Search/telegram
Vendor

telegram

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
web
Connections
844 relationships
Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers
Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers Russian software developer Microolap confirmed that hackers had compromised some of its systems but denied claims that they gained access to its network monitoring platform or stole data belonging to major Russian companies. Microolap, which develops software for intercepting and analyzing network traffic, said Thursday that it had detected an attempted breach of several non-critical systems but found no evidence that hackers accessed its core infrastructure, customer data or other sensitive information. "We urge people not to treat the attackers' claims as fact," Microolap CEO Andrey Smirnov said. "Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure." The statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform. The hackers claimed they extracted and deleted data belonging to several Microolap customers, including Russian Railways, state banknote and document producer Goznak, VTB Bank and its leasing subsidiary, and Russian IT company NEK.TECH. The group published several screenshots that it said showed compromised systems and data obtained during the intrusion. The authenticity of the images could not be independently verified. Microolap acknowledged that some of its systems had been compromised but rejected the hackers’ account of the scope of the attack. The company said its investigation found that the hackers accessed several rarely used development systems hosted by another Russian provider, an outdated version of its website and an old Bitrix24 customer management system containing a limited amount of data. The affected systems were isolated from Microolap's core infrastructure, and their compromise did not give the attackers access to EtherSensor or data belonging to customers and partners, the company added. Microolap said none of its production systems or components critical to EtherSensor were affected. The platform continued to operate normally, and the incident had no impact on its performance, data integrity or availability, it added. Microolap said it had taken its outdated website offline, introduced additional security measures and was investigating the incident with the help of "one of Russia's largest cybersecurity companies," which it did not name. Black Spark describes itself as an "underground movement in Russia." In a manifesto published on Telegram, the group said its members had remained in Russia and chosen what it called "armed resistance." Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaAug 21, 2026extracted
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. The operation ran for at least 35 days between June 17 and July 22, compromising devices by exploiting vulnerabilities, brute-forcing logins, and using offline recovery codes from serial numbers for cloud-registered cameras. Researchers at threat intelligence company Hunt.io discovered the campaign after finding a working directory on an HTTP server that the operator left unprotected. Hunt.io recovered 407 MB of data comprising 2,616 files across 234 directories, including source code, logs, credentials, captured camera images, shell history, and exploitation results, which helped them map an impressive operation. According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel: A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses. It captured usable camera snapshots, sent results to Telegram, and exported them for Dahua’s SMART PSS platform. Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras. The account survives password changes and, on most firmware versions, factory resets. A cloud-relay attack reached 283 cameras behind NAT using only serial numbers and SDK credentials embedded in Dahua applications. Data indicates that 89.4% of live serials exposed an access channel without authentication. The recovery code generation mechanism in the attack toolkit leverages the camera serial number, which allows the CameraSwarm operator to redeem new codes via Dahua’s standard password-recovery process without knowing the current admin password. The researchers found two misleading vulnerability references in the toolkit, CVE-2024-39943 and CVE-2025-31702, which are not exploited in the observed attacks. Hunt.io's analysis uncovered that scanning was global, first checking the Russian address space, then scanning the entire IPv4 range. According to the researchers, "the operator's focus settled on Russian and CIS telecom netblocks." However, the researchers also found Russian comments in modified code inserted in repurposed public tools. On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign. Dahua cameras reachable through port 37777 between June and July should be treated as potentially compromised. Owners should examine them for the presence of a ‘p2pwn’ account and remove it. Hunt.io warns that removing the backdoor account does not invalidate recovery codes generated by the toolkit, and they remain usable until Dahua alters the derivation server-side. Additionally, users are recommended to disable P2P when not needed, and apply the Dahua SA-2021-0130 firmware updates for CVE-2021-33044 and CVE-2021-33045, or a later firmware version. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 19, 2026extracted
Your polite reply to that text is worth $2 on the dark web
Most wrong-number texts are harmless. Some are the first step in a carefully planned scam. By replying, you may be confirming that your number is active and that you’re willing to engage with strangers, making you a more valuable target for future fraud. Here’s why a polite response can be worth money to cybercriminals.  The politeness trap  Sunday night. You’re on the couch, half-watching Netflix, when your phone buzzes.  “Hey! Are we still on for dinner tomorrow? Don’t forget the wine ”   You don’t recognize the number. You glance at it for two seconds, then type what most polite people would:  “Sorry, I think you have the wrong number!”   You put your phone down. Go back to Netflix, and forget about it within five minutes.  On the other end, though, your reply has just told the sender something valuable. Not because of a technical exploit or an invisible cyber-attack, but because you just proved you’re the kind of person who responds to strangers politely.  According to cybercrime intelligence reports, responsive phone numbers are worth significantly more than inactive ones. With a single reply, you’ve entered a global criminal ecosystem run by transnational syndicates that, according to analysts , moves tens of billions of dollars.   What your reply told them  Let’s be clear: the “wrong number” text is not a phishing link. It’s not malware. In many cases, it’s not even the scam itself. It’s a personality test.   The scammers already have your number. They may have bought it in bulk from a data breach for a fraction of a cent per record. They already know the message was delivered because their SMS gateway received no delivery failure. Text messages remain one of the most effective ways to reach people, with exceptionally high open rates and most being read within minutes. That’s one reason scammers prefer SMS to email.  What they don’t know is whether you’re worth spending more time on. Your reply told them three useful things:   You’re responsive. You saw the message and felt compelled to reply. This immediately places you in their top 15–20% most active numbers category.   You’re polite. You didn’t ignore it and didn’t respond aggressively. You wanted to help a stranger. Scammers deliberately exploit that instinct to be polite and helpful.   You reply quickly. The time between their message and your reply can reveal how closely you monitor your phone, help estimate your timezone, and indicate how likely you are to respond to future messages. The two paths your number takes  From this moment, your story splits. Both paths described below play out across millions of phones worldwide.  Scenario A: The slow burn  Within minutes of your reply, another message arrives in response to yours:  “Oh no, I’m so sorry! But honestly, you seem like a really kind person. It’s rare to find polite people these days. I’m Sarah, by the way.”    Some people stop the conversation there. Others reply out of curiosity or because they’re simply being friendly. A few messages later, you’re in a conversation.  In some large scam operations, those early exchanges may be handled by AI (Artificial Intelligence) using open-source language models such as Llama or Mistral. That allows scammers to hold thousands of conversations at once and focus their time on the people who seem most likely to keep talking.   While keeping you engaged, the AI assigns you a real-time vulnerability score based on your response time and message length. If your score crosses a certain threshold, a human operator takes over. They read the conversation, learn your name, your job, and your communication style, then continue as though nothing has changed.  Within two or three weeks, this person has become a friend. They text you good morning, ask about your day, and send photos stolen from real social media profiles.  Around week three, they casually mention an investment:   “I’ve been making really good money on an investment platform lately. Almost $4,000 last month. It’s crazy.” If you show interest, they’ll send you a link to a fake trading platform with a convincing design. You might deposit $500 to test it. The next day, your dashboard shows a fake gain of $1,800, so you invest more. A week later, the platform disappears, along with your money, and the person who texted you every day.  According to the FBI’s Internet Crime Complaint Center (IC3), investment fraud generated more than $4.5 billion in reported losses in a single year. To be clear: while most wrong-number texts never reach this stage, victims who fall for so-called “pig butchering” scams (long-term romance/financial scams) suffer catastrophic average losses ranging between $70,000 and $75,000 per person.  Scenario B: The silent recycling  In this scenario, you replied “wrong number” and never heard from them again. You think you dodged the scam, but instead your number was simply moved to a different category: “Active, responsive, polite, but not susceptible to the wrong-number hook.”  That profile still has enormous commercial value. Your number is added to a cleaned database and sold or reused for a different campaign.   A week later you receive a text from another number:   “Hi! I saw your profile on LinkedIn. We have an opportunity that’s a perfect fit for your background.”   Or:  “Your package couldn’t be delivered, update your address by clicking here.”   Or a fake alert from your bank warning of “suspicious activity.”  You’ll probably never connect these messages to the wrong-number text you received the week before. They’re different topics and different senders. But they may all be part of the same criminal ecosystem. The first message was simply a way to sort potential targets. Everything that follows is the actual attack.  The most common hooks  If you’ve received one of these messages (or something very similar), you’re not alone. These are some of the most common opening lines used in wrong-number scams, tested on millions of people and optimized to maximize response rate:  The friend who doesn’t exist:   “Hey! See you tonight at 6? Don’t be late ”  “Are you still free tomorrow?”  “Did you send those files to the office?” “Hey Marco, are we still on for dinner tonight?”  The concerned neighbor:  “Sorry to bother you, I’ve noticed your dog sometimes runs into my yard.”  “I found a phone number on the dog tag, is this yours?”  “Hi, your package was delivered to my address by mistake.”  The professional mix-up:  “Hi, I tried to reach you about the delivery but you didn’t answer.”  “The shipment arrived at your address, can you confirm?”  “This is Mike from the office, did you get my earlier message?”  The family emergency:  “Do you know Sarah? There’s been an emergency.”  “Is this [common name]’s number? Something happened.”  The recruiter:  “Hi! I came across your profile, we have an incredible opportunity.”  “Hey, I’m reaching out about a position that matches your background perfectly.” If you’ve received one of these messages, it doesn’t automatically mean it’s a scam. People genuinely do text the wrong number sometimes. But if the conversation quickly moves to making small talk, asking personal questions, or encouraging you to keep chatting, stop replying.  Don’t recognize that number? We’ll check it. CHECK NOW The crime industry behind the text  These messages aren’t usually sent by a lone cybercriminal. They’re part of a highly organized criminal industry with its own market dynamics and global supply chains.  In January 2026, Cambodian and Chinese authorities arrested Chen Zhi, president of Prince Holding Group, accusing him of running a network of scam compounds across Southeast Asia where thousands of trafficked people were forced to manage these conversations. Those operations relied on underground marketplaces where criminals could buy everything they needed, from phone lists and stolen identities to AI tools and fake investment websites.  The scale is staggering. Blockchain analytics firm Elliptic estimates the Huione Guarantee underground marketplace processed more than $134 billion in transactions. Separately, researchers at the University of Texas at Austin estimate that pig-butchering scams stole more than $75 billion in cryptocurrency over four years.   The scam funnel: Costs and revenue  To understand why this ecosystem is so huge, look at the math. Sending hundreds of thousands of text messages costs very little. Even if only a tiny fraction of people reply, and an even smaller number eventually send money, the profits can far outweigh the costs.   Look at this illustrative model of a campaign sending 100,000 SMS messages:  The figures in this model aren’t arbitrary. They combine observed pricing from underground marketplaces such as Russian Market and BidenCash with average victim losses reported by law enforcement agencies, including the FBI’s Internet Crime Complaint Center (IC3).   Even allowing for variation between campaigns, the economics are compelling. A single campaign can cost less than $1,000 to run while generating more than $200,000 in revenue, representing a potential return on investment (ROI) of 90x to 200x.  Those same economics are reflected in underground marketplaces, where verified, enriched contact details command significantly higher prices than raw data. In our previous investigation into underground marketplaces , we found that a typical stolen personal record sold for around 95 cents. The more criminals learn about a potential victim, the more valuable that person’s data becomes.  The price ladder of your phone number:  .kb-table-container445707_d29b97-2a{overflow-x:auto;}.kb-table445707_d29b97-2a tr > *:nth-child(2){width:21%;}.kb-table445707_d29b97-2a{table-layout:fixed;width:100%;}.kb-table445707_d29b97-2a tr{height:0px;}.kb-table-container .kb-table445707_d29b97-2a th{padding-top:var(--global-kb-spacing-xxs, 0.5rem);padding-right:var(--global-kb-spacing-xxs, 0.5rem);padding-bottom:var(--global-kb-spacing-xxs, 0.5rem);padding-left:var(--global-kb-spacing-xxs, 0.5rem);text-align:left;}.kb-table-container .kb-table445707_d29b97-2a caption{text-align:center;}.kb-table-container .kb-table445707_d29b97-2a td{padding-top:var(--global-kb-spacing-xxs, 0.5rem);padding-right:var(--global-kb-spacing-xxs, 0.5rem);padding-bottom:var(--global-kb-spacing-xxs, 0.5rem);padding-left:var(--global-kb-spacing-xxs, 0.5rem);text-align:left;}.kb-table-container .kb-table445707_d29b97-2a td, .kb-table445707_d29b97-2a th{border-top:2px solid #CCCAD7;border-right:2px solid #CCCAD7;border-bottom:2px solid #CCCAD7;border-left:2px solid #CCCAD7;}@media all and (max-width: 1024px){.kb-table-container .kb-table445707_d29b97-2a td, .kb-table445707_d29b97-2a th{border-top:2px solid #CCCAD7;border-right:2px solid #CCCAD7;border-bottom:2px solid #CCCAD7;border-left:2px solid #CCCAD7;}}@media all and (max-width: 767px){.kb-table-container .kb-table445707_d29b97-2a td, .kb-table445707_d29b97-2a th{border-top:2px solid #CCCAD7;border-right:2px solid #CCCAD7;border-bottom:2px solid #CCCAD7;border-left:2px solid #CCCAD7;}} .kb-table-container .kb-table tr.kb-table-row445707_c65fe3-3f{background-color:rgba(0,89,255,0.17);height:48px;} Lead Type   Price   What Triggers It   Raw phone number (unverified, from old breach)  $0.01 – $0.05  Your data leaked years ago  Confirmed active number  $0.50 – $2.00  You replied “wrong number”  Enriched with profile data (name, job, income estimate)  $1.00 – $5.00  OSINT scripts scraped your socials  “Hot lead” (psychologically vulnerable, lonely, engaged)  $6.00 – $10.00  You chatted for 3+ days, showed openness  That’s a  4,000% value increase  generated by a single polite reply.    From there, scammers can enrich that record with publicly available information such as your name, employer, social media profiles, and estimated demographics using automated open-source intelligence (OSINT) techniques.  The more complete the profile becomes, the more valuable it is. Researchers monitoring underground marketplaces have found that enriched, pre-profiled contacts command premium prices because they’re more likely to become victims of high-value pig-butchering scams that generate billions of dollars in illicit revenue each year. How do they know who you are?  