Threat Intelligence — Page 3

TELEPUZ: The New Malware Hiding Behind Fake 'Fix This' Website Pop-ups
A modular info-stealer is spreading through booby-trapped websites that trick visitors into pasting malicious commands into their own computers.

Two Scattered Spider Members Jailed in UK's Largest Ever Cybercrime Prosecution
Thalha Jubair and Owen Flowers each received five and a half years in prison for a 2024 attack on Transport for London that cost the city £29 million.

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords
A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.

China-Linked 'Daxin' Rootkit Returns After Four Years, Found Inside Taiwan Factory
The stealthy kernel malware, last documented in 2022, showed up alongside a new backdoor called Stupig on a manufacturer's network.

Brazilian Government Sites Turned Into Malware Traps in PhantomEnigma Campaign
Attackers quietly took over more than 20 official .gov.br domains and used them to push a stealthy backdoor, according to new analysis from ANY.RUN.

Russian Crew Hides Starland Backdoor Inside Fake Zoom and WebEx Installers
UAT-11795 is spiking popular software downloads with a credential-and-crypto stealer, and US users are the main target.

How a Spanish Cybercrime Gang Stole €140 Million and Almost Got Away With It
Spanish police, working with partners across Europe and beyond, dismantled a fraud network that used fake boss emails, phony investment sites, and nearly a thousand bank accounts to steal the equivalent of $161 million from ordinary people and businesses.

A Botnet Author Asked an AI for Malware. The AI Left the Warning Label On.
Researchers found TuxBot v3 Evolution, a new IoT botnet whose creator appears to have copy-pasted AI-generated code, safety disclaimer and all.

OkoBot Malware Hijacks Ledger and Trezor Apps to Steal Crypto Recovery Phrases
A Windows malware framework active since April 2025 waits for victims to open their hardware wallet software, then fakes a prompt for the 24 words that unlock everything.

Trojanised AsyncAPI packages slip onto npm, hitting a library downloaded 2.25 million times a week
Attackers hijacked a GitHub build pipeline on 14 July to publish five poisoned versions of AsyncAPI tools, wiring in a stealthy info-stealer that talks to its operators over Ethereum and peer-to-peer networks.

US Charges Three Russians for Running 'Bulletproof' Hosting That Powered Ransomware and Phishing Attacks on 42 American Organisations
A grand jury indictment unsealed this week names Aleksandr Volosovik, Kirill Zatolokin, and Yulia Pankova as the operators behind two companies that rented out hidden, hard-to-shut-down internet infrastructure to criminals worldwide.

When 80,000 fans log on at once: the cybersecurity headache facing 2026 World Cup stadiums
Tens of thousands of personal phones on one network, payment terminals, body cameras on referees, and sensors inside match balls. Stadium IT teams face a security puzzle that has no clean solution.

Hijacked AsyncAPI npm Packages Slipped a Botnet Loader Into Developer Machines
Four packages under the popular @asyncapi namespace were tampered with to deliver a multi-stage malware loader, in the latest reminder that the open-source supply chain is a soft target.

EU, UK and France Sanction Russia Over Coordinated Hacking and Sabotage Campaign Across Europe
France summoned Russia's ambassador on Monday after European governments accused the FSB, Russia's main intelligence service, of running a campaign to spy on and disrupt critical infrastructure across more than a dozen countries.

Spanish police dismantle €140 million fraud ring that drained company bank accounts
Four arrests across Spain, Portugal and Panama close down a laundering network that pushed nearly €100 million through 800 bank accounts, much of it stolen through fake CEO emails.