threat-intel Red Flags That Expose Fake North Korean IT Workers North Korean operatives are increasingly sophisticated in their attempts to infiltrate organizations by posing as IT workers, often leveraging stolen or fabricated identities and VPNs to mask their locations. Huntress Intelligence, a security firm, has identified multiple instances of this fraud, particularly within th… Dark Reading · 4d ago High CHNEnorth koreanvpnproxy
threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and con… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel Hackers infect Android car systems to build proxy botnet Hackers are exploiting vulnerabilities in Chinese automotive software provider DoFun's Android car head units to build a proxy botnet. The malware, initially delivered through a legitimate system application (TWCore), al… The Record · 6d ago High CHGEandroidbotnetproxy
threat-intel The invisible passenger in your car Researchers at Securelist discovered a new Android malware campaign targeting automotive head units, orchestrated by the MoYu Group, a group linked to the BADBOX botnet. The malware, delivered through legitimate system u… Securelist · Aug 21, 2026 High androidiotbotnet
threat-intel Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies A new Linux botnet, dubbed Evooo1Bot, leveraging Mirai's code, is actively exploiting vulnerabilities in internet-facing devices to turn them into SOCKS5 proxies. The botnet utilizes a range of capabilities including enc… The Hacker News · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558botnetsocks5proxy
threat-intel New Mirai variant adds stealth capabilities to notorious botnet code A new, stealthier variant of the Mirai botnet, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for over a month. This malware boasts advanced features like encrypted communicati… The Record · Aug 13, 2026 High CACHGEmiraibotnetvulnerability
threat-intel 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One A massive collection of 737 Chrome VPN and proxy extensions are being used to route user traffic through a single SOCKS5 proxy infrastructure, primarily targeting Russian-speaking users seeking access to blocked content.… The Hacker News · Aug 12, 2026 High RUvpnproxychrome
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
threat-intel Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th) The SANS Internet Storm Center is observing a scanning campaign targeting Solana infrastructure, likely conducted by automated tools. These scans are attempting to enumerate Solana API endpoints and potentially extract c… SANS Internet Storm Center · Aug 10, 2026 Medium solanascanningreconnaissance
threat-intel Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer A sophisticated campaign involving nearly 800 malicious npm packages has been deployed to deliver cross-platform malware – a Remote Access Trojan (RAT) and infostealer – targeting Windows, macOS, and Linux systems. The p… The Hacker News · Aug 7, 2026 High RUnpmsupply chainmalware
threat-intel Token Jacking: Cybercriminals Could Be Stealing Your AI Resources Cybercriminals are exploiting a growing trend of AI token jacking to generate significant financial losses. As AI adoption increases and costs for accessing powerful models rise, attackers are stealing API keys – known a… Palo Alto Unit 42 · Aug 6, 2026 High CHaitoken jackingtransfer station
threat-intel Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Cybersecurity researchers have uncovered a network of underground services, including ‘Poison Claude,’ offering discounted access to Anthropic’s AI models (like Claude Opus) to users in China and elsewhere. These service… The Hacker News · Aug 5, 2026 High CHaisynthetic identityproxy
threat-intel Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk Chinese-speaking hackers are targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, using two new backdoors, OctLurk and SilkLurk, along with… The Hacker News · Jul 31, 2026 High AFKYTAbackdoorproxycyberattack
threat-intel Read This Before You Buy That TV Streaming Stick A security firm, Bitsight, uncovered a complex and widespread ad fraud network centered around H96 streaming devices. These devices, often sold by major retailers, are secretly used to generate revenue by masquerading as… Krebs on Security · Jul 30, 2026 High CHHOSIiotproxyad fraud
threat-intel Spur Raises $200 Million for IP Intelligence Platform Spur Intelligence, a company specializing in IP intelligence and bot detection, has secured $200 million in funding from Insight Partners to combat increasing fraud and security challenges driven by the widespread use of… SecurityWeek · Jul 29, 2026 Info ip intelligencefraud preventionvpn
threat-intel GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration A sophisticated, evolving threat actor, potentially linked to TetrisPhantom, has been targeting government and diplomatic entities in Southeast Asia since late 2025 with a campaign utilizing tools like GoSerpent, Stowawa… Securelist · Jul 16, 2026 High VNTHproxyremote accessdata exfiltration
threat-intel 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May. These packages, initially designed as tutoring tools, lo… The Hacker News · Jul 14, 2026 High USbotnetddosproxy
vulnerability Friday Squid Blogging: “Squidbleed” Vulnerability A vulnerability, dubbed ‘Squidbleed,’ has been discovered in the Squid proxy server, allowing attackers to leak HTTP requests. This flaw stems from a flawed implementation of the HTTP/2 protocol, potentially exposing sen… Schneier on Security · Jul 10, 2026 Medium http2proxyvulnerability
threat-intel Winning 54% of the time Cisco Talos Intelligence has identified a China-nexus threat actor, UAT-7810, expanding its Operational Relay Box (ORB) network. The group exploits unpatched vulnerabilities in Ruckus and ASUS routers to deploy custom ma… Cisco Talos · Jul 9, 2026 High CHorbproxyrouter
threat-intel Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes A China-based threat actor, dubbed Lurking Lizard, has been running a sophisticated, multi-year residential proxy business. The operation involves tricking users into installing malicious 7-Zip installers and other fake… The Hacker News · Jul 9, 2026 High CHresidential proxybotnetmalware