Related Threat Clusters
-
Slovakia Discovers Russian Backdoor in Traffic Speed Cameras
Slovakia's national security service NBU has issued a security alert regarding NERO R-ONE high-speed traffic cameras, which were found to contain a backdoor allowing access via SMS from hardcoded Russian phone numbers.…
4 articles · Updated August 19, 2026 -
Malware Campaign Disables Windows Update in Corporate China
Microsoft detected an active malware campaign targeting corporate systems in China, where attackers use fake software download sites to distribute malware that disables Windows Update and weakens Microsoft Defender. The…
3 articles · Updated September 3, 2026 -
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is…
10 articles · Updated August 13, 2026 -
Critical Vulnerabilities Discovered in Apache OFBiz Affecting All Versions Pre-24.09.06
Apache OFBiz has critical vulnerabilities that allow attackers to exploit hardcoded keys and bypass authentication. The vulnerabilities, CVE-2026-31986 and CVE-2026-45434, were published on 2026-05-19 and affect all…
3 articles · Updated May 21, 2026 -
Chaos Malware Variant Targets Misconfigured Linux Cloud Servers
A new variant of Chaos malware, originally targeting routers, has been observed exploiting misconfigured Linux cloud servers. This development was documented by Darktrace's CloudyPots program, which captures attacker…
3 articles · Updated April 8, 2026 -
Silver Fox Targets Japanese Firms with Spearphishing During Tax Season
The Silver Fox cyber threat group is conducting a targeted spearphishing campaign against Japanese businesses, particularly manufacturers, during the annual tax filing and corporate restructuring season. The attackers…
8 articles · Updated March 26, 2026 -
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
8 articles · Updated July 20, 2026 -
Active Malware Campaign Distributes VBScript via Compromised WhatsApp Accounts
In June 2026, a malware campaign was identified that spreads malicious VBScript files through WhatsApp direct messages. The campaign primarily targets users of WhatsApp Desktop and WhatsApp Web, with the highest number…
29 articles · Updated June 22, 2026 -
SilverFox Expands ValleyRAT with Kernel-Mode Rootkit in New Campaign
The SilverFox APT group has upgraded its ValleyRAT malware into a sophisticated eight-stage malware chain, culminating in a kernel-mode rootkit. This evolution enhances post-exploitation persistence and evasion…
2 articles · Updated July 6, 2026 -
Silver Fox APT Campaign Distributes ValleyRAT via Fake Telegram Installer
A new malware campaign linked to the Silver Fox APT group has been identified, utilizing a fake Chinese language pack installer for Telegram to deliver ValleyRAT, a sophisticated remote access trojan. The malicious MSI…
2 articles · Updated April 9, 2026
Recent Intelligence Reports
- ValleyRAT se distribuye oculto en software chino firmado — Ciberseguridadlatam · September 1, 2026
- ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool — Securityaffairs.Co · August 31, 2026
- Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India — Cybersecuritynews · August 31, 2026
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — Thehackernews · August 31, 2026
- ValleyRAT masquerading as adware — Securelist · August 31, 2026
- Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras — News.Risky.Biz · August 19, 2026
- 120038 — securelist.com · August 13, 2026
- Cruciferra Crypter Uses Process Ghosting to Evade Detection — Infosecurity-Magazine · July 20, 2026