Threat Intelligence — Page 34

CERT-UA Attributes Prometheus-Themed Phishing Run Against Ukrainian Government to Ghostwriter (UAC-0057)
Compromised mailboxes deliver lures impersonating a Ukrainian e-learning platform, with the Belarus-aligned operator tracked as UNC1151 named as the responsible cluster.

Laravel-Lang Packages Hijacked to Push a Cross-Platform Credential Stealer
Four popular Laravel-Lang packages were tagged with malicious releases that drop a credential-harvesting framework on Windows, macOS, and Linux.

Eight Packagist Projects Hijacked to Pull Linux Payload From GitHub Releases
The injected code lived in package.json, not composer.json, and targeted JavaScript-shipping Composer projects.

TrapDoor Campaign Plants Credential Stealers Across npm, PyPI, and Crates.io
A coordinated operation seeded 34+ malicious packages across three registries since May 2026. If you ship code, this one is sitting in your dependency tree right now.

GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers
Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.

The Boy Who Topped the Leaderboard: How 'Tylerb' Became a Cooperating Witness
Tyler Buchanan, the Scottish core of Scattered Spider's 2022 phishing spree, pleaded guilty in U.S. federal court. His path there ran through a blowtorch, a Barcelona departure gate, and a Telegram scoreboard.

The Firewall Guard Was Holding a Crowbar: Brazilian DDoS-Protection Firm Caught Powering the Attacks
Exposed archive ties Huge Networks infrastructure and its CEO's SSH keys to a long-running Mirai botnet hammering Brazilian ISPs. The CEO blames a competitor.

Ottawa 23-Year-Old Charged as 'Dort,' Alleged Operator of the 30 Tbps Kimwolf IoT Botnet
Jacob Butler is in OPP custody on a U.S. extradition warrant. Prosecutors say his botnet pushed nearly 30 terabits per second. The questions I sent his lawyer remain unanswered.

Lazarus' RemotePE Lives Entirely in Memory, Targets Crypto Treasuries
A fresh in-memory RAT from DPRK's Lazarus Group is being chained behind two custom loaders to drain finance and crypto orgs. Here is what to check tonight.

The Week the Backlog Came Due: Linux Holes, Defender Zero-Days, and a Poisoned Dev Tool
A messy seven days for defenders, where forgotten servers and trusted tooling did most of the damage.

Nimbus Manticore Drops MiniFast and MiniJunk V2 in Aviation Phishing Wave
Iran-linked UNC1549 is back with refreshed loaders, SEO-poisoned lures, and aviation-themed bait aimed at U.S., European, and Gulf targets.

Threat Detection Summits Are Useful. Whether Anyone Acts on Them Is Another Matter.
A free on-demand security summit covering threat detection and incident response frameworks is now available. The sessions are solid. The gap between watching and doing remains, as ever, wide.

Laravel Lang Composer packages backdoored via GitHub tag rewrite, dropping infostealer on developer machines
Attackers reused legitimate version tags on the laravel-lang GitHub repository to push malicious Composer payloads to downstream installs, harvesting credentials from build environments.