threat-intel GigaWiper Lets Threat Actors Choose Their Own Destructive Attack GigaWiper is a novel, modular malware that combines backdoor and wiper capabilities, allowing attackers to choose how to destroy a targeted system while minimizing their operational footprint. Initially identified as a G… Dark Reading · Jul 13, 2026 High IRRUVEwiperbackdoormodular
threat-intel GigaWiper Combines Multiple Malware for System-Level Sabotage Microsoft has identified a sophisticated malware strain called GigaWiper, a Go-based backdoor combining multiple destructive capabilities – including a physical disk wiper, ransomware-like encryption, and persistent C&C… SecurityWeek · Jul 10, 2026 High IRbackdoorransomwarewipe
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction
vulnerability Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices A security researcher discovered an unpatched backdoor in Tenda firmware, granting attackers administrative access to Tenda devices. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass authenticatio… SecurityWeek · Jul 9, 2026 High CVE-2026-11405CVE-2026-13753backdoorunpatchedwebserver
threat-intel China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors A China-linked advanced persistent threat group, UAT-7810, has expanded its arsenal with new backdoors, including LongLeash, DogLeash, and JarLeash, as part of a long-running espionage campaign. The group primarily targe… SecurityWeek · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CNbackdooraptespionage
threat-intel China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware A Chinese APT group, UAT-7810, is expanding its Operational Relay Box (ORB) network by utilizing custom malware, including LONGLEASH and LEASHTEST, to establish persistent access for secondary threat actors. The group le… The Hacker News · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717TWaptmalwarec2
vulnerability CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The CERT Coordination Center has issued a warning about a hidden backdoor embedded in Tenda router firmware. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass password verification and gain full a… The Hacker News · Jul 7, 2026 High CVE-2026-11405routerbackdoorfirmware
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
threat-intel Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking Advanced Persistent Threat (APT) group, CL-STA-1062, has been actively targeting government entities and critical infrastructure in Southeast Asia since 2022, utilizing a new custom backdoor called Tin… The Hacker News · Jun 26, 2026 High VNaptbackdoorsoutheast asia
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utili… Palo Alto Unit 42 · Jun 25, 2026 High VNeast asiasoutheast asiabackdoor
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
malware Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payout… BleepingComputer · Jun 24, 2026 High USbrowser extensionnative messagingransomware
threat-intel Stealthy Mistic backdoor linked to ransomware access broker KongTuke A new stealthy backdoor, dubbed Mistic, has been identified as a tool used by the initial access broker KongTuke to facilitate ransomware attacks against organizations in the insurance, education, IT, and professional se… BleepingComputer · Jun 24, 2026 High USbackdoorinitial accessransomware
supply-chain ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack A supply chain attack compromised multiple WordPress plugins from ShapedPlugin, injecting backdoor code into Pro plugin releases distributed through official update channels. The malicious plugins, affecting versions of… The Hacker News · Jun 22, 2026 Critical CVE-2026-49777CVE-2026-10735wordpresssupply chainbackdoor
supply-chain ShapedPlugin update flow hacked to infect WordPress sites A supply-chain attack targeting WordPress plugins from ShapedPlugin resulted in malicious updates containing a backdoor designed to steal sensitive data from affected websites. The attack exploited a compromised build pi… BleepingComputer · Jun 18, 2026 High CVE-2026-10735CVE-2026-49777wordpresssupply chainbackdoor
threat-intel SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Hondur… Dark Reading · Jun 16, 2026 High HNTWTHkernel-driveraptbackdoor
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor