Tag: cybercrime
-
58 arrested in international cybercrime crackdown
Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe. First seen on therecord.media Jump to article: therecord.media/58-arrested-international-cybercrime-crackdown-interpol
-
Police arrests dozens of suspects in global cybercrime crackdown
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown/
-
Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo but instead deliver the Vidar information stealer. The campaign targets browser credentials, session cookies, and other profile data that can let attackers access accounts even after victims change their passwords. The…
-
The cybercrime supply chain has five stages, each with a price
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/cybercrime-supply-chain-video/
-
AnMed Confirms Data Theft, Warns Patients of Criminal Scams
Ransomware Gang Gentlemen Says It Stole 6TB of Sensitive Patient Info. Nonprofit health system AnMed has confirmed cybercriminals stole information in a July cyberattack that disrupted its IT environment and patient services for several weeks. The organization is also warning patients not to fall for potential fraud, payment and other scams by criminals. First seen…
-
Cybercriminals Turn GTA VI Leaks Into Malware Bait
A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to >>take one for the…
-
iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000 base price. The author also offers for sale additional capability modules separately. The headline feature is…
-
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an…
-
The Rise of Service-Centric Credential Compilations
How Cybercriminals Are Repackaging Infostealer Data Over the last year, the underground economy has undergone a significant transformation. Cybercriminals are no longer focused on distributing massive collections of raw infostealer logs, they are increasingly investing time in organizing and enriching stolen information into service-specific compilations. These datasets are no longer random collections of credentials extracted……
-
ShinyHunters Leaks 7.1 Million Baxter International Records
Gang Claims It Stole Medical Device Maker’s Salesforce Info Including Personal Data. Extortion gang ShinyHunters has struck the healthcare sector again. The notorious cybercriminal gang claims on its darkweb site of leaking 7.1 million Salesforce records stolen from medical device maker Baxter International, including personally identifiable information. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/shinyhunters-leaks-71-million-baxter-international-records-a-32630
-
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children, which was hit in a ransomware incident in 2022 that disabled some of its systems, released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application. First seen on therecord.media Jump to article: therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/money-and-mindset-the-two-biggest-roadblocks-to-cyber-policing
-
US man sentenced to 77 years for child sexual abuse tied to online extremist group
Kyle Spitze of Tennessee faced federal charges for targeting girls online as part of ‘764 network’ investigated by FBIA 27-year-old Tennessee man described by the US justice department as a “nihilistic violent extremist” was sentenced to 77 years in prison on Wednesday for his targeting of girls online as part of <a href=”https://www.theguardian.com/technology/ng-interactive/2026/jul/21/764-network-gamification-of-harm-the-com-cybercrime-ntwnfb”>the 764 network,…
-
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
-
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that…
-
Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School
Education has overtaken every other industry to become the most targeted sector for cyberattacks worldwide, according to new research from Check Point, with threat actors ramping up activity in the run-up to the new academic year. Between January and July 2026, schools, colleges, universities and research institutes faced an average of 4,696 weekly cyberattacks per…
-
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.”The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software…
-
659 Stripe Merchant API Keys Leaked Online, Exposing 688,000 Customer Records
A data leak published on a cybercrime data-trading forum has exposed live Stripe API credentials for 659 merchant accounts, along with approximately 35 GB of customer- and payment-related data. The exposure affects an estimated 688,363 customer records across merchants in 42 countries, but available evidence indicates that Stripe’s own infrastructure was not breached. The dataset…
-
Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to Campus
Every fall, school districts and universities across the country race to onboard thousands of new students, faculty and staff, provisioning accounts, issuing credentials and connecting a wave of new devices to institutional networks. It is a moment of organized chaos, and cybercriminals know it. Now, with artificial intelligence supercharging phishing campaigns and a hidden layer…
-
2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring
A newly identified cybercrime operation dubbed StopAndProtect has been quietly running its entire criminal infrastructure through close to 2,000 hacked WordPress websites, according to new research from Check Point. Rather than relying on dedicated command-and-control servers, which are relatively easy for defenders to identify and take down, the group behind StopAndProtect compromised thousands of legitimate…
-
Cybercriminals Turn to Indirect Prompt Injection Attacks
Cybercriminals are developing indirect prompt injection tools to target AI agents. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cybercriminals-turn-to-indirect-prompt-injection-attacks/
-
President Trump Signs Memo Expanding Private Sector Role in Offensive Cyber Operations
Trump’s cybercrime memo directs a federal program for vetted U.S. firms to conduct supervised operations against foreign criminal groups. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-trump-private-sector-offensive-cyber-operations-us/
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/

