Threat Intelligence — Page 27

Mistic Backdoor Shows Up in IAB-Brokered Intrusions Across Four Verticals
A quiet new implant tied to the KongTuke access broker is landing on insurance, education, IT, and professional services networks — and it's not riding a CVE to get there.

Mistic Backdoor Ties to IAB Selling Enterprise Footholds to Ransomware Gangs
A new in-memory backdoor named Mistic has been active since April, and the threat actor behind it has reportedly funneled access to Qilin, Akira, Black Basta, and others.

Operation Endgame Hits Amadey and StealC, Pulls 27M Credentials From Loader Infrastructure
Europol-led takedown dismantled command servers behind two of the most prolific malware-as-a-service loaders, with Microsoft, ESET, Bitdefender, and Bitsight providing technical support.

Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC
Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.

FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest
Researchers attribute the long-running operation to a financially motivated IAB, with credential lists feeding brute-force runs against exposed FortiGate appliances since February.

Three npm Packages Squat PostCSS Names to Drop a Windows RAT
Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

WhatsApp DMs Push VBScript Loaders That Deploy Legitimate RMM Tools
An active campaign abuses WhatsApp Desktop and Web to distribute scripted droppers that install commercial remote-management software across at least ten jurisdictions.

ShapedPlugin's Update Channel Hijacked, Pro Plugins Shipped with Backdoor
Attackers slipped malicious code into licensed Pro releases by compromising the vendor's own build pipeline — a clean supply-chain hit on WordPress installs.

The 'Search-as-a-Service' Economy Built on Stolen Credentials
Underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews alike.

OXLOADER Drops CastleStealer via Poisoned Google Ads, Researchers Say
Elastic Security Labs links the malvertising chain to a likely Russian-speaking, financially motivated operator.

Weekly Threat Roundup: EDR Killers, Browser Bugs, and an Android Trojan With Too Many Hands
Another week of recycled tradecraft — abused integrations, poisoned WordPress, and ransomware crews still gunning for endpoint sensors.

ShinyHunters Doesn't Need Malware. That's the Point.
The group's latest breaches are a reminder that stolen credentials and patience beat zero-days most days of the week.

AryStinger Quietly Conscripts 4,300 Old Routers Into a Recon Proxy Fabric
Researchers say the malware skips the usual DDoS playbook and instead builds infrastructure for pre-breach reconnaissance.

INTERPOL Flags Sharp Rise in Phishing, Ransomware and AI Scams Across Asia-Pacific
A new INTERPOL assessment maps a region where cybercrime is outpacing defensive capacity, with phishing leading the volume charts and ransomware crews exploiting the gap.

FortiBleed Campaign Hits 86,644 FortiGate Boxes; CISA Pushes Customers to Lock Down
Russian-speaking operators are working through internet-exposed Fortinet appliances at scale. CISA wants admins moving now.