Threat Intelligence — Page 7

Chinese Hacking Group Adds Three New Backdoors to Its Router Attack Kit
The group behind a long-running campaign targeting small office routers has quietly expanded its toolbox, giving it more ways to hide inside a victim's network.

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

Fake CAPTCHA Pages Are Stealing From Mexican Bank Customers
Elastic Security Labs is tracking a fraud campaign, dubbed REF6045, that tricks people into pasting a malicious command from a bogus 'prove you're human' page.

Blocking Phishing Emails Is Not Enough. Here Is Why the Attack Carries On Anyway.
Filtering a malicious email out of your inbox stops one message, not the criminal behind it. A live webinar on 8 July 2026 sets out what disrupting a phishing campaign at its source actually requires.

Convicted fraudsters are running a US startup offering $7 million for software exploits
IRIS C2 says it pays up to $7 million for zero-day exploits. Its owners are Jacob Wohl and Jack Burkman, best known for felony robocall convictions and a string of political dirty-tricks stunts.

Fake Tax Emails Are Planting Two Separate Spying Tools on Indian Taxpayers' Computers
A campaign timed to India's tax filing season tricks people into downloading what looks like an official government utility. Inside: two hidden programs that give criminals full remote control of the victim's machine.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins all share the same quiet flaw: the copy most people read is rarely the full story.

Fake DoorDash Calls Are Draining Delivery Drivers' Wallets
Criminals are posing as DoorDash support staff, tricking gig workers into handing over account details, then quietly emptying their earnings. One driver lost $21,000.

Chinese hackers hijack unpatched routers to build a stealth relay network
A group Cisco Talos calls UAT-7810 is breaking into Ruckus and ASUS routers to hide the tracks of other China-linked spying crews.

RedWing: The Rent-a-Fraud Kit Turning Android Phones Into Bank Robberies
A new Android malware sold on Telegram lets almost anyone hijack a victim's phone, steal banking logins and grab the codes meant to keep accounts safe.

Spanish police arrest suspected helper of pro-Russian hacking crews
The man in Palencia allegedly helped a Ukrainian hacker flee toward Russia and supported groups linked to attacks on U.S. water and energy sites.

A Windows Device ID Helped Trace an Alleged Scattered Spider Hacker to a Jewelry Heist
Federal prosecutors say a single hardware identifier tied a May 2025 intrusion at a luxury retailer to the online accounts of a 19-year-old.

Iran-Linked Hackers Hit Israeli IT Firms to Reach High-Value Targets
A group tied to Iran used a flexible, plug-in-style hacking toolkit to break into IT service providers in Israel, then moved through those companies to attack their clients.

Suspected Chinese Hackers Target University Webmail in Credential-Stealing Campaign
A hacking group tied to China is breaking into Roundcube webmail systems at physics and engineering faculties across US and Canadian universities to steal login details.

German Court Case Exposes Telegram Network That Drugged and Filmed Women in Secret
A phone call from police told a Chinese student in Germany that her ex-boyfriend had taken nude photos of her while she slept. She was one of many victims of an organised online group.