threat-intel Un recrutement VPN français intrigue sur un forum pirate A Russian cybercriminal forum member is recruiting French speakers to develop a VPN, claiming it is entirely legal. However, the individual's history on the forum – including discussions about buying hacked accounts, spam, generating malicious traffic, and distributing trap files – raises significant concerns. The shif… ZATAZ · Aug 21, 2026 Medium FRvpnrecruitmentfrance
threat-intel SilkParasite Threatens Central Asian Orgs With Flurry of RATs A Chinese-nexus cyber-espionage group, linked to FamousSparrow and the ShadowPad ecosystem, known as SilkParasite, is targeting government organizations across Central Asia (Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikist… Dark Reading · Aug 19, 2026 High UZTMKGchinaespionagerat
threat-intel WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud A new Android malware family, WindRelay, is being used in conjunction with a remote access trojan (RAT) called SpyNote to facilitate contactless payment fraud. The malware turns infected devices into NFC relays, allowing… The Hacker News · Aug 13, 2026 High CZSKSIandroidnfcrelay
threat-intel Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking A Russian state-sponsored APT group, Storm-2945 (linked to Midnight Blizzard/APT29), is leveraging compromised public Wi-Fi gateway networks to steal Microsoft 365 credentials of traveling employees. The campaign involve… SecurityWeek · Aug 3, 2026 High aptcredential theftdns manipulation
threat-intel Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates A remote access trojan (RAT) called Flying Eagle, along with a related control kit called Night Dragon, is circulating through criminal Telegram channels. Researchers have identified 170 servers hosting the RAT framework… The Hacker News · Jul 29, 2026 High CNandroidrattelegram
threat-intel MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection MedusaHVNC is a sophisticated remote access trojan (RAT) sold as a service, utilizing hidden Windows desktops to evade detection and maintain a persistent presence on victims' systems. BlackFog researchers discovered the… SecurityWeek · Jul 27, 2026 High RUrathidden desktopencryption
supply-chain Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT A sophisticated software supply chain attack, dubbed ViteVenom, is leveraging a blockchain-based command-and-control (C2) infrastructure to deliver a remote access trojan (RAT) targeting Vite frontend developers. The att… The Hacker News · Jul 17, 2026 High supply chainblockchainc2
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
threat-intel ClickFix's Mushrooming Ecosystem Demands New Defense Tactics ClickFix, initially a social engineering attack vector, has evolved into a sophisticated malware-as-a-service (MaaS) ecosystem, outpacing traditional security defenses. Attackers are now utilizing a range of malware, inc… Dark Reading · Jul 14, 2026 High social engineeringmalware-as-a-serviceyara
apt Armored Likho APT Targeting Government, Electric Power Entities The Armored Likho APT group is actively targeting government and electric power entities across multiple countries, including Russia, Brazil, and Kazakhstan. The group utilizes a diverse toolkit of malware, including RAT… SecurityWeek · Jul 6, 2026 High RUBRKZaptspear-phishingrat
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service
threat-intel Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign The Securelist report details a new cyber espionage campaign conducted by the Armored Likho (Eagle Werewolf) APT group, targeting government agencies and the electric power sector globally. The group utilizes a sophistic… Securelist · Jul 3, 2026 High RUBRKZaptphishinginfostealer
threat-intel ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news highlights several vulnerabilities and ongoing threats across various sectors. A phishing campaign targeting small businesses globally with ransomware, a root escape vulnerability in Claude Cowo… The Hacker News · Jul 2, 2026 High CVE-2026-33825CHUNGEphishingransomwaresandbox
malware The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign A large-scale cyber campaign utilized the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware onto compromised systems. Threat actors disguised installers of popular software like OBS Studio and DNS Ju… Securelist · Jul 1, 2026 High GDremote accessdll sideloadingpersistence
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
threat-intel ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures ClickFix campaigns are expanding their malware delivery tactics with new loaders, including BabaDeda Loader, Lorem Ipsum Loader, and Storage Crypter, targeting education and financial organizations. These attacks utilize… The Hacker News · Jun 16, 2026 High RUBYsocial engineeringloaderpayload
ransomware Ransomware gang abuses Microsoft Teams relays to hide malicious traffic DragonForce ransomware utilized a custom malware, Backdoor.Turn, to conceal command-and-control traffic by leveraging Microsoft Teams’ TURN protocol. This technique allowed the attackers to bypass traditional network def… BleepingComputer · Jun 16, 2026 High CVE-2023-52271CVE-2025-61155CVE-2025-1055USteamsturnrat
threat-intel Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK f… The Hacker News · Jun 16, 2026 High NOSOspear-phishingratnorth korean
ransomware From a VHDX File to a Remcos RAT, (Tue, Jun 16th) A malicious ZIP archive, containing a VHDX file, was discovered utilizing a multi-stage attack chain to deploy the Remcos RAT. The initial delivery involves a JavaScript payload that leverages WMI and PowerShell to execu… SANS Internet Storm Center · Jun 16, 2026 High DEratpowershellwmi
threat-intel China's TA4922 Expands Cybercrime Attacks Globally China's TA4922 cybercrime group has significantly expanded its operations globally, targeting a diverse range of countries and employing a wider array of tactics and techniques than previously observed. Initially focused… Dark Reading · Jun 4, 2026 High CHJATAphishingratmalware