Before that text reaches your phone, your number may already have passed through automated script pipelines capable of cross-referencing tens of thousands of records in minutes.  Acquisition : Your number is pulled from historical data breaches, such as the Facebook leak affecting 533 million users, Twitter/X data leaks, or massive aggregated databases like Naz.api, and the Mother of All Breaches (MOAB), a collection of more than 26 billion records compiled from thousands of previous breaches.  Automated scraping : Software queries public sources to check whether your number is linked to an active WhatsApp account, collect your profile information and picture and match the number to public LinkedIn, Instagram, and Facebook profiles.  Data broker integration : Scammers exploit the same commercial data services used by marketing companies to associate a phone number with estimated age, address, and income bracket.  The result is a psychographic and commercial profile that helps scammers choose the most convincing approach. If your social media shows you have a dog, you might receive the neighbor hook: “Your dog keeps getting into my yard.” If you recently changed jobs on LinkedIn, the fake headhunter hook activates.  The human factor: Modern slavery  There’s one aspect of these scams that’s often overlooked: many of the people sending the messages are victims themselves.  In its August 9, 2023 policy report , the United Nations Office on Drugs and Crime (UNODC) described a human rights crisis tied to forced criminality in Southeast Asia. It estimates at least 120,000 people in Myanmar and tens of thousands in Cambodia are being held in fortified mega-compounds run by criminal syndicates.  Many were lured by fake job adverts promising legitimate work in digital marketing or customer service. Once they cross the border, their passports are confiscated. They were stripped of freedom and forced, under the threat of violence, to spend up to 16 hours a day managing dozens of scam conversations. Those who failed to meet financial targets were often beaten, isolated, or sold to other compounds.  When you reply to one of these messages, you’re interacting with a system designed to simultaneously exploit your financial availability and the enslavement of another human being.  Breaking the chain  You can’t erase your number from dark web databases: that damage may have done years ago. But you can make your profile far less valuable to scammers.  Make yourself harder to profile : Review the privacy settings on any messaging apps and social media platforms that use your phone number. Limit who can see information such as your profile photo, status, last seen, and phone number. The less information scammers can gather automatically, the harder it is to build a detailed profile about you. On WhatsApp, for example, you can set Profile Photo , About , Status , and Last Seen to My Contacts . On Telegram, set Phone Number to Nobody .  Report before you block: Blocking protects only you. Reporting protects everyone. When you use WhatsApp’s Report and Block function, the last five messages in the chat are sent to Meta’s security teams. If enough people report the same number, it may be permanently banned, destroying the entire active campaign on that line.  The golden rule: If you receive an unexpected message from an unknown number, the safest response is no response at all . Don’t reply, don’t explain yourself, and don’t worry about seeming impolite. If it’s a genuine wrong number, the sender will usually realise their mistake and move on. If it’s a scam, you’ve denied the criminals exactly what they wanted: proof that your number is active and that you’re willing to engage.   Something feel off? Check it before you click.    Malwarebytes Scam Guard  helps you analyze suspicious links, texts, and screenshots instantly.   Available with  Malwarebytes Premium Security  for all your devices, and in the  Malwarebytes app for iOS and Android .   Try it free →  
malwarebytes.comAug 19, 2026extracted
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. A notable capability is copying the victim's Chromium profile, including its authentication state, and loading it into a hidden, headless browser on the infected system. This allows the hacker to access victims' authenticated sessions while preserving the identifiers associated with the browser, host, and network. AmnesiaStealer can collect data in 16 Chromium-based web browsers as well as other sensitive information, such as passwords, cryptocurrency wallets, Apple Notes and documents, and keychain data. The malware is currently distributed through ClickFix campaigns that use a fake GitHub download page to drop a password-protected ZIP archive. Researchers at Jamf, an Apple device management and security company, analyzed AmnesiaStealer's distribution and found that it used the same template previously used to spread the Atomic and MacSync infostealers. The ClickFix command executes a shell-script loader that downloads and launches the password-protected archive containing the AmnesiaStealer Mach-O payload. The malware captures the victim’s macOS password and uses it to collect keychain data, as well as browser profiles, Apple Notes, Telegram sessions, documents, system information, and cryptocurrency wallet data. The researchers highlight that the malware features a component called stream_module, retrieved using the remote_stream command, which gives the malicious operator remote control over authenticated sessions deployed from a headless browser instance. According to Jamf, AmnesiaStealer's stream_module can duplicate user profiles in seven Chromium-based browsers, including Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium, because they share the same DevTools Protocol, launch flags, and cookie encryption. The module launches the legitimate browser executable in headless mode with command-line switches that weaken browser defenses, duplicates the victim’s profile, and specifies its location for storing the profile data. The malware then establishes a WebSocket channel that connects to the operator's relay and sends a JSON registration message containing the browser name and build. The operator can then send commands over this channel, such as navigation and mouse clicks, while the malware returns status and tab information as JSON and transmits screencast frames as binary WebSocket messages. A second WebSocket channel connects to the local headless Chromium instance through the browser’s webSocketDebuggerUrl, providing access to the Chrome DevTools Protocol (CDP). This allows the hacker to navigate websites with mouse and keyboard control, export or import cookies, and operate online portals using the victim’s existing authenticated sessions. “The operator receives a live screencast of the session at around 3fps and can drive it with a full input set: keyboard, mouse, scroll, navigation and tab management,” Jamf explains. "In effect the remote_stream command turns an infected host into a live, operator-driven browser running the victim's authenticated sessions, which is a materially different level of access from file collection." According to the researchers, the AmnesiaStealer can exfiltrate cookies, saved logins, browsing history, bookmarks, extensions, local state, and other profile data from the 16 Chromium-based browsers it targets. It also steals cryptocurrency wallet details and identifies them by enumerating extensions and IndexedDB data. Jamf notes that the malware contains a fallback mechanism when it runs on macOS 26 and cannot recover the existing Chrome Safe Storage key, which replaced it with an attacker-supplied value. This makes previously stored cookies and passwords permanently unreadable while allowing the attacker to decrypt data later. The Chrome DevTools Protocol (CDP) has been abused by malware in the past, including by Chaos ransomware to hide command-and-control communications, and by Chaes malware to expose browser functions that could enable data theft. However, AmnesiaStealer appears to be the first documented macOS malware to combine a cloned Chromium profile with CDP-based, live remote control, allowing attackers to interact with authenticated sessions through a hidden browser running on the infected computer. Users are advised never to execute commands in the terminal that they found online and don't fully understand. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 16, 2026extracted
