Related Threat Clusters
-
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Nearly 300 Fake GitHub Repositories Distributing BoryptGrab Malware
Since late June 2026, nearly 300 fake GitHub repositories have been created, impersonating well-known software brands to distribute malware. The malware, a variant of BoryptGrab, targets Windows systems and is designed…
2 articles · Updated July 16, 2026 -
Artlist Subdomain Compromised in ClickFix Campaign Using EtherHiding Technique
In July 2026, a ClickFix campaign was discovered on the Artlist subdomain new-blog.artlist[.]io, where attackers injected malicious code that masqueraded as a CAPTCHA to install a Remote Access Trojan (RAT). The attack…
33 articles · Updated July 14, 2026 -
Millenium RAT 4.*: Evolving Threat with Global Impact
The Millenium RAT, particularly version 4.*, has seen a significant rise in exploitation, affecting over 62,000 endpoints across 160 countries. This remote access trojan, now written in C++, utilizes the Telegram Bot…
3 articles · Updated June 25, 2026 -
Millenium RAT 4.* Enhances Stealth with Base64 and XOR Encryption
Millenium RAT version 4.* has evolved from .NET to native C++, utilizing a Telegram-based command-and-control model that eliminates the need for dedicated server infrastructure. The malware embeds its configuration in…
2 articles · Updated June 29, 2026 -
Curly COMrades Exploit Hyper-V for Covert Cyberespionage
The Russian APT group Curly COMrades is exploiting Microsoft's Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows 10 systems. This tactic allows them to evade endpoint security measures…
1 article · Updated November 5, 2025 -
Critical Vulnerabilities in Fortinet FortiWeb Actively Exploited
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…
74 articles · Updated November 28, 2025 -
Curly COMrades Exploit Hyper-V for Covert Malware Operations
The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain…
5 articles · Updated November 5, 2025
Recent Intelligence Reports
- Fake-GitHub-Repositories: Infostealer Instead of Security or Developer-Tools — www.heise.de · July 17, 2026
- Millenium RAT Uses Base64 and XOR Configuration to Hide Telegram C2 Settings — Gbhackers · June 29, 2026
- Millenium: A RAT Rewritten, A Threat Multiplied | Group — Group-Ib · June 25, 2026
- Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open — Trendmicro · June 9, 2026
- Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open — Trendmicro · June 8, 2026
- FortiWeb CVE‑2025‑64446: What We’re Seeing in the Wild — Greynoise · November 19, 2025
- Russian APT abuses Windows Hyper — Csoonline · November 5, 2025