threat-intel China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa A China-linked cybercrime group, TA4922, has broadened its phishing attacks to include organizations in the UK, Germany, Italy, and South Africa. The group utilizes a constantly evolving arsenal of malware, including Val… The Hacker News · Jun 4, 2026 Medium UKGEITphishingratcredential theft
malware Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT A new malspam campaign is leveraging Google's DoubleClick domain to deliver the DesckVB RAT, a .NET-based remote access trojan. The campaign’s scalability and cost-effectiveness stem from its ability to dynamically perso… The Hacker News · Jun 3, 2026 High USmalspamratdoubleclick
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
threat-intel Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns This report from Palo Alto Unit 42 details ongoing espionage campaigns conducted by the Iran-nexus APT group Screening Serpens (UNC1549). The group, active since 2022, targeted entities in the U.S., Israel, the UAE, and… Palo Alto Unit 42 · May 22, 2026 High USIRILaptespionagesocial engineering
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat