threat-intel SE Asian Cybercriminal Syndicates Become a Global Power Southeast Asian cybercriminal syndicates have evolved into a global organized crime crisis, fueled by technological advancements and corruption. These groups, originating largely from China and operating across Southeast… Dark Reading · Jul 30, 2026 Critical CHMYCAcybercrimecryptocurrencytrafficking
threat-intel Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A sophisticated malvertising campaign, dubbed SourTrade and linked to Confiant, is using legitimate browser technologies like Bun and a ServiceWorker to build Windows executables for victims, primarily targeting retail t… The Hacker News · Jul 25, 2026 High malvertisingbrowserbun
threat-intel Kenya probes hack of president's website after bitcoin ransom demand Kenya’s presidential website was hacked, with attackers demanding a ransom of five bitcoins in exchange for not releasing sensitive information. The incident follows a previous coordinated attack in November 2025, highli… The Record · Jul 21, 2026 Medium KEcyberattackransomwaregovernment
threat-intel UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised website… The Hacker News · Jul 19, 2026 High RUsocial engineeringclickfixrussia
threat-intel Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors, linked to the Contagious Interview campaign (REF9403), are using fake coding tests and SVG images containing steganography to deliver a multi-stage malware payload – OtterCookie – to software… The Hacker News · Jul 17, 2026 High KPsteganographysupply chaindeveloper
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
threat-intel Dutch police dismantle global crypto investment scam, arrest alleged mastermind Dutch police have dismantled a global cryptocurrency investment scam involving over 700 employees operating from dozens of call centers across multiple countries. The operation, led by a ‘well-known hacker’ with Israeli… The Record · Jul 15, 2026 High NEPOBEcryptocurrencyfraudscam
threat-intel OkoBot: new sophisticated malware framework targets cryptocurrency users OkoBot is a sophisticated and evolving malware framework developed by threat actors since 2025, primarily targeting cryptocurrency users. The framework utilizes a layered approach, starting with a PowerShell downloader (… Securelist · Jul 15, 2026 High ransomwarecryptocurrencybrowser
threat-intel Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Threat actors compromised the Injective Labs GitHub repository and injected a malicious npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. The package, disguised as telemetry func… The Hacker News · Jul 10, 2026 High npmsupply-chaincryptocurrency
threat-intel Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets Attackers are exploiting a vulnerability called ‘Ill Bloom’ in several cryptocurrency wallets, allowing them to drain funds. A coordinated attack on May 27th resulted in $3.1 million being stolen from 431 wallets, with a… The Hacker News · Jul 10, 2026 High CVE-2023-39910CVE-2023-31290vulnerabilitycryptocurrencywallet
ransomware Mount Royal University Confirms Data Stolen in Ransomware Attack Mount Royal University in Canada suffered a ransomware attack that resulted in the theft of employee and student data. The attackers, identified as CMD Organization, exfiltrated over 10 terabytes of information and are d… SecurityWeek · Jul 9, 2026 High CAransomwaredata breachtor
threat-intel Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish authorities, with assistance from the FBI, arrested a man suspected of aiding pro-Russian hacktivist groups, specifically in facilitating the escape of a Ukrainian hacker linked to CARR. The investigation uncover… The Record · Jul 8, 2026 Medium SPPOBErussianhacktivismddos
threat-intel Attackers vote themselves $20 million in BONK cryptocurrency Attackers exploited a governance mechanism within the decentralized finance project overseeing BONK cryptocurrency, draining $20 million worth of the token. This was achieved through a malicious governance proposal, leve… The Record · Jul 6, 2026 High KRdaogovernancecryptocurrency
threat-intel U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case A U.S. government entity reportedly paid $1 million to the group known as Kairos to prevent the leak of stolen data following a data breach at Union County, Ohio. Kairos, however, operated solely through data theft extor… The Hacker News · Jul 4, 2026 High USRUdatatheftextortionnegotiation
threat-intel North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This… The Hacker News · Jul 4, 2026 High KPnorth koreangithubmalware
threat-intel Ukraine to use seized crypto from cybercrime group to buy war bonds Ukraine is utilizing cryptocurrency seized from a notorious international cybercrime group to bolster its war effort. Over $8.3 million in digital assets, obtained from investigations targeting attacks across Europe and… The Record · Jun 29, 2026 High UKRUUScybercrimecryptocurrencywar bonds
threat-intel DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering The U.S. Department of Justice seized a cloud computing account belonging to HuiOne Group subsidiaries, following an investigation into their role in facilitating cryptocurrency-based cyber scams and money laundering ope… The Hacker News · Jun 24, 2026 Critical CACHUScryptocurrencyfraudmoney laundering
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
supply-chain Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account… BleepingComputer · Jun 20, 2026 High KPsupply-chainnpmcryptocurrency
malware Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has detailed a new Windows-based malware campaign, dubbed Windows Clipper, that leverages USB LNK files and a Tor-based command-and-control infrastructure to steal cryptocurrency data. The clipper silently moni… The Hacker News · Jun 18, 2026 High clipboardtorusb