Related Threat Clusters
-
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Critical Vulnerabilities in ConnectWise ScreenConnect Exploited in Active Attacks
ConnectWise ScreenConnect has been compromised by two critical vulnerabilities, CVE-2024-1708 and CVE-2024-1709, which allow attackers to bypass authentication and execute remote code. The vulnerabilities were disclosed…
9 articles · Updated April 29, 2026 -
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…
12 articles · Updated August 7, 2026 -
Formbook Malware Campaign Targets Organizations with Advanced Phishing Techniques
Two phishing campaigns have been identified targeting organizations in Greece, Spain, Slovenia, Bosnia, Croatia, and several South American countries, aiming to deliver the Formbook infostealer malware. The first…
2 articles · Updated April 21, 2026 -
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
8 articles · Updated July 20, 2026 -
Global Phishing Campaign Uses Lua Loader Disguised as TrueType Font Files
Since late March 2026, a large-scale phishing campaign has been observed utilizing disguised TrueType Font (.ttf) files to deliver Lua-based loaders and various malware, including Agent Tesla and Remcos. The attackers…
5 articles · Updated July 16, 2026 -
Microsoft Disrupts StegoAd Campaign with Malicious Edge Extensions
Microsoft has dismantled the StegoAd operation, removing 119 malicious Edge extensions that used steganography to hide malware within image and font files. The campaign, active since 2021, targeted over 2.6 million…
13 articles · Updated June 29, 2026 -
Phishing Campaign Distributes AsyncRAT, VenomRAT, and XWorm via Fake Invoice PDF
A phishing campaign has been identified that utilizes a fake invoice PDF to deliver multiple remote access trojans (RATs), primarily AsyncRAT, along with VenomRAT and XWorm. The attack begins with a phishing email…
2 articles · Updated July 2, 2026 -
Surge of Email-Borne Worms Targeting Industrial Control Systems
In Q4 2025, a significant increase in email-borne worms targeting industrial control systems (ICS) was reported, primarily driven by the XWorm backdoor. This malware spread through phishing emails, affecting operational…
2 articles · Updated April 17, 2026 -
Aeternum Botnet Leverages Polygon Smart Contracts for Resilience
The Aeternum botnet has emerged as a sophisticated loader that utilizes Polygon's blockchain to store its operational instructions, making it challenging to dismantle. This malware targets Windows systems via multiple…
2 articles · Updated August 14, 2026
Recent Intelligence Reports
- Aeternum Botnet Uses Polygon Smart Contracts for Takedown — Cybersecuritynews · August 14, 2026
- Microsoft Warns Hackers Are Using BNB Chain to Spread Malware — U.Today · August 6, 2026
- The Ttf Trap A Global Campaign Of A Low Detection Lua Loader — www.fortinet.com · July 21, 2026
- Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service — Proofpoint · July 20, 2026
- Cruciferra Crypter Uses Process Ghosting to Evade Detection — Infosecurity-Magazine · July 20, 2026
- Fake TTF files deliver stealthy malware in global phishing campaign — Csoonline · July 17, 2026
- Phishing Campaign Hides Lua Loader as TrueType Font File — Infosecurity-Magazine · July 16, 2026
- Phishing Campaign Uses Fake Invoice PDF to Drop AsyncRAT, VenomRAT, and XWorm — Gbhackers · July 2, 2026