
A Check Point exposure report documents pre-positioned phishing kits, lookalike domains and multilingual scam pages built well ahead of the June 11 opening match.

From Modded Game Controllers to IBM X-Force Red: The Chris Thompson Arc
A teenage hardware tinkerer grows up to run one of the most recognizable offensive-security brands in enterprise tech — then leaves to build something new.

Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke
Microsoft researchers flagged a counterfeit Perplexity Chrome extension that piped queries and omnibox input to an attacker server before completing the search.

Mustang Panda Turns Zoho WorkDrive Into C2 in Twin Campaigns Against Indian Government
The China-aligned crew is running parallel operations against New Delhi ministries and hydropower operators, abusing a legitimate cloud collaboration service to move commands past network defenses.

Monday Brief: A DirtyClone Linux Bug, Turla's New Backdoor, and the Infostealer Churn
Old access paths, missed patches, and a fresh kernel flaw kept defenders busy. A roundup of what moved this week in the cybercrime ecosystem.

236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App
Infoblox researchers tie a sprawling fake-exchange and wallet-drainer ecosystem to a legitimate Chinese cross-platform dev framework.

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft
The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

Harvest Now, Decrypt Later: Why Credentials Are the First Casualty of Q-Day
Captured ciphertext today becomes plaintext tomorrow. Credentials sit at the top of the target list.

Microsoft Pulls 119 Edge Extensions Tied to 'StegoAd' Steganography Campaign
The add-ons concealed payloads in image and font files and activated days after install. Microsoft attributes the activity to a single actor operating since 2021.

Supply-Chain Attackers Hide Python Stealer in npm and Go Packages, Sidestep Lifecycle Scripts
JFrog flags two hijacked npm packages and a Go cluster that abuse VS Code tasks to drop a cross-platform infostealer — bypassing the script hooks defenders typically watch.