Threat Intelligence — Page 32

SideCopy Hits Afghan Finance Ministry With Xeno RAT in Pashto-Lure Phish
A new spear-phishing run tracked to the Pakistan-aligned cluster pairs LNK-laced ZIPs with an open-source RAT, in what looks like a continuation of the group's South and Central Asia espionage focus.

Dutch Police Take Down C2 Infrastructure Behind 17-Million-Device Botnet
Authorities in the Netherlands seized command-and-control servers powering a botnet spanning infected computers, phones, and tablets — infrastructure allegedly rented out as a residential proxy network for criminal operations.

Operation Dragon Weave Drops AdaptixC2 on Czech, Taiwanese Targets
Spear-phishing campaign hits government, academia, and finance with ZIP-borne lures and an open-source C2 framework.

Dragos Buys Phosphorus to Close the xIoT Visibility Gap
The OT security firm absorbs an extended-IoT specialist, promising customers a unified platform that can actually see—and fix—the devices most asset inventories quietly ignore.

Malicious npm Package codexui-android Pulls 29K Weekly Downloads, Targets OpenAI Codex Tokens
A package posing as a remote web UI for OpenAI Codex is harvesting developer credentials. It's still live on npm and GitHub.

Dutch Police Pull the Plug on 17-Million-Device Botnet Run Through 200+ NL Servers
Politie and NCSC seized command infrastructure hosted on Dutch soil, dismantling a network that pulled in PCs, phones, tablets and IoT gear at scale.

Russia's Tech Embargo Run-Around: Shell Companies, Middlemen, and Embedded Spies
Western sanctions were supposed to starve Moscow's military-industrial base of critical components. Instead, Russian intelligence built a procurement machine to go get them anyway.

GREYVIBE: New Russian-Speaking Cluster Tied to Sustained Operations Against Ukraine
Researchers attribute an August 2025 campaign wave to a previously undocumented actor whose tasking patterns align with Kremlin interests.

GlassWorm Is Down. The Repository Problem Isn't.
CrowdStrike, Google, and Shadowserver severed four C2 channels simultaneously. Meanwhile, 157 OSV false positives quietly eroded trust in the tools defenders depend on.

FBI Flags Silent Ransom Group's Physical Intrusion Tactic Against U.S. Law Firms
The threat actor known as Silent Ransom Group has added walk-in impersonation to its toolkit, sending actors posing as IT support into law firm offices to insert storage devices into employee computers.

Three Stories You Probably Missed: Trump Mobile Leak, FIFA Phishing, and CISA's Supply Chain Cleanup
A customer data exposure, a tournament-themed phishing campaign, and a federal agency scrambling to respond to upstream compromise — a busy week for the incidents no one headlined.

LLM Agent Spotted Driving Post-Exploitation After Marimo Notebook Compromise
An unattributed intrusion set chained CVE-2026-39987 against an exposed Marimo notebook, then handed the keyboard to a language model.

DDoS-as-a-Service Grows Up: Tiered Pricing, Reseller Programs, Real Support Tickets
The booter market has shed its script-kiddie aesthetic. Today's stresser panels look like SaaS — because operationally, they are.

GREYVIBE: The Russian-Speaking Threat Actor Targeting Ukraine
Persistent attacks align with Kremlin interests, spotlighting continuous geopolitical cyber warfare.

Typosquatted NuGet 'Sicoob.Sdk' Hoovers PFX Certs From Brazilian Banks
A poisoned package impersonating Brazil's Sicoob co-op banking network exfiltrates client IDs and PFX certificates — the same certs that sign API calls into the financial system.