Threat Intelligence — Page 8

Meet BusySnake: The Stealthy Malware Quietly Raiding Government Networks
A newly discovered hacking group is hitting government offices and critical services in three countries with a cunning piece of spy software. Here is what it does and who is at risk.

Fake IT Helpdesk Calls on Microsoft Teams Are Planting EtherRAT on Company PCs
Attackers pose as internal support staff over Teams voice calls, then walk employees through installing remote-access tools that drop a Node.js trojan.

Fake job interviews from 'Adidas', 'Netflix' and 'OpenAI' recruiters are stealing Google logins
A phishing crew is impersonating more than 30 major brands, hiding behind real business software from PeopleForce and Salesforce to trick marketing staff into handing over their Gmail passwords.

Iranian Spies Target Israeli IT Firms With a New Custom Toolkit Called Cavern
A hacking crew tied to Iran's intelligence ministry is running a previously unseen command-and-control framework against Israeli government bodies and their IT suppliers.

The Weak Link This Week Wasn't Code. It Was Trust.
From home streaming boxes turned into criminal relays to AI assistants tricked by hidden instructions, this week's incidents share one root cause: systems trusting the wrong thing.

North Korean Hackers Poisoned Over 100 Open Source Packages to Spy on Developers
A campaign called PolinRider has quietly corrupted legitimate software building blocks used by developers worldwide, planting tools that steal data and leave a hidden door open for attackers.

Fake Indian tax portal used to plant spyware on finance teams' computers
A suspected Chinese hacking group is posing as India's Income Tax Department to slip a remote-control virus onto the machines of accountants and corporate finance staff.

TrojPix: Academic Research Shows Air-Gapped PCs Can Leak Data Through Screen Pixels
Researchers at Shandong University describe a covert channel that turns a monitor cable into a radio transmitter, but the technique still needs malware on the target first.

QuimaRAT: A New Rent-a-Malware Kit That Hits Windows, Mac and Linux
Researchers at LevelBlue say the Java-based remote access tool is being sold as a subscription, starting at $150 a month, and works across all three major desktop systems.

North Korean hackers flood open-source repositories with 108 booby-trapped packages
The Contagious Interview crew is back, seeding npm, Packagist, Go and Chrome with malware aimed at developers.

Google and FBI cut off NetNut, a two-million-device botnet hidden inside smart TVs
The residential proxy service let hundreds of criminal and spy groups route attacks through ordinary homes.

Fake Rollup Helper Packages on npm Traced to North Korean Hackers
Two look-alike JavaScript packages copied a popular developer tool line-for-line, then quietly opened a back door onto the machines of anyone who installed them.

Three Quick Hits: Canadian Hacker Jailed, Open-Source Flaws Dropped, ATM Jackpotters Sentenced
A week's worth of security stories that deserve a second look — from an Anonymous-linked arrest in Canada to cash-machine criminals facing US prison time.

Armored Likho: the newly-named hacking crew hitting power grids and government offices
Russian security firm Kaspersky says the group mixes espionage against big institutions with money-driven attacks on ordinary people.

A Spyware Investigator Got Spied On: Pegasus Hit an EU Lawmaker Probing Pegasus
Forensic analysis of Stelios Kouloglou's phone shows repeated Pegasus infections while he sat on the European Parliament's own spyware inquiry.