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Most of the 2,500 organizations believed to have been affected by the LiteLLM supply chain attack were actually exposed before, SOCRadar reports. The compromise was blamed on and claimed by TeamPCP, the threat actor behind multiple open source software (OSS) supply chain attacks involving the Shai-Hulud worm. It started with Aqua Security’s Trivy scanner and propagated downstream to multiple packages and repositories in a ripple effect fueled by the malware’s worm-like behavior and by the automated inclusion of the malicious libraries in more builds. More than 2,500 organizations were likely affected by the LiteLLM attack, CloudSEK and HudsonRock said earlier this week. According to SOCRadar, most of them were victims of the Trivy compromise, not LiteLLM. All the compromises associated with TeamPCP followed a similar pattern: malicious code was automatically executed when the infected package was fetched and run to harvest credentials, tokens, API keys, and other secrets. Additionally, the worm used stolen developer secrets to modify accessible packages and push the malicious versions to the registry, expanding the attack surface. This is how LiteLLM was compromised and how two poisoned package versions were published on March 24 and stayed online for roughly 40 minutes. They were injected with a .pth file that Python automatically executed at interpreter startup, even if LiteLLM was never imported, bypassing ignore-scripts protections. The compromise timeframe According to SOCRadar, a close examination of the LiteLLM incident data revealed per-organization records for 2,188 entities, including timestamps, credential types, CI/CD platforms, and domains. “Every record carries first-seen and last-seen timestamps. The earliest is March 19 at 18:05 UTC and the latest is March 24 at 20:09 UTC, a span of just over five days,” the cybersecurity firm notes. For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry. “That timing lines up with the upstream Trivy compromise rather than the LiteLLM install window. The 40 minutes everyone reported was the closing act, not the whole play,” SOCRadar says. The earliest collection occurred 18 minutes after the malicious Trivy build was published on March 19. The activity surged on March 22 and March 23 when malicious Trivy images were live on Docker Hub, and closed on March 24 after PyPI quarantined the packages. “[This] is what persistence on already-infected hosts looks like: the .pth payload kept running after the source of the infection was gone,” SOCRadar notes. The compromise involved six CI/CD platforms, namely GitHub Actions, GitLab CI, Jenkins, Bitbucket, CircleCI, and Buildkite, and impacted organizations worldwide, with Germany, Brazil, and France affected the most. Stolen, now brokered secrets The malware targeted secrets broadly, but over 1,000 organizations exposed JWT and auth tokens. Hundreds of them exposed private keys, AWS access keys, GitLab tokens, OpenAI API keys, Slack webhooks, GitHub Actions tokens, and Google API keys. “The highest secret count in the set is roughly 3,477 [the organization has not been named], followed by roughly 3,459. Several high-secret rows rest on very few files or repositories. One row carries 3,459 secrets across just six files,” SOCRadar notes. The cybersecurity firm also points out that committer email addresses were compromised across over 1,100 organizations. In those cases, the attackers have both developer identities and machine tokens. “Of the 2,188 organizations in the record-level set, 56% are rated high confidence, 39% medium, and 6% low, with figures rounded. Headline reporting cites 2,500+ organizations; the difference reflects which records carry attributable identifiers,” SOCRadar notes. “High-confidence matches are keyed on CI host identity and legitimate committer domains, meaning whose systems a captured file came from, rather than any observed use of a stolen credential. These are exposure figures rather than confirmed compromises, drawn from a reconstructed sample rather than a complete census,” it continues. The stolen information is already being brokered. One threat actor is offering on Telegram a collection of LiteLLM, Trivy, and CanisterWorm data, likely compiled at various stages of the campaign. Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: Hackers Exploiting Unpatched GeoServer Zero-Day
securityweek.comAug 14, 2026extracted
Armored Likho expands its cyber-espionage toolkit
In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage. We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal. During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data to gain ongoing access to the victim’s account. With this stolen data, attackers can leverage the Telegram API to automatically pull chat logs, media files, and other information from the account. The second component, Still Audio, is an implant for covert audio surveillance. It analyzes the incoming audio stream, automatically detects speech, records conversations, and sends the recordings to a command-and-control server. In this article, we’ll look at the initial infection method, how the new Still Toolkit components are built, and the technical details of how they operate. Kaspersky products detect this threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic. Background Armored Likho’s malicious activity has been documented several times before: in November 2024, and in February and July 2026. The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure. At the same time, our research uncovered a number of new tools that point to the attackers expanding their capabilities. Initial infection The infection chain starts with an app that mimics a donation service. As of this writing, the app distribution method remains unknown. During our research, however, we obtained several samples posing as apps from different Russian foundations. In reality, the app is a dropper. Its developers wrote it in Rust on top of the popular Tauri framework, and it has a graphical interface designed to deceive the user. After launch, it displays a login form that asks for a password, presumably one the attackers supplied. After the user enters a valid password, they see a catalog of donatable items. The app pulls item and category information from orderapiserver[.]info through the public/categories and public/products endpoints. A clickable catalog makes the app look legitimate. While the user browses the items, the dropper quietly decrypts and launches the payload for the next stage in the background. Our analysis shows that the mechanism for decrypting the payload and launching subsequent stages hasn’t changed since the February campaign. However, we found a new cyber-espionage toolkit – the Still Toolkit – made up of two components: Still Sync and Still Audio. Still Sync Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API. Architecturally, Sync is an asynchronous application based on the Tokio library. It talks to the server over gRPC and serializes messages with FlatBuffers. It supports both HTTP and HTTPS as transport protocols; the URL of the command-and-control server determines which one it uses. How it works When Sync launches, the attackers set several environment variables. Before starting any malicious activity, the implant pulls configuration parameters from these: STILL_SYNC_ADDR: the address of the command-and-control server. By default, this is https://tg4service[.]com:443 . STILL_SEND_PATH: the path to the tdata STILL_TELEGRAM_PASSCODE: the password for decrypting the tdata folder, if Telegram data encryption is enabled on the victim’s device. Sync also supports several command-line arguments: --console : runs as a console application. If this parameter is absent, the implant creates a TReload service to keep running in the background. --version : prints version information and exits. --firefly : launches a trace thread that monitors the program’s operation. It writes error messages to a hidden file, bin, located in the same folder as the main executable. --db : turns on debug mode with detailed logging. Once it launches, the malware begins registering the device with the C2 server. To do this, Sync collects the following information about the victim’s system: Motherboard serial number CPU ID System UUID BIOS serial number Computer domain name The malware combines the collected data into a single string with a colon as the separator. It then hashes that string with SHA-256 and stores the resulting hash under the key sysmarker. Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm. Sync then serializes a package containing all the collected information and the agent version, and sends it in a POST request to /still.rpc.Sync/RegisterMachine. The response contains a machine_id value, which Sync uses to identify itself in subsequent requests. Once registration succeeds, Sync sends a POST request with the machine_id parameter to /still.rpc.Sync/GetMachineSettings. The server responds with the following settings: enabled: triggers malicious activity on the infected device. scan_portable: turns on extended scanning when searching for the tdata We’ll cover this feature in more detail below. fetch_telegram: if this parameter is on, Sync attempts to log in to Telegram and extract data. We’ll cover this feature in more detail below. download_channels: if this parameter is off, Sync skips channel dialogs when exfiltrating Telegram data. These parameters have no default values, so Sync doesn’t perform any malicious actions until the registration and settings-retrieval processes both complete successfully. Telegram data collection Before stealing a Telegram session, Sync searches for the tdata folder, unless the STILL_SEND_PATH variable is already set. The list of search paths includes both standard and nonstandard directories, if the scan_portable option is turned on: C:\Users\ \AppData\Roaming\Telegram Desktop\: the standard Telegram Desktop installation directory. C:\Users\ \AppData\Local\Packages\ \LocalCache\Roaming\: the installation directory for the Microsoft Store version. Sync identifies the package folder by a name that contains the string TelegramMessenge. C:\: used for the extended search (if the scan_portable option is on). Sync then sends a POST request with a list of files from the tdata folder to the /still.rpc.Sync/CheckFiles endpoint. The server responds with the following values: snapshot_id: an identifier the server assigns to the current data snapshot. present: a list of file paths that are already present on the server. This lets the C2 server avoid re-receiving files it already has. In addition, if Sync can’t access files on disk through standard methods, it falls back on three mechanisms that abuse the SeBackupPrivilege privilege: Opening files with the CreateFileW function using theFILE_FLAG_BACKUP_SEMANTICS parameter Creating a backup copy through the Shadow Copy service and reading files from there If the previous methods all fail, attempting to copy the file using the Robocopy utility in backup mode Beyond stealing Telegram session data, Sync can carry out full-scale collection of user information from the messaging app. When the fetch_telegram option is on, it launches a separate thread that authenticates to the chat app using the previously obtained tdata. Once authentication succeeds, Sync gains access to the account data and sends the following collected information to the server: User details, such as username, phone number, first and last name Information about private chats, groups, or channels, such as chat name and ID, the member list, and so on Dialogs from private chats, groups, and channels (if the download_channels option is on) Media files under 250MB: photos, documents, stickers, and contacts Still Audio Still Audio is an audio surveillance implant written in Rust. Its main job is to analyze the incoming audio stream and start recording voice when certain conditions are met – we’ll cover those in the next section. Architecturally, Still Audio largely mirrors Sync and uses the same mechanisms for communicating with the C2 server. On launch, Still Audio performs a sequence of actions: It extracts libmp3lame.dll , a file stored inside the executable. This is a library used to encode audio data. If the --console command-line argument is absent, the implant creates a service namedauxhost , connects to it, and continues running in the background. While running in the background, it creates a file, logfile.log , to write logs to. Next, Still Audio retrieves the C2 server address. As with Sync, it stores the URL in an environment variable – in this case, STILL_AUDIO_SYNC_ADDR. If that variable isn’t set, it falls back to STILL_SYNC_ADDR, which shows the two modules are compatible with each other. If neither variable is set, it uses the default URL, https://srwinservice[.]com. Still Audio also uses the Dead Drop Resolver technique as a fallback mechanism for obtaining the C2 address. If the current server stays unreachable for three days, the tool tries to pull the current C2 URL from a GitHub repository. In the sample under analysis, we found the following URL for the page containing C2 information: hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json The repository, a fork of a popular project, contains the server URL Base64-encoded and encrypted with the Blowfish algorithm in ECB mode, using the key 5c8e153228edd3c6cbf75684 (lowercase string). Older AquilaRAT samples use this exact same algorithm and key. Once it obtains the current C2 address, the Audio module starts a registration process similar to Sync’s, but through a different endpoint: /still.rpc.Audio/RegisterAudioMachine. Also, unlike Sync, Audio sends a list of available audio input devices along with the system information. The server responds with settings for the implant: machine_id: a unique identifier for the current device. vad_threshold: the threshold value for the VAD (Voice Activity Detection) algorithm. Expressed as a decimal fraction, it represents a proportion of the maximum sound level the input device can pick up. Sound above this threshold counts as voice activity. The default vad_threshold is 02. max_silence_duration: the number of audio samples with a VAD value below the set threshold after which the implant considers the recording finished. max_buffer_size: the maximum buffer size for recorded audio data. active_device: the name of the input device selected for recording, from the list of available devices. The eavesdropping process Still Audio works with raw audio samples it captures directly from the input device. To detect voice activity, it implements an algorithm based on Root Mean Square (RMS), a lightweight signal-processing method that distinguishes speech from silence by measuring the audio signal’s average power over time. The implant doesn’t rely on any third-party libraries here; it implements all the calculations itself. The implant compares the calculated RMS value against the vad_threshold parameter. If RMS meets or exceeds this threshold, recording starts. To avoid losing the beginning of the recording, Still Audio uses a pre-buffer, a size-limited buffer that stores samples from just before the current recording moment. A sequence of max_silence_duration samples (320 by default) with RMS values below the threshold signals the end of the recording. For example, with a standard headset running at a 44.1kHz sampling rate, recording stops after roughly 7ms of silence. Interestingly, the Audio module makes no attempt to hide its use of the microphone: its name shows up in Windows settings. In the sample we examined, the file was saved to disk as IntAudio.exe, and it appeared in the list of apps using the microphone as “Intel Audio”: Before sending recordings to the server, the implant uses the libmp3lame library to encode the raw audio samples. It sends the recording files via a POST request to /tgfrg, adding a Client-Id header containing the machine_id obtained during registration to identify the device. Infrastructure This campaign draws on a broad set of hosting providers and domains registered at different points in time, which suggests the attackers are trying to make their infrastructure harder to detect. We found no direct overlap in domains or IP addresses with the February campaign. Even so, the two infrastructures share some similarities: They use the same hosting providers, with the ASNs 149440, 202448, and 215311. Their domain names follow similar naming patterns that mimic Windows system services and update mechanisms. Victims In this campaign, we’ve determined that the attackers’ primary targets are users in Russia. Most victims are private individuals, though the corporate sector, government organizations, IT companies, and educational institutions are also affected. Attribution This campaign has been using both new tools and malware families documented in BI.ZONE’s February report. While some components turned up for the first time, they show significant code-level overlap with malicious tools seen in earlier Armored Likho campaigns. Based on these overlaps, along with additional technical artifacts, we’re highly confident the Armored Likho group is behind the campaign. The overlaps we identified include: Identical dropper architecture in the February and current campaigns, which includes the use of the Tauri library to build the graphical interface, a similar user-input handler, a payload with the ICRYPTMP header, and the same multi-part encryption format. The same encryption algorithm and key used in AquilaRAT from the previous campaign and in the Still Audio module from the current campaign, both implementing the Dead Drop Resolver technique. Identical logic for generating the sysmarker value in older AquilaRAT samples and in the Still toolkit from the current campaign. The algorithms match down to the PowerShell commands used to collect system information. Substantial infrastructure overlap, which includes the hosting providers and domain-naming patterns described in the Infrastructure section. Takeaways The campaign described in this post