ProBackend
Threats & Attacks

Threats & Attacks

Ransomware, malware, phishing and the actors behind them.

ransomware extortion tacticsJun 28, 20263 min

FBI Warns: Hackers Are Walking Into Law Firms to Steal Data — No Malware Needed

The FBI’s May 27, 2026 flash alert reveals the Silent Ransom Group is bypassing malware entirely, sending actors in person to insert USB drives into law firm computers after remote social engineering fails.

cyber threat intelligenceJun 26, 20265 min

How Crypto Clipper Malware Hides Behind Tor's SOCKS5 Proxy to Steal Crypto Wallets

A deep dive into how the Crypto Clipper malware campaign uses a local SOCKS5 proxy at localhost:9050 to route all command-and-control traffic through Tor, evading traditional network defenses while stealing cryptocurrency seed phrases, private keys, and swapping wallet addresses.

ai national securityJun 26, 20264 min

Boring and Brutal: How Russia's Gamaredon Scaled Its Spear-Phishing Pipeline

Analysis of ESET's 2025 report on the Gamaredon APT group: their downloader development, infrastructure obfuscation, and strategic collaborations.

health aiJun 24, 20264 min

The Digital Scalpel: Dr. Mehmet Oz Employs AI to Target Medicare Fraud

An in-depth look at Dr. Mehmet Oz's AI-powered strategy to modernize fraud prevention at CMS.

ai agent security safetyJun 24, 20265 min

Fake Security Verification Frameworks Abuse Native macOS Utilities to Execute Hidden Infostealers

An in-depth analysis of the macOS ClickFix campaign, which leverages system commands to bypass manual interaction by silently downloading, mounting, and launching the Atomic macOS Stealer (AMOS), highlighting how the threat landscape is evolving to bypass user and OS boundaries.

law enforcement takedownsJun 23, 20266 min

Operation Endgame: Law Enforcement Seizes Control of SocGholish Malware infrastructure From Nearly 15,000 WordPress Sites

A sweeping international operation dismantled the SocGholish malware distribution network, cleaning 14,971 compromised WordPress sites and disabling over 100 servers tied to Evil Corp—marking a pivotal moment in the multi-year Operation Endgame campaign against global cybercrime.

cloud security incidentsJun 22, 20265 min

How a Developer Token Compromise Sparked a Global Pharma Data-Extortion Crisis

Novo Nordisk recent massive data breach: Investigating the impact of a developer token compromise on pharma data security, research, and manufacturing.

cyber threat intelligenceJun 22, 20264 min

WordPress Compromise Fuels Vice Society Ransomware Delivery

A new malware campaign is leveraging compromised WordPress sites and 'ClickFix' tactics to deploy threats linked to the ransomware group Vice Society.

cyber threat intelligenceJun 19, 20263 min

The JDY Botnet: A Malware Network Expanding Its Targeting Scope

The JDY botnet, previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts to include US military networks.

cybersecurityJun 18, 20264 min

Android Malware Campaign: Fake Banking Updates Distribute NFCShare on GitHub

A coordinated campaign distributes the NFCShare Android malware via fake banking app updates on GitHub, targeting European financial institution customers to harvest payment card information through NFC data extraction.

cloud security incidentsJun 18, 20264 min

Chinese Espionage Group UNC5221 Deploys Brickstorm Backdoor to Maintain Persistent Access to Microsoft 365 Environments

Analysis of UNC5221's Brickstorm backdoor campaign targeting Microsoft 365 environments, including technical details, attribution to Chinese APT groups (APT31, APT41), and defensive recommendations for enterprise security teams. Also covers related incidents including the Fortinet credential harvesting campaign affecting 30K devices.

cybersecurityJun 18, 20266 min

C0XMO Botnet Spreads via DD-WRT Router Flaw, Kills Rival Malware

A new variant of the Gafgyt botnet called C0XMO targets DD-WRT router firmware and can move to other device types with various CPU architectures. Fortinet researchers discovered the botnet's modular design and sophisticated capabilities including 19 DDoS methods, lateral movement via brute-force attacks, and anti-competitor mechanisms that kill rival malware.