Ursnif is a long-standing banking Trojan family known for credential theft and data exfiltration, often deployed via loaders and downloaders.
Ursnif is a long-standing banking Trojan family known for credential theft and data exfiltration, often deployed via loaders and downloaders. The recent reports tie Ursnif to attacks that abuse a Windows LNK shortcut vulnerability exploited as a zero-day, highlighting the threat's ongoing adaptation to Windows flaws and its relevance in current threat activity.
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
Ransomware operators are leveraging virtual machines (VMs) provided by ISPsystem to host and distribute malicious payloads. Cybersecurity researchers at Sophos identified this tactic during their investigation of recent…
A China-linked hacking group, UNC6384, has exploited a Windows zero-day vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks, which occurred in…
Microsoft has mitigated a high-severity Windows LNK vulnerability, tracked as CVE-2025-9491, which has been exploited by state-backed and cybercrime groups in zero-day attacks. This flaw allows attackers to hide…
The cybercriminal group TA584 has intensified its operations by deploying Tsundere Bot malware through ClickFix social engineering tactics. This initial access broker has significantly increased its campaign volume,…
A Chinese-linked hacking group, UNC6384, has been exploiting a Windows shortcut vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks involve spear…
Proofpoint reported a significant increase in activity from the cybercriminal group TA584 in 2025. The group is linked to initial access brokering and follow-on attacks, including ransomware and data theft, utilizing…