Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
Prinz Eugen Ransomware: Go-Based Encryptor Targets Recent Files, Leaves No Footprint
Threatdown's deep-dive analysis of Prinz Eugen reveals a Go-based ransomware encryptor that sorts files by modification date to hit active data first, uses ChaCha20-Poly1305 with Argon2id key derivation, and leaves no ransom note — while attribution points to a lone operator known as ROOTBOY behind breaches including Standard Bank's 1.2 TB data theft.
FBI and CISA Warn: Russian Hackers Target Signal Backup Keys
The FBI and CISA warn that Russian intelligence is phishing Signal users to steal Backup Recovery Keys, granting attackers permanent access to message archives.
Bluekit’s Browser-in-the-Middle Phishing Is Now a Living, Breathing Threat
Bluekit’s phishing-as-a-service platform has evolved from simple credential harvesting to a dynamic, adaptive browser-in-the-middle attack that bypasses detection by mimicking real user behavior — and it’s getting smarter every week.
NSO Group Keeps Coming: WhatsApp Disrupts New Spear-Phishing Push and Asks Court to Hold Them in Contempt
Meta says it disrupted NSO-linked spear-phishing attempts against WhatsApp users and is asking a federal judge to hold the Israeli spyware maker in contempt for violating a 2025 permanent injunction that bars it from targeting the platform.
The Trojan Horse in Your Brain: How Alzheimer’s Uses a Memory Protein to Spread
Researchers have uncovered that toxic Tau proteins hijack Arc-containing extracellular vesicles to spread between neurons, presenting a critical 'mid-flight' therapeutic target for slowing Alzheimer's disease progression.
AryStinger: The Silent Botnet Hijacking 4,000 Routers Worldwide
Qianxin’s XLab uncovers AryStinger—a previously unknown botnet that’s turned thousands of end-of-life D-Link routers into proxy nodes for scanning, tunneling, and traffic interception. Here’s what you need to know.
JDY Botnet: How a Reconnaissance Network Became the Eyes of China’s Cyber Offense
The JDY botnet, linked to Chinese threat actors like Volt Typhoon, has grown significantly, mapping global SOHO/IoT devices to target U.S. military networks for state-sponsored reconnaissance.
GreyVibe’s AI Lures Are Scary Because They’re Not Perfect
A likely Russian threat group tracked as GreyVibe is blending AI-generated phishing lures with crude malware — and that’s exactly why it’s dangerous.
Kali365 Operators Didn’t Just Survive the FBI—They Grew Stronger
Despite FBI warnings and takedown attempts, the operators of Kali365 have expanded their phishing-as-a-service platform, refining their MFA bypass techniques and scaling operations globally.
Hacking for Quality, Not Quantity: How AI Is Elevating Phishing Standards
Phishing volume is down 20% but losses tripled to $215M. Learn how AI-driven quality-over-quantity attacks are outpacing traditional email defenses.
Ghost CMS Got Hacked. Here’s How Your Blog Got Turned Into a Scam Page.
A massive campaign is weaponizing a patched SQLi flaw in Ghost CMS to hijack sites and trick visitors into installing malware via fake Cloudflare prompts.
How a Client-Controlled Byte Broke Check Point’s VPN — And Why Qilin Ransomware Won
A critical authentication bypass in Check Point’s legacy IKEv1 implementation allowed Qilin ransomware affiliates to gain unauthenticated access — and it wasn’t a zero-day exploit, it was an ignored warning.