ProBackend
Cyber Threat Intelligence

Cyber Threat Intelligence

Articles about cyber threat intelligence, APT groups, and nation-state malware campaigns

cyber threat intelligenceJun 29, 20265 min

Mini Shai-Hulud: The Python Startup Hook Powering the Hades Supply Chain Attack

How a tiny *-setup.pth file and the Bun JavaScript runtime became the delivery mechanism for one of 2026's most sophisticated PyPI poisoning campaigns — and why the Mini Shai-Hulud loader is now the default weapon for supply chain attackers.

cyber threat intelligenceJun 29, 20264 min

AryStinger: The Silent Botnet Hijacking 4,000 Routers Worldwide

Qianxin’s XLab uncovers AryStinger—a previously unknown botnet that’s turned thousands of end-of-life D-Link routers into proxy nodes for scanning, tunneling, and traffic interception. Here’s what you need to know.

cyber threat intelligenceJun 29, 20265 min

JDY Botnet: How a Reconnaissance Network Became the Eyes of China’s Cyber Offense

The JDY botnet, linked to Chinese threat actors like Volt Typhoon, has grown significantly, mapping global SOHO/IoT devices to target U.S. military networks for state-sponsored reconnaissance.

cyber threat intelligenceJun 28, 20265 min

How a Client-Controlled Byte Broke Check Point’s VPN — And Why Qilin Ransomware Won

A critical authentication bypass in Check Point’s legacy IKEv1 implementation allowed Qilin ransomware affiliates to gain unauthenticated access — and it wasn’t a zero-day exploit, it was an ignored warning.

cyber threat intelligenceJun 28, 20263 min

Unauthenticated Remote Code Execution in Fortinet FortiSandbox Under Active Exploitation by Threat Actors

Attackers are actively exploiting multiple critical vulnerabilities in Fortinet's FortiSandbox platform, including unauthenticated command injection flaws that allow remote code execution without user interaction.

cyber threat intelligenceJun 26, 20265 min

How Crypto Clipper Malware Hides Behind Tor's SOCKS5 Proxy to Steal Crypto Wallets

A deep dive into how the Crypto Clipper malware campaign uses a local SOCKS5 proxy at localhost:9050 to route all command-and-control traffic through Tor, evading traditional network defenses while stealing cryptocurrency seed phrases, private keys, and swapping wallet addresses.

cyber threat intelligenceJun 26, 20264 min

Your Bluetooth Speaker Just Became a Remote Code Execution Vector

A security flaw in the Sound Blaster Katana V2X lets attackers upload custom firmware and turn the speaker into a HID keyboard proxy, executing arbitrary commands on any connected PC from Bluetooth range.

cyber threat intelligenceJun 23, 20263 min

Contactless Card Harvesters: Inside the Latest NFCShare Android Campaigns Targeting European Banks

Security researchers have tracked the evolution of the NFCShare Android trojan, which has transitioned from localized campaigns to distributing malicious APK updates through GitHub repositories while employing anti-analysis tricks.

cyber threat intelligenceJun 23, 20264 min

Unmasking AryStinger: A New Threat to Outdated Network Hardware

Analyze the AryStinger botnet: learn how this malicious threat targets outdated D-Link routers, its operational techniques, and essential steps to secure your network hardware. (Keywords: AryStinger, botnet, D-Link, router security, malware infection, IoT security)

cyber threat intelligenceJun 22, 20264 min

Disguising Command-and-Control: How DragonForce Exploits Microsoft Teams Relays

An investigation into the techniques used by the DragonForce ransomware gang, specifically their utilization of a custom 'Backdoor.Turn' malware to tunnel malicious traffic through Microsoft Teams relay infrastructure. Includes verified attack chain details, BYOVD evasion techniques, and Backdoor.Turn capabilities from Symantec research.

cyber threat intelligenceJun 22, 20268 min

'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud

The latest Mini-Shai-hulud payload introduces Hades-themed GitHub exfiltration markers and AI analyst misdirection. TeamPCP compromised 19 PyPI packages (37 malicious wheels) via wheel startup hooks, deploying cross-platform memory scrapers and a token-revocation wiper. Read more about understanding supply chain risk in our Cyber Threat Intelligence category. Learn more about Supply Chain Security. Python Security Essentials.

cyber threat intelligenceJun 21, 20265 min

Unraveling the HTTP/2 Rapid Reset: A Threat to Large-Scale Web Infrastructure

This article explores the mechanics of CVE-2023-44487, commonly known as the HTTP/2 Rapid Reset vulnerability, and its severe impact on organizations with extensive, distributed web footprints.