Related Threat Clusters
-
Russian Drone Attack on Chernobyl's New Safe Confinement Raises Nuclear Safety Concerns
On February 14, 2025, a Russian drone struck the New Safe Confinement (NSC) at the Chernobyl Nuclear Power Plant, damaging its structure and raising alarms about potential radiation leaks. The NSC, designed to contain…
146 articles · Updated April 14, 2026 -
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…
12 articles · Updated August 7, 2026 -
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing
The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the…
5 articles · Updated July 30, 2026 -
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
Dragon Boss Solutions' Signed Adware Disables Antivirus on 25,000+ Endpoints
On March 22, 2026, Huntress identified a campaign involving signed adware from Dragon Boss Solutions LLC that disabled antivirus protections on over 23,500 endpoints across 124 countries. The software, marketed as…
7 articles · Updated April 15, 2026 -
Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool
The Smoke#Screen campaign exploits social engineering tactics to install the legitimate ScreenConnect RMM tool on compromised systems, providing attackers with remote access. Targeting both Windows and macOS, the…
8 articles · Updated August 4, 2026 -
LeakNet Ransomware Expands Tactics with ClickFix and Deno Loader
LeakNet, a ransomware group, has adopted new tactics involving ClickFix social engineering and a Deno-based fileless loader. This shift allows them to gain initial access through compromised websites, prompting users to…
7 articles · Updated March 18, 2026 -
MSHTA Utility Exploited in Ongoing Malware Campaigns
Bitdefender researchers have identified that the Microsoft HTML Application Host (MSHTA) utility is being actively exploited by cybercriminals to deliver a variety of malware, including infostealers and loaders. Despite…
8 articles · Updated May 19, 2026 -
Crazy Ransomware Gang Exploits Employee Monitoring Tools for Attacks
The Crazy ransomware gang has been observed exploiting legitimate employee monitoring software, specifically Net Monitor for Employees Professional, along with the SimpleHelp remote support tool. This tactic allows them…
13 articles · Updated February 11, 2026 -
Matanbuchus 3.0 Malware Analysis: New Features and Ransomware Links
Matanbuchus 3.0, a C++-based downloader offered as Malware-as-a-Service since 2020, was identified in July 2025. This version introduces Protobuf-based serialization, ChaCha20 encryption, and enhanced anti-analysis…
2 articles · Updated December 4, 2025
Recent Intelligence Reports
- Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs — Decrypt.Co · August 7, 2026
- Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook — Darkreading · August 4, 2026
- 115909 — securelist.ru · July 30, 2026
- Hackers Abuse ScreenConnect Remote Access Tool to Deploy AsyncRAT Through Fake Installers — Gbhackers · July 2, 2026
- Microsoft's MSHTA Legacy Tool Still Powers Malware Campaigns on Windows — Bitdefender · May 19, 2026
- When PUPs Grow Fangs: Dragon Boss Solutions' $10 Supply Chain Risk — Huntress · April 14, 2026
- LeakNet adopts ClickFix lures & Deno fileless loader — Securitybrief.Co.Nz · March 18, 2026
- Ransomware gang abuses legitimate software for network persistence — Scworld · February 13, 2026