Threat Intelligence — Page 31

npm Hit by Dual Supply-Chain Campaigns: Rust Stealer With eBPF Rootkit, Self-Spreading Worm
Researchers flagged two parallel intrusions into the npm registry. One delivers a kernel-level credential scraper. The other propagates through more than 50 poisoned packages.

Asin Android Spyware Surfaces in Arabic-Language Lures, ESET Says
ESET ties early-2025 campaigns to decoy sites posing as utilities, war-tracking tools and a fake government news portal.

OP-512 Cluster Hits IIS Servers With Custom Web Shell Kit, Researchers Link Activity to China
A previously unreported intrusion set is dropping a bespoke web shell framework on Microsoft IIS servers, with espionage indicators pointing toward Beijing.

Five Eyes Warns: Chinese Intelligence Officers Posing as Recruiters to Harvest Government Secrets
A joint advisory flags a persistent social engineering campaign targeting personnel with access to classified material — fake job offers, real espionage.

World Cup 2026 Phishing Infrastructure Is Already Stood Up
Lookalike FIFA domains, trojanized streaming apps, and credential harvesters are live weeks before kickoff. The pattern is familiar; the scale isn't.

TA4922 Broadens Phishing Sweep Into U.K., Germany, Italy and South Africa
The China-linked crew is rotating through ValleyRAT, Atlas RAT and freshly minted payloads at a pace researchers describe as unusually fast.

The Week the Tape Came Off: Old Bugs, Cheap C2, and AI That Breaks Things
A roundup of the criminal-economy churn driving this week's intrusions, from plugin holes to agentic AI gone feral.

FlutterShell: A macOS Backdoor Wrapped in Flutter, Dropped by Ad Clicks
Unit 42 traces a malvertising operation to the same crew behind JSCoreRunner, this time hiding a backdoor inside Flutter-built Mac apps.

TA4922 Broadens European Targeting With ValleyRAT, Atlas RAT Loadouts
A China-nexus cluster tracked as TA4922 is hitting orgs in the UK, Germany, Italy, and South Africa, mixing known RATs with newer tooling.

Five-Month Outlook Intrusion at Global Stock Exchange Exfiltrated via Dropbox, OneDrive
Threat hunters say the executive's mailbox was siphoned in small batches over consumer cloud channels — a pattern consistent with state-aligned espionage rather than financially motivated crime.

Disruption Week: Feds Yank Millions of Accounts in Crypto Fraud Sweep, Seize $3.8M
DOJ-led action against Southeast Asia 'pig butchering' rings hit infrastructure, not just wallets. The interesting question is what the platforms knew, and when.

DesckVB RAT Campaign Routes Phishing Lures Through Google's DoubleClick Domain
Attackers are bouncing victims off a Google-owned ad redirect before landing them on attacker infrastructure — a trick that buys cover from filters trained to trust doubleclick.net.

Feds Sound Alarm on Exposed Fuel Tank Gauges as Hackers Probe Critical Infrastructure
CISA, FBI, NSA and DOE say internet-facing ATG systems at fuel depots, hospitals and military sites are being scanned and hit. The fix is mostly operator hygiene.

Weedhack MaaS Hijacks Minecraft Players Through YouTube Lures
A malware-as-a-service operation impersonating Minecraft clients and mods has compromised thousands of systems since January, with YouTube tutorials serving as the primary funnel.

Gamaredon Keeps Riding the WinRAR Path-Traversal Bug Into Ukrainian Endpoints
CVE-2025-8088 is months old and patched. The Russian crew is still landing GammaPhish, GammaWorm, and GammaSteel with it.