Tag: group
-
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
Tags: blockchain, breach, data, data-breach, extortion, government, group, ransom, ransomware, theftA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left.The odd part: the group that took the money calls itself Kairos, but it may not be…
-
Armored Likho APT Deploys BusySnake Stealer Against Government and Power Sector Targets
A focused phishing campaign operated by a previously unreported APT we’ve named Armored Likho (also tracked under the provisional alias Eagle Werewolf). The group is targeting government agencies and the electric power sector across Russia, Brazil and Kazakhstan, and demonstrates an evolving toolkit that blends commodity and bespoke tooling to support both financially motivated operations…
-
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The…
-
Pegasus Used Against MEP Investigating Pegasus, Citizen Lab Finds
A former EU lawmaker was hacked with Pegasus spyware while investigating its use, according to Citizen Lab. The Citizen Lab published a report documenting one of the more darkly ironic findings in recent surveillance research: former Member of the European Parliament Stelios Kouloglou was repeatedly infected with NSO Group’s Pegasus spyware while serving on the…
-
FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets
Tags: access, advisory, attack, cloud, cyber, cybercrime, exploit, group, kubernetes, software, supply-chain, updateThe Federal Bureau of Investigation (FBI) has issued an urgent FLASH advisory warning that the cybercriminal group TeamPCP is weaponizing trojanized software updates to harvest cloud access tokens, SSH keys, and Kubernetes secrets at scale. This campaign represents one of the most sophisticated software supply chain attacks observed in 2026, exploiting trust in widely deployed…
-
Politician who investigated spyware abuses had his phone hacked with Pegasus spyware
A government customer of NSO Group used the company’s Pegasus spyware to hack into the phone of a European politician, who at the time was serving on an EU committee tasked with investigating the spyware industry. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/02/politician-who-investigated-spyware-abuses-had-his-phone-hacked-with-pegasus-spyware/
-
Someone infected a spyware probe overseer with spyware
Citizen Lab says the phone of a member of Europe’s PEGA Committee was infected twice with Pegasus, the NSO Group spyware that gave the panel its name. First seen on cyberscoop.com Jump to article: cyberscoop.com/pegasus-spyware-pega-committee-member-targeted/
-
Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks
Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026. This action is part of an ongoing campaign to…
-
FortiBleed Hacks Tied to INC Ransom and Lynx Operation
Theat Actor Accessed INC and Lynx Ransom Negotiation Panels. SOCRadar linked the FortiBleed credential-harvesting operation to ransomware groups INC Ransom and Lynx, citing evidence that a sophisticated initial access broker compromised more than 430,000 FortiGate firewalls, prioritized high-value organizations and enabled ransomware attacks against governments, critical infrastructure and major enterprises. First seen on govinfosecurity.com Jump…
-
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
Google has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people’s traffic.Working with the FBI, Lumen, and others, Google’s Threat Intelligence Group (GTIG) said this week it had reduced the network’s pool of usable devices by millions.Google identifies NetNut, also tracked as Popa, as a network…
-
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Tags: access, citrix, credentials, exploit, group, monitoring, ransomware, supply-chain, tactics, threat, vulnerabilityThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.”Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral First seen on thehackernews.com Jump to…
-
Scattered Spider Suspect Extradited From Finland to US
FBI Says Peter Stokes, 19, ‘Exhibited Substantial Wealth for a Person of His Age’. A suspected member of the notorious Scattered Spider cybercrime group has been extradited from Finland to stand trial in the United States. Peter Stokes, 19, a dual U.S.-Estonian citizen, faces a six-count indictment, including an attempted $8 million shakedown of a…
-
Phishing Campaign Uses Fake Invoice PDF to Drop AsyncRAT, VenomRAT, and XWorm
A sophisticated phishing campaign that uses a fake invoice PDF to mask the delivery of multiple remote access trojans primarily AsyncRAT, but also VenomRAT and XWorm via layered shortcuts. TryCloudflare quick tunnels, and disguised Python packages. The campaign echoes an August attack previously analysed by X”‘Labs and reinforces the group’s 2025 Future Insights prediction that…
-
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.”An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment First seen on thehackernews.com Jump to…
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…
-
