news.mlab.sh
11 results
threat-intel

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

The Chinese-speaking cybercrime group UAT-10147 is aggressively targeting web servers globally, leveraging AI-powered tools to automate intrusion operations and establish persistent access. They utilize a new cross-platform backdoor, SPECTRE, with advanced anti-analysis techniques and EDR bypass capabilities. The group…

The Hacker News · 6d ago High
threat-intel

Attackers Use AI to Automate EDR Evasion Testing

Attackers are leveraging artificial intelligence to automate the process of testing and developing malware designed to evade endpoint detection and response (EDR) systems. Sophos researchers discovered a sophisticated re…

Dark Reading · Jun 3, 2026 High
ransomware

State of ransomware in 2026

Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans…

Securelist · May 12, 2026 High
malware

EDR killers explained: Beyond the drivers

This article analyzes the increasing use of "EDR killers" in modern ransomware attacks. These tools, often based on vulnerable drivers or custom scripts, are deployed by affiliates to disrupt endpoint detection and respo…

WeLiveSecurity · Mar 19, 2026 High