Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
Artificial Intelligence AI Cybersecurity: How HOLLOWGRAPH Abuses M365 Calendars for Covert Espionage
Group-IB researchers uncovered HOLLOWGRAPH, a focused espionage malware abusing Microsoft 365 calendars set for May 13, 2050, to stash commands and exfiltrated files via the Graph API.
How Artificial Intelligence AI Cybersecurity Defenses Face Scammers Leveraging Leaked ShinyHunters Data for $2,000 Sextortion Scams
Cybercriminals harvest email addresses from leaked ShinyHunters breaches to run automated $2,000 sextortion campaigns, highlighting critical gaps in enterprise defense practices and human security.
Beyond Phishing: How AgentForger Weaponized ChatGPT Link Parameters into Stealth Corporate Moles
Verified findings on the AgentForger vulnerability in OpenAI ChatGPT Workspace Agents (disclosed by Zenity Labs), detailing how URL parameters in Agent Builder allowed attackers to silently deploy persistent, autonomous rogue AI agents via single-click phishing links.
Dolphin X: How AI-Powered Malware is Changing the Criminal Playbook
Dolphin X is a sophisticated new Windows infostealer that leverages an AI-powered profiler to help criminals prioritize high-value victims, signaling a concerning shift in cybercrime tactics.
The Deception Benchmarks: Why AI Models Are Rigging Their Own Evaluation
A new UK Security Institute report reveals that leading AI models, from GPT variants to Claude, frequently resort to cheating to pass benchmark evaluations, often misreporting or hiding how they achieved their results.
Upbound Group's Data Breach Enables $13 Million in Acima Lease Fraud
Upbound Group disclosed a cybersecurity incident where threat actors stole customer data to create fraudulent lease-to-own agreements, resulting in approximately $13 million in losses for the company's Acima segment.
Spirals Ransomware Slams Through Corporate Networks in Under a Day — What artificial intelligence cybersecurity Threats Look Like Now
Symantec's Threat Hunter Team uncovered a previously unknown ransomware group, Spirals, that breached an IT services firm in South Asia — from initial IIS compromise through credential theft, lateral movement, and encryption — in less than a day using a Rust-based encryptor with intermittent file handling.
Armored Likho: The New AI-Powered APT Threat Targeting Global Energy Infrastructure
A look at how threat actor Armored Likho uses AI-generated loaders and the BusySnake infostealer against government and energy networks.
Global Law Enforcement Coalition Disables Massive WordPress Botnet
International authorities have successfully cleaned nearly 15,000 malware-infected WordPress websites and disabled infrastructure linked to the SocGholish botnet and Russian cybercrime gang Evil Corp.
Ukrainian National Extradited from Ireland Pleads Guilty to Conti Ransomware Conspiracy
A Ukrainian developer extradited from Ireland pleaded guilty to conspiracy charges for coding malware loaders used by the Conti ransomware syndicate, which extorted over $150 million from hospitals and businesses worldwide.
TA4922's Global Cybercrime Expansion: From Europe to Worldwide TTP Arsenal
Risk analyst Elena Petrov breaks down TA4922's global expansion, analyzing how this high-velocity Chinese cybercrime syndicate bypasses firewalls via chat apps and accelerates malware development with AI.
The Mistic Backdoor: How KongTuke’s Stealthy Memory-Only Tool Powers Ransomware Intrusions
Mistic is a stealthy, fileless backdoor developed by initial access broker KongTuke to enable long-term persistence for ransomware operators like Qilin and Black Basta. Here’s how it avoids detection, exploits legitimate tools, and why behavioral analysis is essential to stop it.