threat-intel Chinese Routers Sold Worldwide Contain Backdoors Chinese router manufacturer Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) has been selling routers containing multiple backdoors, some dating back a decade, to white-label distributors worldwide. These backdoors, including EndlessDoors, SpeakingStone, and DarkLantern, allow remote access and control of infected devices… Dark Reading · 2d ago High CHUSRUbackdoorsupply-chainespionage
threat-intel Iran-linked hackers expand infrastructure across Europe and Middle East, report says Iranian-linked hackers, known as Tortoiseshell, are expanding their operations across Europe and the Middle East, including establishing infrastructure in Britain. The group, associated with Iran's Islamic Revolutionary… The Record · 3d ago High UKBESAiranaptssh tunnel
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 3d ago High IRMIEUsshbackdoorc2
threat-intel Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode A previously unreported Windows backdoor, dubbed SLEEPWALKER, has been identified by a malware researcher. The backdoor remains dormant until a specific crafted network packet is received, at which point it executes a cu… The Hacker News · 4d ago High backdoorside-loadingvmci
threat-intel You don't want this Sleepwalker backdoor on your Windows machine A previously unknown backdoor, dubbed ‘Sleepwalker,’ has been discovered in Nvidia’s drivers for Windows machines. This backdoor allows attackers to remotely execute code on vulnerable systems, potentially leading to ful… The Register · 5d ago High backdoorvulnerabilitynvidia
threat-intel Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor A cyber espionage campaign, dubbed Operation QUICSILVER, targeting Myanmar's government and IT sector is being conducted by a China-linked threat actor. The campaign uses a graduation ceremony lure to deliver a Go backdo… The Hacker News · 6d ago High MYMOPAcyber espionagebackdoorkernel-mode
threat-intel 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 A new AI-powered Linux backdoor, RedC2 4.0, is being distributed through malicious npm packages, significantly lowering the barrier to entry for attackers. The framework, developed and sold by Red Offsec, offers advanced… The Hacker News · Aug 21, 2026 High npmlinuxbackdoor
threat-intel Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia A threat actor, dubbed Operation CameraSwarm, has compromised over 14,000 Dahua IP cameras across Ukraine and Russia through a sophisticated campaign utilizing brute-force attacks and exploiting multiple vulnerabilities… SecurityWeek · Aug 20, 2026 High CVE-2021-33044CVE-2021-33045RUUKip camerasvulnerabilitybackdoor
threat-intel Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a dri… The Hacker News · Aug 14, 2026 High MYMOPArootkitkernel-modestealth
threat-intel New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure A Pakistan-aligned threat actor, APT36 (Transparent Tribe), is targeting Afghan telecom providers and critical infrastructure in South Asia with a new backdoor campaign called PATCHCORD. The campaign utilizes sector-spec… The Hacker News · Aug 13, 2026 High CVE-2024-6387AFINbackdoorc2afghanistan
threat-intel Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants The Head Mare APT group is exploiting multiple vulnerabilities in TrueConf servers to deliver the PhantomCore and PhantomGraph backdoors. Attackers connect to TrueConf servers without authorization, call a server functio… Securelist · Aug 11, 2026 Critical aptmalwarebackdoor
threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor
threat-intel Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Chinese router manufacturer Zbtlink ships router firmware with a factory-installed backdoor, dubbed "ENDLESSDOORS," that automatically attempts to connect to command-and-control infrastructure every 35 seconds. This back… The Hacker News · Aug 6, 2026 High CHbackdoorrouterc2
threat-intel Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway A Chinese router vendor, Longchen, initially denied that its firmware contained backdoors, but subsequently paused downloads to address security concerns. This follows reports of potential vulnerabilities and a desire to… The Register · Aug 6, 2026 Medium CHUSsupply-chainrouterbackdoor
threat-intel Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk Chinese-speaking hackers are targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, using two new backdoors, OctLurk and SilkLurk, along with… The Hacker News · Jul 31, 2026 High AFKYTAbackdoorproxycyberattack
threat-intel Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts A state-sponsored threat group, potentially linked to Lazarus and operating between 2025 and 2026, exploited vulnerabilities in AnySign4PC, a certificate-based electronic signature software, to install backdoors on targe… The Hacker News · Jul 30, 2026 High CVE-2020-7882SOwatering holebuffer overflowremote code execution
threat-intel Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays The Iranian state-backed hacking group Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is deploying a new campaign targeting entities across the Middle East, Africa, and South… The Hacker News · Jul 28, 2026 High IREGJOwindowsbackdoortunneling
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
threat-intel Senator calls on Rubio, Blanche to push back against Canadian surveillance legislation Senator Ron Wyden is urging the Trump administration to push back against Canadian legislation that could force U.S. tech companies to create backdoors and share user data, potentially compromising U.S. national security… The Record · Jul 16, 2026 High CAUSsurveillanceprivacyencryption
threat-intel 20+ Hijacked Government Websites Became an Attack Channel A sophisticated campaign, dubbed PhantomEnigma, has hijacked over 20 Brazilian government websites to deliver malware and conduct attacks against banks and public agencies. Attackers leveraged compromised .gov.br infrast… The Hacker News · Jul 16, 2026 High BRgovernmentphishingmalware