ProBackend
Threats & Attacks

Threats & Attacks

Ransomware, malware, phishing and the actors behind them.

cloud security incidentsJun 30, 20265 min

Undocumented SprySOCKS Windows Backdoors Reveal FishMonger's Expanded Espionage Reach

FishMonger expands operations by deploying undocumented Windows variants of the SprySOCKS backdoor against government targets using kernel stealth and spooler abuse.

social engineering phishingJun 30, 20265 min

When Malware Wears a Halo: The New Era of Reputation Hijacking in Crypto Attacks

How attackers weaponize GitHub, YouTube, and VirusTotal to build false trust for crypto clipboard hijackers — and what defenders can do about it.

cloud security incidentsJun 30, 20265 min

Ghost-Sender: How a Common Exchange Setup Lets Attackers Impersonate Anyone

A widespread Microsoft Exchange misconfiguration allows attackers to spoof any email address—bypassing SPF, DKIM, and DMARC protections—and evidence suggests the flaw is being actively exploited in the wild.

mfa bypass authentication attacksJun 30, 20267 min

Autonomous Defenders: Reframing the Phishing Threat for AI-Native Operating Systems

With the rise of AI-native operating systems and autonomous agentic workflows, the frontline against social engineering cyberattacks is migrating away from the individual employee. Instead of training humans to spot deceptive lures, the security burden is shifting to the OS and AI assistants themselves, exposing new architectural vulnerabilities like prompt injection, dynamic skill hijacking, and untrusted execution contexts.

cloud security incidentsJun 30, 20264 min

Legacy D-Link Routers Harnessed by Undocumented AryStinger Botnet for Malicious Proxy Operations

Qianxin researchers discovered AryStinger, a botnet exploiting CVE-2013-3307 and CVE-2016-5681 to turn outdated D-Link routers into proxy executors for scanning, DNS hijacking, and traffic interception.

ai platform abuse social engineeringJun 30, 20264 min

The ChatGPT Outage Scam That Actually Lives Inside ChatGPT

Malicious actors exploit ChatGPT's content-sharing feature to host fake OpenAI outage pages, tricking users into downloading malware disguised as the ChatGPT desktop app in a campaign dubbed LLMShare.

android malware threatsJun 30, 20268 min

No-Code Android RAT Lets Cybercriminals Build Custom Phishing Payloads for Device Takeover

BTMOB is a malware-as-a-service Android remote access trojan evolved from the SpySolr family, sold with an APK builder that lets buyers generate custom payloads and localized phishing lures without coding. Priced at $5,000 for a lifetime license plus monthly support, the RAT abuses Android Accessibility Services to escalate privileges and exfiltrate data, capture screenshots, record audio, and take full remote control of infected devices. First documented by Cyble in February 2025 and analyzed extensively by ESET in May 2026, BTMOB is primarily active across Brazil and Latin America but poses a growing regional threat.

data breach incident responseJun 30, 20264 min

Ransomware Ecosystem Realigns as European Markets Become Prime Targets

Ransomware gangs, once focused heavily on the US, are increasingly shifting their attention to European organizations and their broader supply chains, leveraging automation and exploiting new vulnerabilities in the region.

ai built ransomware edr bypassJun 30, 20265 min

AI Built This Ransomware Toolkit—And It’s Learning Faster Than Your EDR

Sophos researchers uncovered a ransomware attack framework whose tool and payload development was assisted by Cursor and Claude Opus AI agents — generating nearly 80 evasion modules tested against Sophos, CrowdStrike, and Microsoft Defender EDR solutions.

cloud security incidentsJun 30, 20264 min

Kodak Brings in Cyber Experts After Extortion Gang Says It Stole 2.2 Million Records

Kodak has confirmed a security breach and brought in external cybersecurity experts to investigate after the ShinyHunters extortion gang claimed responsibility for stealing over 2.2 million customer and corporate records, threatening to publish the data.

cyber threat intelligenceJun 22, 20263 min

AryStinger Botnet Hijacks 4,000+ Routers as Malicious Proxy Network

Previously undocumented malware botnet AryStinger has compromised thousands of outdated D-Link routers worldwide, converting them into remotely controlled 'executors' for scanning, proxying, and command execution activities.

ai psychologyJun 22, 20264 min

AI Voice-Cloning Scams: How Vocal Timbre Bypasses Human Skepticism

A new study reveals that AI voice-cloning scams are highly persuasive because they weaponize vocal timbre to bypass human critical skepticism and force compliance.