Tag: backdoor
-
Hackers breach TrueConf to trojanize client installers with backdoors
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/
-
Zbtlink denies backdoor claims amid firmware download pause
First seen on scworld.com Jump to article: www.scworld.com/brief/zbtlink-denies-backdoor-claims-amid-firmware-download-pause
-
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of…
-
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.Nothing here…
-
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to…
-
QuickFox VPN targeted in long-standing supply chain attack delivering FDMTP backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/quickfox-vpn-targeted-in-long-standing-supply-chain-attack-delivering-fdmtp-backdoor
-
VulnCheck Warns That Chinese Zbtlink Routers Include a Backdoor
VulnCheck researcher say at least 100,000 Chinese-made Zbtlink routers around the world may include an intentionally implanted backdoor dubbed “Endlessdoors” that could give threat actors access to devices on the network. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/vulncheck-warns-that-chinese-zbtlink-routers-include-a-backdoor/
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute.When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and…
-
Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
Ransomware operators are now abusing Ethereum smart contracts as stealthy command”‘and”‘control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding them in the malware. The toolkit shows a clear progression: scheduled tasks that bootstrap PowerShell, privileged account creation (“support2” with Supp0rt2@2026!). LSASS…
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to…
-
OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments
The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities in the Middle East by an East Asia-linked threat actor tracked as OctLurk. The disclosure follows Part 1, which detailed the TELESHIM backdoor and the MIXEDKEY loader used earlier in the same multi-stage intrusion chain.…
-
Apple challenges UK government’s latest demand for iCloud backdoor: report
Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/03/apple-challenges-uk-governments-latest-demand-for-icloud-backdoor-report/
-
Kaspersky to scan AI agents for backdoors as shadow AI spreads
The security supplier will release a tool this month that vets agent skills, models and artificial intelligence development components before they reach corporate networks to defend against threats from shadow AI First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646680/Kaspersky-to-scan-AI-agents-for-backdoors-as-shadow-AI-spreads
-
To Ban or Not Ban Chinese Open-Weight AI Models
Tags: ai, backdoor, china, control, cybersecurity, data, defense, finance, government, infrastructure, international, malicious, microsoft, military, network, nvidia, open-source, openai, regulation, risk, software, supply-chain, technology, usaShould the US ban American companies from using Chinese open-weight AI models? That is the ugly question. US officials have openly expressed concerns and a desire to implement regulations. The technology community has aggressively responded, with over 20 leading AI companies, including Microsoft, Nvidia, Meta, and Dell, urging legislators not to rush imposing restrictions on…
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…
-
Wordfence Finds Critical Backdoor in ARVE WordPress Plugin
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites. First seen on hackread.com Jump to article: hackread.com/wordfence-critical-backdoor-arve-wordpress-plugin/
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign
OctLurk and SilkLurk are highly customized, memory”‘resident backdoors used in an ongoing cyberespionage campaign against government and critical”‘sector networks across Central Asia and Syria, operated by a Chinese”‘speaking threat actor but not yet linked to a known APT. Active since January 2025, the operation leverages victim”‘specific loaders, multi”‘plugin frameworks, and shared infrastructure, along with Linux”‘focused…
-
Kremlin hackers are exploiting Exchange flaw to backdoor unpatched networks
Exploits can give persistent server access that survives credential rotation and disk re-imaging. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/
-
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,…
-
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations First seen on hackread.com Jump to article: hackread.com/fake-it-calls-microsoft-teams-gogrpc-backdoor/
-
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware Chaos ransomware’s msaRAT: Living…
-
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
At a glance Malware family GoSerpent backdoor, plus McMx, Stowaway, ThumbcacheService, and TmcLoader/TmcPayload Threat actor Unconfirmed. Kaspersky notes First seen on securityonline.info Jump to article: securityonline.info/goserpent-backdoor/
-
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma”‘associated Node.js backdoor through trusted GitHub Actionsdriven release workflows and exposing high”‘value developer and CI/CD environments to remote access, credential theft, and further lateral movement. Malicious versions were shipped for @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, and @asyncapi/specs@6.11.2 and 6.11.2-alpha.1, together accounting for…
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…