shows Armored Likho’s toolkit evolving, with the group steadily expanding its cyber-espionage capabilities. Beyond the components we already knew about, the attackers rolled out new modules that let them not only access Telegram data but also conduct audio surveillance on victims. Together, these capabilities significantly widen the range of information attackers can collect in a single compromise. One point deserves particular attention: the new tools form a cohesive set, sharing similar architecture, C2 communication mechanisms, and common implementation elements. This points to the group building out its own tool ecosystem, designed for long-term use and further expansion. The emergence of new, specialized modules shows the attackers aren’t just trying to preserve their existing capabilities – they’re working to make intelligence-gathering more effective by controlling multiple communication channels at once. Indicators of compromise Additional information about this threat, indicators of compromise included, is available to customers of Kaspersky Threat Intelligence Reporting. Contact [email protected] for more details. File hashes Droppers C1D1EE16B92E6A138FFA048855F75D7D 17674B250D8B422A50A86C9FF207186D 62801F6223E860A7CCA271522E303B2D Still Sync 68F0365D2FA8C828D012D8859E52A773 4BD7C352AE277B0E38D07BEEDD4DD507 D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD Still Audio 2CA8ADBAB98EBE305EACF272CF48F5A0 3AC41B097236A7723821848AE31EF141 439255736797BC88BD19F282449E0436
securelist.comAug 13, 2026extracted
Social media platforms crack down on drone factory recruiting game
A video game about drone warfare may look like an unusual cybersecurity story. But cybersecurity isn’t only about malware or stolen passwords. Sometimes it’s about understanding how online platforms are used to influence decisions, build trust, and persuade people to share personal information or take actions they otherwise wouldn’t. According to Straight Arrow News, the online game Drone Battle: Ukraine is linked to Russia’s Alabuga Special Economic Zone in Tatarstan, a site associated with the production of attack drones used in the war against Ukraine. Investigators say the game is the latest part of a broader campaign that has used major social media platforms, including YouTube, TikTok, Instagram, and X to reach young people. The game is just the lure. Investigators say it forms the entry point to a recruitment funnel that markets education, careers, travel, community, and technological opportunity to young people before ultimately steering some recruits toward jobs assembling drones at Alabuga. Available in English, Russian, and Chinese, Drone Battle: Ukraine presents a stylized conflict between Russia and NATO. But investigators say the game is only one part of a larger campaign that combines games, esports tournaments, influencers, and career messaging to recruit young people globally into Russia’s drone industry. This campaign is not limited to drone combat. The same channels have also promoted games that frame construction work, teamwork, strategy, and professional development as challenges to be completed and levels to be unlocked. That’s gamification serving a recruitment purpose. The game doesn’t have to persuade someone to take a job on its own. It only needs to make participation feel like a game, make a military-industrial workplace appear modern and exciting, and make the transition between the two seem natural. Gamification itself isn’t unusual. Companies use games, quizzes, competitions, and rewards in education, training, and recruitment every day. The concern here is how those familiar techniques are combined with social engineering to influence decisions while obscuring the true nature of what’s being offered. Social engineering Social engineering is often described as a way of tricking people into giving up a password or opening a malicious attachment. But at its core, social engineering is the manipulation of human decisions. This campaign appears to use several familiar techniques at once. Targeting: Investigators say Drone Battle: Ukraine is described in a registered patent as an “assessment tool in game form.” Rather than simply entertaining players, the game appears designed to engage people who may be receptive to later recruitment. Baiting: The campaign advertises scholarships, training, free travel, housing, and career opportunities while, according to investigators, downplaying or concealing the true nature of the work. Influencers: Social media promotions and seemingly personal testimonials make the campaign more persuasive than a straight-up advertisement. Normalization: A drone in a game is a tool to use for victory and fun. Researchers have warned that game-like recruitment can make militarized narratives feel routine, technical, and emotionally distant. Small steps: It starts with playing a game or following an account. People may then join a tournament, communicate with a recruiter, submit personal details, travel, and only later discover the full nature of the work. As with many social engineering campaigns, each interaction asks for a little more commitment, making the next step feel less significant than it really is. Social platforms are taking action US-based social media platforms have increasingly taken action against Alabuga-linked accounts after investigations alleged deceptive recruitment practices and human rights abuses associated with the campaign. Social media platforms have been trying to disrupt the campaign for nearly two years. Following an Associated Press investigation in 2024, Google, Meta, and TikTok removed accounts linked to Alabuga Start for violating their policies. But according to the Foundation for Defense of Democracies (FDD), the organizers later created new accounts and continued recruiting across multiple platforms. More recently, Ukraine’s Minister of Foreign Affairs, Andrii Sybiha, said that roughly 600 videos promoting Alabuga were removed from YouTube. The videos had been posted across hundreds of channels with a combined audience of more than 500 million subscribers. He wrote: “The work does not end with removals. We will be now pursuing sanctions against individual bloggers who accepted payment to promote a sanctioned weapons manufacturer to millions of viewers.” According to the Straight Arrow News investigation, however, the campaign remains active on X and Telegram. How to stay safe For home users, the traditional scam advice still applies: Independently verify a prospective employer, search for complaints and reporting, discuss an offer with someone you trust, and never pay to get a job. Gamers should treat unsolicited career, travel, competition, and “exclusive training” offers with the same caution they would apply to any job pitch that feels unusually generous or vague. Offers to turn your gaming into a paid job should also be treated as “too good to be true.” Other actions that might go a long way Friends, families, educators, and youth organizations should talk openly about recruitment tactics without assuming that people targeted by them are naïve. They are often drawn in through a series of small steps that feel natural. Platforms should investigate networks, influencer relationships, referral links, and coordinated messaging, not just individual posts or game titles. Game developers and community platforms need reporting systems that are easy to find and will cater to recruitment concerns, not just cheating or abusive chat. Governments and civil society groups in targeted countries need practical awareness campaigns that explain the specific promises being used and offer credible alternatives for education and employment. Something feel off? Check it before you click. Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
malwarebytes.comAug 11, 2026extracted
British ‘Com’ member who abused more than 100 girls worldwide jailed for two years
