threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver
supply-chain OptinMonster WordPress plugin hacked in CDN supply-chain attack A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN… BleepingComputer · Jun 15, 2026 High UScdnwordpresssupply chain
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
threat-intel OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack OceanLotus, a 15-year-old APT group with a history of targeting China and human rights activists, has been conducting a prolonged cyber espionage operation against Vietnamese entities, including a transport construction… The Hacker News · Jun 11, 2026 High VNsupply chainbackdoorespionage
threat-intel OceanLotus: From external espionage to domestic targeting OceanLotus, a Vietnamese-aligned cyberespionage group (formerly APT32), has shifted its focus from external espionage to domestic targeting, particularly in relation to corruption investigations in Vietnam. Since 2020, f… WeLiveSecurity · Jun 11, 2026 High VNsupply-chainespionagebackdoor
threat-intel VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances A China-based cyber espionage group, VerdantBamboo, deployed a BSD variant of the BRICKSTORM backdoor and the PLENET malware family on Linux appliances to target a victim organization. The attack involved exploiting vuln… The Hacker News · Jun 8, 2026 High CVE-2026-22769CHlinuxbackdoorespionage
apt Chinese APT deploys new malware to keep access to hacked networks A Chinese Advanced Persistent Threat (APT) group, tracked as UNC5221 (VerdantBamboo), has been conducting a prolonged espionage campaign targeting organizations in the United States, primarily leveraging the Brickstorm b… BleepingComputer · Jun 5, 2026 High CNespionagebackdoorpersistence
malware FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads A new macOS malvertising campaign, dubbed Operation FlutterBridge, is utilizing FlutterShell, a backdoor that spreads adware via malicious Google and YouTube ads. The campaign, traced back to the CL-CRI-1089 threat actor… The Hacker News · Jun 4, 2026 High USCAAUmalvertisingmacoswebview
vulnerability Acer working to patch max severity zero-days in Wave 7 routers Acer has confirmed the existence of two critical zero-day vulnerabilities in its Wave 7 mesh routers, reported by security researcher Gergo Pap. These flaws, CVE-2026-49200 and CVE-2026-49201, allow unauthorized access t… BleepingComputer · Jun 3, 2026 Critical CVE-2026-49200CVE-2026-49201zero-daymesh routercredentials
malware Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor Palo Alto Unit 42 is tracking ‘Operation FlutterBridge,’ a widespread malvertising campaign targeting macOS users. The campaign, a follow-up to the ‘JSCoreRunner’ campaign, utilizes malicious desktop applications built w… Palo Alto Unit 42 · Jun 2, 2026 High USmacosmalvertisingbackdoor
malware Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning Iranian state-sponsored threat actor Nimbus Manticore (UNC1549) has launched a new campaign utilizing the MiniFast backdoor, developed with potential AI assistance, to target organizations in the aviation and software se… The Hacker News · May 26, 2026 High SAAUIRphishingbackdoorappdomain hijacking
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat
malware Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS A new macOS infostealer, dubbed SHub Reaper, is targeting users through fake WeChat and Miro installers, mimicking Google, Microsoft, and Apple to lure victims. This malware combines stealer and backdoor capabilities, ut… Dark Reading · May 19, 2026 High USmacosinfostealerbackdoor
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage
apt GopherWhisper: A burrow full of malware ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go… WeLiveSecurity · Apr 23, 2026 High MNaptchinago