threat-intel Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices Manic, a sophisticated Android malware, is actively targeting financial institutions and government services across Ukraine, Russia, Central and Western Europe, and the U.K. This malware combines banking malware capabilities with spyware features, utilizing a novel Wi-Fi mesh relay system to exfiltrate data even when o… The Hacker News · Aug 20, 2026 High UKRUCEandroidbanking malwarespyware
threat-intel Apple plugs image-processing hole ripe for spyware abuse Apple has patched a security vulnerability in its image processing system that could have been exploited to install spyware. The flaw allowed attackers to trick an AI system into revealing instructions on how to self-hac… The Register · Aug 18, 2026 High CVE-2026-65346CVE-2026-65329aispywarevulnerability
threat-intel SpyGuard et MVT traquent les spywares mobiles This article highlights two tools – SpyGuard and Mobile Verification Toolkit (MVT) – designed to detect spyware on mobile devices. SpyGuard focuses on monitoring network communications for suspicious behavior, while MVT… ZATAZ · Aug 18, 2026 Medium spywaremobile securitydigital forensics
threat-intel Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware Apple is warning users in over 150 countries about potential mercenary spyware attacks, sending notifications via email and in-app alerts. These sophisticated attacks target specific individuals – journalists, activists,… The Hacker News · Aug 14, 2026 High spywaremercenarythreat-intel
threat-intel UK court rejects Bahrain immunity claim in spyware case The UK Supreme Court ruled that Bahrain cannot use state immunity to block a lawsuit filed by two dissidents alleging the Bahraini government used the FinSpy spyware to monitor them and their contacts, including politica… The Record · Jul 27, 2026 Medium BHGBsurveillancespywarestate-sponsored
threat-intel Hackers used Telegram phishing campaign to target exiled Belarusian activist Hackers are using highly personalized Telegram phishing campaigns targeting exiled Belarusian activists and users in Russia and Kazakhstan. The campaign leverages private messages and tailored fake login pages to steal T… The Record · Jul 27, 2026 High KZRUBYphishingaccount-hijackingtelegram
threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel Greek victims file lawsuit against Intellexa over Predator spyware Greek victims are suing Intellexa, the manufacturer of Predator spyware, seeking €7.6 million in compensation for privacy violations and data breaches. The spyware was allegedly used by the Greek government and intellige… The Record · Jul 8, 2026 High GRsurveillancespywareprivacy
threat-intel European Parliament Member Investigating Spyware Was Hacked With Pegasus A report by Citizen Lab revealed that former European Parliament member Stelios Kouloglou was repeatedly hacked with the Pegasus spyware while investigating the use of commercial surveillance tools, including Pegasus. Th… The Hacker News · Jul 3, 2026 High UKGRRUspywarepegasusapple
threat-intel Spyware found on phone of European Parliament member probing it A former European Parliament member, Stelios Kouloglou, was repeatedly targeted with Pegasus spyware while investigating the misuse of commercial spyware. Citizen Lab researchers discovered the infections occurred during… The Record · Jul 3, 2026 High GRDERUspywarepegasuseuropean parliament
threat-intel China-Linked Group Targets Southeast Asia Critical Systems A China-linked cyber threat group, CL-STA-1062 (formerly UAT-7237), has been targeting critical infrastructure providers in Southeast Asia over the past year, deploying a new backdoor tool called TinyRCT. The group has s… Dark Reading · Jul 1, 2026 High CNMYTHchinaaptbackdoor
threat-intel Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells… The Hacker News · Jun 22, 2026 High CAUSbotnetiotcybersecurity
threat-intel Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says A report by Human Rights Watch revealed that Bulgaria allowed a surveillance technology firm, Circles, to sell its products – including Pixcell, Landmark, and Voice Over Location Enabler software – to repressive regimes… The Record · Jun 18, 2026 High BUELUAsurveillancespywareexport control
threat-intel NSO Group Hacking WhatsApp Despite Court Order Recent reports indicate that NSO Group, a cybersecurity firm specializing in offensive intelligence, has been found to be utilizing its Pegasus spyware to target WhatsApp users despite a court order restricting its use.… Schneier on Security · Jun 10, 2026 High spywarewhatsappnsogroup
threat-intel WhatsApp says NSO targeted users with spearfishing attacks in violation of court order WhatsApp has accused NSO Group of violating a court order by conducting spearfishing attacks against its users, utilizing social engineering techniques to lure individuals into clicking malicious links. This follows a pr… The Record · Jun 8, 2026 High USspear-phishingsocial-engineeringspyware
threat-intel ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories This bulletin highlights several ongoing cyber threats, including a high-severity SSRF vulnerability in Cisco Unified Communications Manager, a large-scale spyware operation targeting Russian officials by foreign intelli… The Hacker News · Jun 4, 2026 High CVE-2026-20230CVE-2022-0492CVE-2019-5736RUIRUSssrfspywarekeylogger
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Inside Department 4: Russia’s secret school for hackers A new investigation has revealed a secret faculty within Bauman Moscow State Technical University, known as ‘Department 4,’ which has been training students to become hackers for Russian military intelligence, the GRU. T… Graham Cluley · May 8, 2026 High RUUSrussian hackingspywaregru
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage