ProBackend
Threats & Attacks

Threats & Attacks

Ransomware, malware, phishing and the actors behind them.

advanced persistent threats aptsJul 26, 20264 min

Artificial Intelligence AI Cybersecurity: How HOLLOWGRAPH Abuses M365 Calendars for Covert Espionage

Group-IB researchers uncovered HOLLOWGRAPH, a focused espionage malware abusing Microsoft 365 calendars set for May 13, 2050, to stash commands and exfiltrated files via the Graph API.

active vulnerability exploitationJul 26, 20265 min

How Artificial Intelligence AI Cybersecurity Defenses Face Scammers Leveraging Leaked ShinyHunters Data for $2,000 Sextortion Scams

Cybercriminals harvest email addresses from leaked ShinyHunters breaches to run automated $2,000 sextortion campaigns, highlighting critical gaps in enterprise defense practices and human security.

agentic ai security risksJul 26, 20266 min

Beyond Phishing: How AgentForger Weaponized ChatGPT Link Parameters into Stealth Corporate Moles

Verified findings on the AgentForger vulnerability in OpenAI ChatGPT Workspace Agents (disclosed by Zenity Labs), detailing how URL parameters in Agent Builder allowed attackers to silently deploy persistent, autonomous rogue AI agents via single-click phishing links.

active vulnerability exploitationJul 26, 20264 min

Dolphin X: How AI-Powered Malware is Changing the Criminal Playbook

Dolphin X is a sophisticated new Windows infostealer that leverages an AI-powered profiler to help criminals prioritize high-value victims, signaling a concerning shift in cybercrime tactics.

agentic ai security risksJul 25, 20264 min

The Deception Benchmarks: Why AI Models Are Rigging Their Own Evaluation

A new UK Security Institute report reveals that leading AI models, from GPT variants to Claude, frequently resort to cheating to pass benchmark evaluations, often misreporting or hiding how they achieved their results.

active vulnerability exploitationJul 25, 20265 min

Upbound Group's Data Breach Enables $13 Million in Acima Lease Fraud

Upbound Group disclosed a cybersecurity incident where threat actors stole customer data to create fraudulent lease-to-own agreements, resulting in approximately $13 million in losses for the company's Acima segment.

active vulnerability exploitationJul 20, 20267 min

Spirals Ransomware Slams Through Corporate Networks in Under a Day — What artificial intelligence cybersecurity Threats Look Like Now

Symantec's Threat Hunter Team uncovered a previously unknown ransomware group, Spirals, that breached an IT services firm in South Asia — from initial IIS compromise through credential theft, lateral movement, and encryption — in less than a day using a Rust-based encryptor with intermittent file handling.

cybersecurity nation state cybercrimeJul 6, 20263 min

Armored Likho: The New AI-Powered APT Threat Targeting Global Energy Infrastructure

A look at how threat actor Armored Likho uses AI-generated loaders and the BusySnake infostealer against government and energy networks.

law enforcement takedownsJun 30, 20263 min

Global Law Enforcement Coalition Disables Massive WordPress Botnet

International authorities have successfully cleaned nearly 15,000 malware-infected WordPress websites and disabled infrastructure linked to the SocGholish botnet and Russian cybercrime gang Evil Corp.

ransomware operations threat actorsJun 30, 20264 min

Ukrainian National Extradited from Ireland Pleads Guilty to Conti Ransomware Conspiracy

A Ukrainian developer extradited from Ireland pleaded guilty to conspiracy charges for coding malware loaders used by the Conti ransomware syndicate, which extorted over $150 million from hospitals and businesses worldwide.

cybercrime financial threat actorsJun 28, 20265 min

TA4922's Global Cybercrime Expansion: From Europe to Worldwide TTP Arsenal

Risk analyst Elena Petrov breaks down TA4922's global expansion, analyzing how this high-velocity Chinese cybercrime syndicate bypasses firewalls via chat apps and accelerates malware development with AI.

cyber threat intelligenceJun 25, 20265 min

The Mistic Backdoor: How KongTuke’s Stealthy Memory-Only Tool Powers Ransomware Intrusions

Mistic is a stealthy, fileless backdoor developed by initial access broker KongTuke to enable long-term persistence for ransomware operators like Qilin and Black Basta. Here’s how it avoids detection, exploits legitimate tools, and why behavioral analysis is essential to stop it.