Scattered Spider Hacker Arrested in Finland and Extradited to U.S. Over Cyber Intrusion Charges
U.S. authorities have announced federal charges against an alleged member of the notorious cybercriminal group Scattered Spider, following his arrest in Finland and extradition to the United States. The defendant, identified as 19-year-old Peter Stokes, a dual national of the U.S. and Estonia, is accused of participating in a widespread conspiracy involving cyber intrusions and…
-
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1.Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on June 30, where a judge…
-
Eric Brabänder übernimmt die Geschäftsführung von Empolis
Der führende Anbieter für KI-basiertes Wissensmanagement im industriellen Bereich und Teil der Proalpha Group, Empolis Information Management, vollzieht einen Wechsel an der Unternehmensspitze. Zum 1. Juli 2026 übernimmt Eric Brabänder die Unternehmensleitung von Andreas Klüter. Brabänder, seit 2018 Mitglied der Geschäftsleitung, führt Empolis in einer Phase, in der KI-basiertes Wissensmanagement für die Industrie zunehmend an…
-
Infinigate beruft Kai Grunwitz zum Chief Growth Officer
Die Infinigate Group, führende Technologieplattform und Trusted-Advisor in den Bereichen Cybersicherheit, Cloud und Netzwerkinfrastruktur, hat Kai Grunwitz zum Chief Growth Officer (CGO) ernannt. Damit unterstreicht der Value-Added-Distributor sein Ziel, die Wachstumsstrategie weiter zu skalieren und den Mehrwert für Hersteller und Channel-Partner zu steigern. Als CGO wird Grunwitz die zentralen Wachstumsfelder des Unternehmens verantworten: die Stärkung…
-
ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts
ToddyCat, an advanced persistent threat group long associated with targeted espionage against corporate environments, has evolved its toolkit to exploit OAuth-based authorization flows and compromise Gmail accounts without directly stealing credentials. Umbrij is deployed on Windows hosts using DLL sideloading: attackers place a malicious DLL alongside legitimately signed executables known to insecurely load libraries (examples…
-
The Gentlemen Ransomware Targets Large Corporations and Critical Infrastructure Worldwide
The Gentlemen ransomware group has emerged in 2026 as a highly adaptive and technically sophisticated ransomware-as-a-service (RaaS) operation targeting large corporations and critical infrastructure across multiple regions. Public reporting places The Gentlemen among the top 10 ransomware actors by victim announcements on its data leak site during the first half of 2026 (see ransomware.live/stats/2026), and…
-
Gamaredon group expands malware arsenal in ongoing Ukraine cyberattacks
First seen on scworld.com Jump to article: www.scworld.com/brief/gamaredon-group-expands-malware-arsenal-in-ongoing-ukraine-cyberattacks
-
China-Linked Group Targets Southeast Asia Critical Systems
The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/china-linked-group-targets-southeast-asia-critical-systems
-
Kremlin Expands AI-Backed Campaigns Across Europe, US
GenAI Is Accelerating Propaganda, Planning and Content Creation. Google Threat Intelligence Group says Russia is expanding AI-enabled influence operations beyond Ukraine to target the European Union and NATO, relying on proxy networks, hacktivists and coordinated cyber campaigns to undermine Western cohesion while reducing attribution. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/google-kremlin-expands-ai-backed-campaigns-across-europe-us-a-32120
-
$10 Million Reward for Russian Hackers Targeting Messaging App Users
The U.S. Department of State is offering up to $10 million for information on Russian-linked groups UNC5792 and UNC4221. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/10-million-reward-for-russian-hackers-targeting-messaging-app-users/
-
US offers $10 million for info on group behind Signal and WhatsApp hacking spree
Operation by two Russia-state groups has been ongoing since at least March. First seen on arstechnica.com Jump to article: arstechnica.com/information-technology/2026/06/us-offers-10-million-for-info-on-group-behind-signal-and-whatsapp-hacking-spree/
-
U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks
The U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists. The U.S. government is offering rewards of up to $10 million for information leading to the identification of members of the Russian-linked groups UNC5792 and UNC4221. The hackers target government officials, military personnel, journalists, and…
-
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach
The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/
-
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel.Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with First seen on thehackernews.com Jump…
-
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
Russia-linked hacking groups tracked as UNC5792 and UNC4221 have socially engineered their way into the messaging accounts of government officials. First seen on therecord.media Jump to article: therecord.media/10million-reward-us-russian-hackers-unc4221-unc5792

