Threat Intelligence — Page 29

Threat Intelligence

FBI and Google Tear Down 'Outsider Enterprise' Phishing Platform Behind $1.9 Billion in Losses

Nine thousand phishing sites. Nearly four million stolen credit cards. One takedown.

2 min read
Threat Intelligence

Facebook Impersonation Scams Sweep MENA, Pushing Fake Subsidies and 'Free Data' Lures

Group-IB ties the campaign to a broader fraud network using cloned political figures, fake government programs and browser-push alerts to harvest credentials and payment data.

2 min read
Threat Intelligence

Outsider Enterprise: the phishing-as-a-service mill that wasn't really 'AI-powered'

FBI, Google and Black Lotus Labs took down a Chinese PhaaS operation running close to a million phishing URLs. The 'AI' part is doing a lot of heavy lifting.

2 min read
Threat Intelligence

Insider Threat, Low Sophistication: Ex-IT Staffer Gets 21 Months for Iowa School District Intrusions

No APT, no zero-day — just a disgruntled former admin with credentials that should have been revoked. The case is a textbook reminder that the highest-impact intrusions often start at HR offboarding.

2 min read
Threat Intelligence

AUR Supply-Chain Hit: 400+ Arch Packages Backdoored With Rust Stealer, Optional eBPF Rootkit

Build scripts in hijacked Arch User Repository packages dropped a credential harvester — and an eBPF rootkit when root was available.

2 min read
Threat Intelligence

Velvet Ant Lived Inside PAM and OpenSSH for Nearly Ten Years

A China-nexus crew skipped the endpoints defenders actually watch and backdoored the Linux login stack itself, where IR runbooks rarely reach.

3 min read
Threat Intelligence

Over 400 AUR Packages Backdoored With Rust-Based Credential Stealer

Attackers rewrote build scripts in Arch's community repo to drop a secret-harvesting binary — with an eBPF rootkit waiting if it gets root.

2 min read
Threat Intelligence

Week in Brief: Google Security Cuts, AudiA6 Forum Axed, Coupang's $400M Fine

ICS exposure holds flat while the attack surface grows, IBM and AT&T face hack cover-up allegations, and Microsoft quietly drops an AI incident-response playbook.

2 min read
Threat Intelligence

Sniper Dz Phishing-as-a-Service Goes Dark After INTERPOL Sweep Nets 201 Arrests

Operation Ramz dismantled a decade-old PhaaS storefront and pulled in its alleged operator, 'Guedz', across 13 MENA jurisdictions.

2 min read
Threat Intelligence

AudiA6 Crypto Laundromat Pulled Offline After Washing €336M for Ransomware Crews

Europol says the takedown severs a major cash-out pipeline tied to ransomware payouts and underground markets.

3 min read
Threat Intelligence

ShinyHunters Hit Universities Through PeopleSoft Zero-Day Before Oracle Patch

Mandiant ties a two-week extortion spree against Oracle PeopleSoft deployments to UNC6240, the cluster better known as ShinyHunters.

2 min read
Threat Intelligence

The Cybercrime Economy Is Looking a Lot Like SaaS

A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents coughing up credentials — the criminal stack is industrialising.

3 min read
Threat Intelligence

OnyxC2 Stealer: $250/Month Buys You Encrypted Payloads and 200+ App Targets

A commodity infostealer is punching well above its price point. OnyxC2 brings DLL sideloading and in-memory execution to anyone with a credit card.

2 min read
Threat Intelligence

FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel

The seized domains posed as consulting firms advertising jobs — a tradecraft pattern consistent with state-directed recruitment campaigns against intelligence community insiders.

2 min read
Threat Intelligence

OceanLotus Turns SPECTRALVIPER on Vietnamese Investors and a Construction Firm

Two campaigns, one toolset. The Vietnam-aligned crew spent eighteen months inside a state-linked infrastructure builder before pivoting to a supply chain hit on retail stock investors.

3 min read
© 2026 Threat Vectr