Related Threat Clusters
-
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware
A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…
7 articles · Updated July 4, 2026 -
JDownloader Website Compromised to Distribute Malware to Users
The JDownloader website was hacked between May 6 and May 7, 2026, to serve malicious installers for Windows and Linux users. Attackers replaced legitimate download links with malicious payloads, specifically targeting…
11 articles · Updated May 9, 2026 -
ProxySmart Software Powers Global SIM Farm Cybercrime Operations
Infrawatch's investigation reveals that ProxySmart, a Belarus-based software platform, is enabling the operation of 87 SIM farms across 17 countries, including 94 locations in the U.S., Europe, and South America. These…
6 articles · Updated April 22, 2026 -
TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations
A new Python-based malware framework named TwinLoot has been discovered, utilizing Microsoft Azure and 365 services for its command-and-control (C2) operations. Researchers from Ontinue Cyber Defense Center identified…
8 articles · Updated August 18, 2026 -
VVS Stealer Malware Targets Discord Accounts with Python Code
VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…
7 articles · Updated January 5, 2026 -
VVS Stealer Malware Targets Discord Users with PyArmor Obfuscation
VVS Stealer, a Python-based malware family, has been marketed on Telegram since April 2025. This malware specifically targets Discord users to exfiltrate sensitive credentials, tokens, and browser data while utilizing…
3 articles · Updated January 3, 2026
Recent Intelligence Reports
- Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud — Darkreading · August 18, 2026
- New APT Group Hits Power Grids in Three Countries with AI-Crafted Malware — Techtimes · July 4, 2026
- JDownloader Website Supply Chain Attack: Installers Replaced with Python RAT Malware ... — Rescana · May 10, 2026
- JDownloader site hacked to replace installers with Python RAT malware — Bleepingcomputer · May 9, 2026
- Inside The Mobile Farm The Oem Stack Powering Us 4g 5g Proxy Networks — infrawatch.com · April 22, 2026
- Researchers Uncover ProxySmart Software Powering 90+ SIM Farms — Infosecurity-Magazine · April 22, 2026
- VVS Stealer: PyInstaller Malware Steals Discord Tokens — Socprime · January 5, 2026
- VVS Stealer Uses Advanced Obfuscation to Target Discord Users — Infosecurity-Magazine · January 5, 2026