threat-intel 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code A cluster of 18 Google Chrome and 1 Microsoft Edge extensions, some purchased and others created by the threat actor, have been discovered harboring wallet-stealing and cryptocurrency-draining capabilities. The campaign, dubbed ‘Superior’ by Socket, has been active since February 2024 and involves acquiring legitimate… The Hacker News · 2d ago High extensionmalwarewallet
threat-intel China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access A Chinese-made router manufacturer, Zhibotong Electronics (ZBT) through its brand Zbtlink, ships routers with two factory-installed implants – SPEAKINGSTONE and DARKLANTERN – that provide unauthenticated remote access to… The Hacker News · 2d ago High CVE-2026-74232CVE-2026-74233CVE-2026-66747CHc2routerfirmware
threat-intel Chinese Routers Sold Worldwide Contain Backdoors Chinese router manufacturer Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) has been selling routers containing multiple backdoors, some dating back a decade, to white-label distributors worldwide. These backdoors, includi… Dark Reading · 2d ago High CHUSRUbackdoorsupply-chainespionage
threat-intel GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address Threat actors linked to Dark Caracal have deployed a new Go-based malware framework, GoCaracal, utilizing an Ethereum smart contract to dynamically update its command-and-control (C2) address. This allows operators to ch… The Hacker News · 3d ago Medium BRECCHethereumsmart contractc2
threat-intel Dark Caracal Adds New Malware to Cyber Espionage Arsenal The Dark Caracal cyber-espionage group, linked to Lebanon, has added a new modular malware framework called GoCaracal to its arsenal. This framework, developed since 2026, is used for data theft, maintaining persistent a… Dark Reading · 3d ago High LBVEBRcyber-espionagedata theftmalware
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
threat-intel Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Multiple banking trojans – Manic, Grandoreiro, and ToxicPanda 2.0 – are actively targeting users worldwide, with a particular focus on financial institutions in Europe, Latin America, and increasingly, Russia. These troj… SecurityWeek · Aug 22, 2026 High BRUKRUbanking trojanmobile malwaresupply chain
threat-intel 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 A new AI-powered Linux backdoor, RedC2 4.0, is being distributed through malicious npm packages, significantly lowering the barrier to entry for attackers. The framework, developed and sold by Red Offsec, offers advanced… The Hacker News · Aug 21, 2026 High npmlinuxbackdoor
threat-intel Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet A new malware family, dubbed JarService, is targeting Android car head units developed by DoFun, leveraging the built-in update mechanism to spread ad fraud and proxy botnet capabilities. The campaign is attributed to th… The Hacker News · Aug 21, 2026 High CNandroidcarmalware
threat-intel UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publ… Cisco Talos · Aug 20, 2026 High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOaiautomationpost-exploitation
threat-intel Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks Pakistan's Transparent Tribe, a known advanced persistent threat (APT) group, has been aggressively targeting organizations in Afghanistan and India, utilizing a refined toolset including the Patchcord backdoor and other… Dark Reading · Aug 20, 2026 High AFINPAaptsocial engineeringbrowser hijacking
threat-intel StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data A sophisticated cybercrime operation, dubbed StopAndProtect, is leveraging over 6,000 compromised WordPress sites globally to distribute malware, steal data, and deploy ransomware. The attackers use a multi-stage attack… The Hacker News · Aug 19, 2026 High USRUINwordpressmalwareransomware
threat-intel TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across netw… The Hacker News · Aug 18, 2026 High c2microsoftlateral movement
threat-intel Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution.… The Hacker News · Aug 17, 2026 High IRc2dnsgoogle
threat-intel Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a dri… The Hacker News · Aug 14, 2026 High MYMOPArootkitkernel-modestealth
threat-intel Global Threat Campaign Hits Critical VMware vCenter Flaw A single threat actor has been aggressively exploiting a critical vulnerability (CVE-2026-59310) in VMware vCenter, initiating a global threat campaign that began shortly after public disclosure. The vulnerability, a dir… Dark Reading · Aug 13, 2026 High USFRIRvulnerabilityexploitreverse_ssh
threat-intel New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure A Pakistan-aligned threat actor, APT36 (Transparent Tribe), is targeting Afghan telecom providers and critical infrastructure in South Asia with a new backdoor campaign called PATCHCORD. The campaign utilizes sector-spec… The Hacker News · Aug 13, 2026 High CVE-2024-6387AFINbackdoorc2afghanistan
threat-intel Armored Likho expands its cyber-espionage toolkit The Armored Likho group (also known as Eagle Werewolf) has significantly expanded its cyber-espionage toolkit with the introduction of the ‘Still Toolkit,’ a new set of tools designed for advanced surveillance and data t… Securelist · Aug 13, 2026 High RUcyber espionagetelegramaudio surveillance
threat-intel Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sop… The Hacker News · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daysocial engineeringphishing