British ‘Com’ member who abused more than 100 girls worldwide jailed for two years A 20-year-old man was sentenced Monday to two years in prison for coercing more than 100 girls worldwide into sexual and self-harm activity using platforms such as Snapchat, Telegram and Discord, British authorities said. Justin Swaddle, of Leeds in northern England, targeted 117 female victims aged 13 to 17, according to the National Crime Agency (NCA). He was 17 at the time of the offenses and operated under aliases including “Epstein” and “Moscow.” Swaddle was part of what British authorities call a “Com” group — loosely-knit online communities whose members coerce victims into self-harm and sexual abuse for the sake of gaining status among peers. Investigators found Swaddle manipulated victims into sending sexual images and carving his usernames into their bodies, threatening to leak intimate material or to contact their schools and parents if they refused. He also attempted to incite a child to sexually abuse a younger child on camera. Investigators recovered hundreds of indecent images of children, some as young as three, from his devices. Eight of the victims were located in the United Kingdom. The NCA, which led the investigation, worked with law enforcement partners in the U.S., Canada, Australia, Norway and New Zealand to identify and safeguard victims. Swaddle pleaded guilty at Leeds Crown Court to multiple child sexual abuse offenses and blackmail. Sentencing him on Monday, Judge Peter Kelson described him as “a predatory shark preying on children swimming in the dark waters of the internet.” He will be subject to a Sexual Harm Prevention Order for 10 years and must sign the Sex Offenders Register. Authorities in the UK and elsewhere have increasingly warned of Com groups like the one Swaddle operated in. “Offenders and victims are usually in the same groups, and offenders are usually not motivated by money or sexual gratification but by the status and notoriety that comes with sharing shocking content with other members,” the NCA stated. Last year, the FBI issued a warning about Com groups more broadly, usually composed of English-speaking minors involved in a range of cybercriminal activity. Those groups have been linked to the extortion of minors and distribution of child sexual abuse material through to other activities including swatting, SIM swapping, cryptocurrency thefts and ransomware attacks. That followed an East London-based member of a Com network being convicted of making indecent images of children, again perpetrating the crimes when he was 17 years old. “Justin Swaddle targeted young and vulnerable victims all over the world to abuse and scare them into carrying out shocking self-harm and sexual activity, purely to gain popularity with his peers online,” said the NCA’s Danielle Pownall. “While the number of people involved in Com groups are relatively small, the impact it has on victims is high and long-lasting, as Swaddle’s offending shows,” she added. Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaAug 10, 2026extracted
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul McCarty said. Unlike other npm-oriented software supply chain attacks that make use of lifecycle hooks like preinstall or postinstall to trigger the execution of malicious code, the newly identified packages come with a README that instructs developers to load them with require(), a built-in function to import modules, local files, and third-party packages. The attack leads to the execution of a downloader named WEL1DROPPER, which, when executed, identifies the host operating system and processor architecture and fetches a compatible payload from one of the three Cloudflare Workers hosts. The three Cloudflare Workers domains are listed below - oob-worker.cf103-070.workers[.]dev oob-worker.cf102-baf.workers[.]dev oob-worker.cf99-9b3.workers[.]dev If the HTTPS-based downloads fail, the malware switches to a platform-specific domain and uses DNS TXT records to obtain the next-stage from the domain "wel1[.]ru." The payload domain for each operating system and CPU architecture is as follows - Linux x64 - sdk.dl.wel1[.]ru Linux ARM64 - ext.dl.wel1[.]ru macOS - pkg.dl.wel1[.]ru Windows - net.dl.wel1[.]ru "The package first requests a TXT record from c. ," McCarty explained. "It parses the response as the number of payload chunks, accepting a value between 1 and 2,000. It then requests numbered TXT records. The returned strings are joined together and Base64-decoded into a binary buffer." In the final stage, the payload is written to a temporary folder and executed either using "/bin/sh" on Linux and macOS, or "cmd.exe" on Windows. Sonatype, which is also tracking the campaign under the moniker Flooding Dropper, said the final stage is launched as a detached process, with the Windows version taking steps to patch Event Tracing for Windows (ETW) and Antimalware Scan Interface (AMSI) to interfere with monitoring, check for sandboxes and virtual environments, establish persistence through a Registry Run key and a scheduled task, and download an encrypted payload ("/pkg/update_win.exe") and run it. The macOS infection chain is similar, performing an identical set of actions to look for debuggers and analysis artifacts before retrieving a compatible payload ("/pkg/beacon_mac.bin") from a remote server. If this fails, it employs the aforementioned DNS TXT delivery, sets up persistence using a LaunchAgent, and then starts the executable in a detached process. The Linux sample, on the other hand, is an UPX-packed ELF binary that's configured to download auxiliary payloads from a Cloudflare Worker URL ("oob-worker[.]cf99-9b3.workers[.]dev"), ultimately leading to the deployment of Sliver, an open-source command-and-control (C2) framework. The packages have also been found to contain a file called "lib/telemetry.js" that implements a plausible-looking telemetry SDK but also contains the same downloader logic. "The package entry point does not import this file, and it contains no additional hard-coded infrastructure," OpenSourceMalware said. "The oversized telemetry implementation appears intended to add noise and make the malicious behavior look like native profiling or analytics functionality during a quick review." The presence of domains like "tcsbank[.]ru" and "cloudpayments[.]ru" in the macOS payload indicates that the campaign could be targeting Russian financial institutions and mobile payments. It's also suspected to be an evolution of a dependency confusion campaign codenamed Moika that was observed earlier this April and saw over 250 packages published to the npm registry to steal environment information and deliver an operating system-specific second-stage payload. The development comes as Palo Alto Networks Unit 42 documented multiple campaigns targeting npm and the Python Package Index (PyPI) repository - A set of 10 npm packages that download an obfuscated cryptocurrency stealer and a remote access trojan from an external server. "After installation, the packages export a 'getPlugin' function that constructs the URL from which the payload is downloaded as an obfuscated IIFE (Immediately Invoked Function Expression) JavaScript code embedded in a JSON object," Unit 42 said. "The payload implements a crypto stealer and Remote-Access Trojan (RAT) that allows the attacker to execute arbitrary commands on the infected host." A set of malicious packages across npm and PyPI representing multiple distinct threat actors that are capable of cloud credential exfiltration, delivering EtherHiding blockchain-based C2 droppers, Solana cryptocurrency wallet key theft via Telegram, .env file secret exfiltration, fake-CAPTCHA social engineering remote code execution, and Discord token theft and GitHub Actions CI/CD credential exfiltration. From Packages to Chrome Extensions Threat actors have also been observed using Google Chrome extensions marketed as game emulators, password managers, productivity tools, CSS inspectors, and markdown converters to turn the web browser into a web crawling proxy. The crawl commands are received remotely via a persistent WebSocket connection. "These extensions embed an identical commercial web bandwidth-sharing SDK that connects the user's browser to a 3rd party residential proxy network for web scraping operations," Unit 42 said, adding it crawls pages by injecting a hidden iframe into active browser tabs, converts page content to Markdown in the background, and sends it to a remote cloud backend. The cybersecurity company noted that some of these extensions disclose the practice in their Chrome Web Store descriptions and in the privacy policies on their SaaS websites. Once installed, the third-party SDK prompts users to opt-in to the service. "While the proxy and crawling features remain inactive if the user declines, some extensions frame this opt-in as necessary for uninterrupted service,'" Unit 42 said. "A notable example is InstaSkip (mdondgockboebafloibbhjofmoedmnnn), which embeds this SDK." Update OpenSourceMalware's co-founder Jenn Gile told The Hacker News that the WEL1DROPPER campaign has involved a total of 1,033 confirmed packages so far. "The velocity has definitely slowed down since last week," Gile added. "The Flooding Dropper threat actors are using account names that appear randomly generated, and individual accounts publish only a handful of packages," Sonatype said. "That prevents defenders from assuming that removing one prolific publisher will eliminate the broader operation." "It also creates a moderation problem for npm. Each account and package may need to be identified, reviewed, and removed independently while the attacker continues generating more." (The story was updated after publication on August 11, 2026, to include the latest developments.)
