Threats & Attacks
Ransomware, malware, phishing and the actors behind them.
FBI Warns: Hackers Are Walking Into Law Firms to Steal Data — No Malware Needed
The FBI’s May 27, 2026 flash alert reveals the Silent Ransom Group is bypassing malware entirely, sending actors in person to insert USB drives into law firm computers after remote social engineering fails.
How Crypto Clipper Malware Hides Behind Tor's SOCKS5 Proxy to Steal Crypto Wallets
A deep dive into how the Crypto Clipper malware campaign uses a local SOCKS5 proxy at localhost:9050 to route all command-and-control traffic through Tor, evading traditional network defenses while stealing cryptocurrency seed phrases, private keys, and swapping wallet addresses.
Boring and Brutal: How Russia's Gamaredon Scaled Its Spear-Phishing Pipeline
Analysis of ESET's 2025 report on the Gamaredon APT group: their downloader development, infrastructure obfuscation, and strategic collaborations.
The Digital Scalpel: Dr. Mehmet Oz Employs AI to Target Medicare Fraud
An in-depth look at Dr. Mehmet Oz's AI-powered strategy to modernize fraud prevention at CMS.
Fake Security Verification Frameworks Abuse Native macOS Utilities to Execute Hidden Infostealers
An in-depth analysis of the macOS ClickFix campaign, which leverages system commands to bypass manual interaction by silently downloading, mounting, and launching the Atomic macOS Stealer (AMOS), highlighting how the threat landscape is evolving to bypass user and OS boundaries.
Operation Endgame: Law Enforcement Seizes Control of SocGholish Malware infrastructure From Nearly 15,000 WordPress Sites
A sweeping international operation dismantled the SocGholish malware distribution network, cleaning 14,971 compromised WordPress sites and disabling over 100 servers tied to Evil Corp—marking a pivotal moment in the multi-year Operation Endgame campaign against global cybercrime.
How a Developer Token Compromise Sparked a Global Pharma Data-Extortion Crisis
Novo Nordisk recent massive data breach: Investigating the impact of a developer token compromise on pharma data security, research, and manufacturing.
WordPress Compromise Fuels Vice Society Ransomware Delivery
A new malware campaign is leveraging compromised WordPress sites and 'ClickFix' tactics to deploy threats linked to the ransomware group Vice Society.
The JDY Botnet: A Malware Network Expanding Its Targeting Scope
The JDY botnet, previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts to include US military networks.
Android Malware Campaign: Fake Banking Updates Distribute NFCShare on GitHub
A coordinated campaign distributes the NFCShare Android malware via fake banking app updates on GitHub, targeting European financial institution customers to harvest payment card information through NFC data extraction.
Chinese Espionage Group UNC5221 Deploys Brickstorm Backdoor to Maintain Persistent Access to Microsoft 365 Environments
Analysis of UNC5221's Brickstorm backdoor campaign targeting Microsoft 365 environments, including technical details, attribution to Chinese APT groups (APT31, APT41), and defensive recommendations for enterprise security teams. Also covers related incidents including the Fortinet credential harvesting campaign affecting 30K devices.
C0XMO Botnet Spreads via DD-WRT Router Flaw, Kills Rival Malware
A new variant of the Gafgyt botnet called C0XMO targets DD-WRT router firmware and can move to other device types with various CPU architectures. Fortinet researchers discovered the botnet's modular design and sophisticated capabilities including 19 DDoS methods, lateral movement via brute-force attacks, and anti-competitor mechanisms that kill rival malware.