Tag: backdoor
-
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
Tags: access, backdoor, cve, cyber, exploit, flaw, linux, malware, remote-code-execution, vulnerabilityA sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation of CVE-2025-53521, an unauthenticated remote code execution flaw affecting BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the vulnerability and links the related compromise activity…
-
Über Zero-Day-Lücke: Angreifer schleusen Backdoor in Onlineshops ein
Hacker kompromittieren Onlineshops auf Basis von Magento über eine Sicherheitslücke. Sie schleusen Schadcode ein und platzieren eine Backdoor. First seen on golem.de Jump to article: www.golem.de/news/ueber-zero-day-luecke-angreifer-schleusen-backdoor-in-onlineshops-ein-2609-212724.html
-
DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations
A previously undocumented Linux espionage toolkit linked with medium confidence to DPRK-aligned threat actors has been used to compromise South Korean organizations in the automotive and media sectors. The campaign is notable because it does not exploit a flaw in HAProxy itself. Instead, the operators appear to have obtained code execution on targeted edge servers…
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Tags: adobe, advisory, attack, backdoor, exploit, flaw, malicious, open-source, vulnerability, zero-dayAttackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4.…
-
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOOKEDGE in espionage operations targeting government, diplomatic, and defense-manufacturing organizations across Europe. The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026. New variants…
-
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on…
-
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on…
-
New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary…
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
ey Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor firstdocumentedtargeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, and familiar offensive utilities.…
-
Silver Fox uses adware to distribute ValleyRAT backdoor
First seen on scworld.com Jump to article: www.scworld.com/brief/silver-fox-uses-adware-to-distribute-valleyrat-backdoor
-
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilities, and in-memory payload execution. No threat actor, victim, delivery chain, or live campaign has yet been attributed to the malware. SLEEPWALKER is an unsigned 64-bit Windows DLL…
-
How AI could make it harder for governments to use hacking tools
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/31/how-ai-could-make-it-harder-for-governments-to-use-hacking-tools/
-
âš¡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.Elsewhere, fake apps, helpful support calls, cheap banking…
-
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese…
-
BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute…
-
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that’s distributed via First seen…
-
White House bans foreign-made equipment for power generation over cyber backdoor concerns
The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology. First seen on therecord.media Jump to article: therecord.media/trump-cyber-electricity-parts
-
Chinese Routers Sold Worldwide Contain Backdoors
An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors
-
Public wary of UK government ‘backdoor’ surveillance following Apple row, poll reveals
A poll of 2,000 UK citizens taken after the government issued a secret order seeking access to Apple users’ encrypted data finds that the public is sceptical of government surveillance powers First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649780/Public-wary-of-UK-government-backdoor-surveillance-following-Apple-row-poll-reveals
-
Public wary of UK government ‘backdoor’ surveillance following Apple row, poll reveals
A poll of 2,000 UK citizens taken after the government issued a secret order seeking access to Apple users’ encrypted data finds that the public is sceptical of government surveillance powers First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649780/Public-wary-of-UK-government-backdoor-surveillance-following-Apple-row-poll-reveals
-
SLEEPWALKER Backdoor Uses Magic Packet, DLL Side-Loading and In-Memory Shellcode Execution
A newly documented Windows backdoor named SLEEPWALKER combines passive network monitoring, DLL side-loading, and encrypted bytecode to remain dormant until attackers deliver a precisely crafted trigger packet. The malware does not beacon to a conventional command-and-control server, making it particularly difficult to identify through outbound-traffic monitoring alone. The 59,904-byte unsigned file masquerades as Microsoft’s dpapi.dll…
-
New ‘Sleepwalker’ backdoor uses custom command language
Tags: backdoorFirst seen on scworld.com Jump to article: www.scworld.com/brief/new-sleepwalker-backdoor-uses-custom-command-language-remains-hidden
-
14 manipulierte npm-Pakete verbreiten Linux-Backdoor RedC2 4.0
Sicherheitsforscher haben manipulierte npm-Pakete entdeckt, die sich als Kalenderwerkzeuge tarnen, jedoch eine KI-gestützte Linux-Hintertür installieren. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/linux-backdoor-npm-pakete
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka First seen on thehackernews.com…
-
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have legitimate uses on Windows systems, making malicious activity harder to distinguish from normal software behavior. According to Cybersecurity News, Iran-linked operators are abusing the legitimate Deno JavaScript…
-
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to give operators covert, durable access to compromised internal networks. The research began with public reporting from Kaspersky on Mirage Kitten’s newer malware ecosystem, which included the NightLedger backdoor and WebSocket tunneling tools ArcBridge and BridgeHead.…
-
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be…

