Tag: group
-
What’s in a Name? The Quest to Understand Scattered Spider
Anarchic Western Adolescent Hacking Groups Appear to Defy Easy Categorization Some cybersecurity entities are groups, with office hours and vacation time. But others, such as Scattered Spider and other Com spinoffs, are largely comprised of adolescent hackers and extortionists, and often display more anarchic behavior that makes their efforts tougher to combat. First seen on…
-
OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration and Security
Melbourne, Florida, United States, July 8th, 2026, CyberNewswire OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop standards, policies and verification frameworks for secure autonomous AI systems and agentic computing environments. As organizations increasingly deploy AI agents…
-
Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip
An FBI tip linked a man living in Spain to the hacking groups CyberArmy of Russia Reborn (CARR), Z-Pentest and NoName057(16). First seen on therecord.media Jump to article: therecord.media/spain-arrest-alleged-supporter-noname-carr-zpentest
-
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT”‘C”‘20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM”‘hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective loading to run an obfuscated C# remote”‘control Trojan that communicates through the legitimate cloud storage…
-
CompassMSP acquires Logic Group
Tags: groupFirst seen on scworld.com Jump to article: www.scworld.com/brief/compassmsp-acquires-logic-group
-
Supreme Court allows Texas app law requiring age verification to take effect
A student advocacy organization and tech trade group had appealed to the high court to stay the Texas App Store Accountability Act on an emergency basis until the lower court rules. First seen on therecord.media Jump to article: therecord.media/supreme-court-allows-texas-app-law-age-verification-to-take-effect
-
Iran-linked MuddyWater espionage campaign targets organisations across four continents
A new threat intelligence report from WatchGuard is warning organisations worldwide to strengthen behavioural detection capabilities after uncovering an espionage campaign by the Iran-linked threat group MuddyWater that successfully targeted high-value organisations across four continents. The report details how the group, also known as Seedworm, targeted organisations across manufacturing, aviation, financial services, education, professional services…
-
Spain arrests suspected member of pro-Russian hacktivist groups
The National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/spain-arrests-suspected-member-of-pro-russian-hacktivist-groups/
-
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
A suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada and harvest user credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/china-aligned-cluster-roundcube/
-
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
A suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada and harvest user credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/china-aligned-cluster-roundcube/
-
Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang
Group-IB analysis argued Scattered Spider is a decentralized collective of independent clusters First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/scattered-spider-as-cybercrime/
-
UK cyber pledge draws only a handful of top firms despite ministerial appeal
Those that did sign include large firms such as Aviva, the London Stock Exchange Group and Marks & Spencer, which lost hundreds of millions of pounds in a cyberattack last year, as well as small cybersecurity consultancies. First seen on therecord.media Jump to article: therecord.media/uk-cyber-pledge-draws-limited-partners-despite-ministerial-appeal
-
Chinese Cyberespionage Exploits University Roundcube Servers
Campaign Combines XSS and Deserialization to Steal Credentials and Deploy Malware. Proofpoint identified a likely China-aligned espionage group exploiting chained Roundcube vulnerabilities to steal credentials and deploy persistent malware against U.S. and Canadian university departments conducting sensitive physics, engineering and national security research. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-cyberespionage-exploits-university-roundcube-servers-a-32165
-
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
Proofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. First seen on cyberscoop.com Jump to article: cyberscoop.com/china-espionage-attacks-us-canada-universities-proofpoint/
-
AI-Generated Malware Powers New Armored Likho APT Campaign
Armored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tracked under the name Eagle Werewolf. The group runs two parallel tracks: financially motivated attacks against private individuals…
-
Complaint urges ban on ‘unlawful’ Europol processing of personal data
Migration campaign group Front-Lex has filed a complaint to Europe’s data protection watchdog, calling for a ban on Europol’s data processing operations that do not comply with EU law, following an investigation by Computer Weekly, Solomon and Correctiv First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645384/Complaint-urges-ban-on-unlawful-Europol-processing-of-personal-data
-
Windows Device ID Helped Authorities Track Scattered Spider Hacking Group Member
Authorities used a persistent Windows Global Device ID, along with VPN telemetry and cloud service records, to connect the infrastructure used in a major extortion attack to a 19-year-old member of the Scattered Spider group, Peter Stokes. In a superseding criminal complaint filed in the Northern District of Illinois, the FBI outlines how Stokes, who…
-
Cavern Manticore Malware Uses Low-Detection .NET Modules for Reconnaissance and Lateral Movement
A newly identified Iran-linked threat group, tracked as Cavern Manticore, is deploying a sophisticated modular command-and-control (C2) framework built on a shared .NET foundation to conduct stealthy reconnaissance and lateral movement against Israeli government and IT organizations. The group’s custom C2 components exhibit extremely low detection rates on public sandboxes, enabling persistent access while evading…
-
US government agency pays $1 million to data extortion group Kairos
First seen on scworld.com Jump to article: www.scworld.com/brief/us-government-agency-pays-1-million-to-data-extortion-group-kairos
-
Canadian spy agency reports hacking three criminal groups in 2025
A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada’s Communications Security Establishment. First seen on therecord.media Jump to article: therecord.media/canada-cse-2025-cyber-operations-ransomware-drugs-extremism
-
‘BusySnake’ Infostealer Slithers into Critical Infrastructure Networks
A threat group researchers call Armored Likho has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/busysnake-infostealer-critical-infrastructure-networks
-
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations.The activity, which has primarily singled out IT providers and government sectors, has been attributed to a threat cluster tracked by Check Point Research First seen…
-
Vect and TeamPCP Cybercrime Groups Link for Ransomware Hits
Supply-Chain Victims Also at Risk From Poorly Coded, Data-Shredding Crypto-Locker. Recently announced tie-ups between ransomware group Vect, supply-chain attack specialists TeamPCP and data-leak stalwart Lapsus$ show cybercriminals continuing their quest to monetize their attacks and develop new profit streams. But not all has been smooth sailing. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/vect-teampcp-cybercrime-groups-link-for-ransomware-hits-a-32159
-
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Check Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’ First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-iran-hacking-group-targets/
-
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
ey Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig…
-
SilverFox Campaign Turns ValleyRAT Into Multi-Stage Malware With Rootkit Capabilities
The SilverFox advanced persistent threat (APT) group has escalated its offensive toolkit by transforming ValleyRAT from a conventional remote access trojan into an eight-stage malware chain culminating in a kernel-mode rootkit. This evolution marks a significant shift in post-exploitation persistence, blending user-mode orchestration with deep kernel control to evade detection and maintain long-term access. The…
-
The future of payment fraud could be automated
Payment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/06/key-payment-fraud-trends-report/
-
Medtronic Notifies 3.8 Million After ShinyHunters Data Breach
Medtronic says a ShinyHunters attack exposed the personal and medical data of over 3.8 million people. Products and operations were unaffected. Medtronic is notifying 3,834,294 individuals after a cyberattack by the ShinyHunters extortion group exposed personal and medical information. In April 2026, Medtronic confirmed a cyberattack on its corporate IT systems after the hacker group ShinyHunters claimed…
-
Security Affairs newsletter Round 584 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. Government Agency Paid $1M to Data Extortion Group Kairos FBI: TeamPCP Compromised Dev Tools to…
-
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Tags: blockchain, data, data-breach, extortion, government, group, ransom, ransomware, theft, threatA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment.…