thehackernews.comAug 7, 2026extracted
Russian businesses erase Durov-linked products after 'terrorist' designation
Russian businesses erase Durov-linked products after 'terrorist' designation Russia's decision to designate Telegram founder Pavel Durov as a terrorist and extremist has produced an unusual side effect: businesses across the country are removing books, films and other products associated with the billionaire, even as Telegram itself remains widely available. The designation, announced last week, came a day after Russia's Federal Security Service (FSB) charged Durov with aiding terrorist activity and said it would seek to place him on an international wanted list. The agency accused Telegram of failing to remove channels and bots allegedly used by Ukrainian intelligence, as well as terrorist and extremist groups. Durov rejected the allegations, saying Moscow was retaliating for his refusal to comply with demands for mass surveillance and censorship on Telegram. "Under Russian law, I'm banned from publishing information on the internet," Durov wrote on Telegram. "Russian officials have clearly got confused about who can ban whom from the internet." He also posted a meme showing his own photograph labeled "terrorist" alongside an image of Russian Foreign Minister Sergei Lavrov shaking hands with Taliban representatives under the caption "respected partners." Under Russian law, people added to the list of terrorists and extremists face strict financial restrictions, including frozen assets, limited access to banking services and increased scrutiny from authorities. Yet the measures have had little visible impact on Telegram itself. The messaging app remains accessible across Russia despite years of official threats to block it, and Russian state institutions, including the central bank, the Defense Ministry and the Foreign Ministry, continue to publish daily updates through official Telegram channels. Businesses rush to comply The most immediate consequences have instead fallen on Russian businesses seeking to comply with laws governing designated individuals. Russian e-book and audiobook platform LitRes has withdrawn The Durov Code and The Durov Code 2, two biographies of the Telegram founder, from sale. Online retail giants Wildberries and Ozon told state news agency TASS they were reviewing products associated with Durov following his addition to the blacklist. Ozon said it planned to remove books and merchandise featuring Durov from its marketplace, citing Russian rules requiring companies to review and block sales of materials associated with designated terrorists and extremists. A tech publication called Durov's Code, which originally focused on Telegram and Durov's projects, rebranded as Kod.ru. Editors said they had been considering the name change for some time as the publication expanded beyond covering Durov, but that recent events accelerated the decision. Streaming service Kion removed the 2021 documentary Durov from its catalog. Meanwhile, Moscow fertility clinic AltraVita, which offers in vitro fertilization using Durov's donated sperm, added a notice to its website informing patients that he had been placed on Russia's terrorist and extremist register. The clinic's director told Russian media he had not ruled out terminating the clinic's agreement with Durov. At the same time, Russians can continue using the messaging platform and paying for Telegram Premium subscriptions without violating the law because the restrictions apply to Durov as an individual rather than to Telegram as a company, according to Russia's financial watchdog Rosfinmonitoring. Mounting international pressure The Kremlin's actions come as Telegram faces growing scrutiny from regulators outside Russia. On Tuesday, Apple briefly removed Telegram from its App Store worldwide after receiving a report that a user had shared child sexual abuse material. The app returned after Telegram removed the content and banned the offending account. "I'm sure this stance will be applied equally to all other apps in the store in the future, right?" Telegram's official account wrote in response to a user who shared Apple's explanation. In April, Britain's online safety regulator opened an investigation into Telegram over evidence that the platform had allegedly facilitated the sharing of child sexual abuse material. Telegram said it has "virtually eliminated" the public spread of such material through automated detection systems and cooperation with non-governmental organizations. Durov also remains under investigation in France over allegations that Telegram facilitated the distribution of child sexual abuse material, drug trafficking, fraud and other organized crime. He has denied wrongdoing, describing his detention in France as "absurd" before returning to Dubai in March. His exact whereabouts remain unclear, although he said he visited Georgia in July. Durov's future remains uncertain. Despite Moscow's plans to seek his extradition, Russian lawyers interviewed by state news agency TASS said France and the United Arab Emirates are highly unlikely to surrender him because he holds citizenship in both countries. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaAug 4, 2026extracted
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, or email when one stops. The self-hosted monitoring tool is MIT licensed, runs in a container or on Node.js, and has 89,800 stars and 8,200 forks on GitHub. The change with the widest reach in version 2.5.0 is that the project now sets a 14-day cooldown on npm updates to minimize supply-chain attacks. That cooldown is aimed at the window in which a hijacked package does its work. When an attacker publishes a malicious version of a dependency, the poisoned release usually gets pulled within days of discovery, so the projects that get hit hardest are the ones that grab the newest version the moment it exists. Uptime Kuma sits inside networks and holds credentials for the 90-plus notification services it can reach, which makes its dependency tree worth attacking. Waiting two weeks means Uptime Kuma builds skip most of the packages that get yanked. New monitor types Uptime Kuma now has an NTP monitor so it watch a network time server directly. NTP is how machines agree on what time it is, and when a time source drifts or dies, certificate checks start failing and log timestamps stop lining up across hosts. Before this release, you could monitor the box running the time service but not the service itself. A second change lifts the ceiling on check intervals, which previously topped out around 24 days. Anyone tracking something that only needs a look once a quarter, like a certificate or a domain expiry, no longer has to fake it with a shorter interval. The author also added a next-rootless Docker tag for people who do not want the monitoring process running as root in its container. Fixes worth knowing about The badge generator was producing broken URLs because of a doubled slash, so status badges embedded in READMEs and dashboards were failing. The MQTT monitor now accepts mqtts:// addresses, meaning a TLS-protected broker no longer needs a workaround. Steam game server monitors resolve hostnames instead of requiring an IP. The DNS monitor stops appending the resolver port to the service URL, and Discord notifications now render timestamps in the right timezone. One database fix is quieter and worth reading twice: the up and down columns in the stat_daily table were widened from SMALLINT to an unsigned integer. A signed SMALLINT stops at 32,767, and monitors checking at short intervals across many hosts can push a daily counter past that. If your uptime history has gaps or nonsense values on busy days, this is a candidate explanation. Must read: 20 open-source cybersecurity tools to keep your team ready for anything GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comAug 4, 2026extracted
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan, launched exploitation attempts against more than 460 targets using autonomous and conventional workflows. Unit 42 described seven exploit tracks. They span eight Common Vulnerabilities and Exposures (CVE) identifiers because the n8n chain combines two vulnerabilities. The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits' configuration requirements. In separate manual operations, Unit 42 reported data exfiltration from three organizations through the NetScaler memory-overread flaw CVE-2026-3055 and command execution on 11 Marimo instances through CVE-2026-39987. Yet it later says it could confirm only three successfully exploited targets across the entire operation. The report does not reconcile the two statements. The Hacker News has contacted Palo Alto Networks for clarification and will update the story with any response. The agent checked versions, downloaded exploits, abandoned an unproductive path, and chose another vulnerability based on severity, deployment scale, and apparent exploitability. Organizations should patch exposed Langflow, n8n and Marimo systems, along with customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers. They should also remove unnecessary public access to workflow and notebook interfaces. Hermes Agent exposed the operation by starting python3 -m http.server 8888 from /home/worker. The unintended HTTP server made the actor's model configurations, application programming interface (API) keys, exploit scripts, target lists, shell history, and autonomous-session logs accessible, according to the company's report. DeepSeek was the primary reasoning model inside Hermes Agent, which supplied terminal access, reusable skills and unattended execution. Unit 42 found limited use of Claude Code and Qwen Code. It also found signs of Codex use in exploit-development directories, but could not verify actual use because the chat logs were not preserved. The framework's own documentation confirms that it can operate through Telegram, run commands, and schedule unattended tasks. In a recovered May 2026 session, DeepSeek downloaded a public exploit for the Langflow code-injection flaw CVE-2026-33017, enumerated 84 instances through FOFA, and found one target running version 1.3.4. Langflow is an artificial intelligence (AI) agent and workflow builder. The attack stopped because the system had neither auto_login enabled nor a usable public flow identifier. The agent then surveyed 10 product families, searched GitHub for recent proof-of-concept repositories and selected n8n, the workflow automation platform. It obtained a chain combining the unauthenticated file-access flaw CVE-2026-21858 with the expression-injection issue CVE-2025-68613. FOFA returned 25,209 n8n systems in China during the session. DeepSeek sampled about 100, probed roughly 40 and identified three running vulnerable versions. One target exposed three form endpoints, but all required authentication. More than 50 additional targets also lacked a usable public form, so no n8n system was compromised. Langflow fixed CVE-2026-33017 in version 1.9.0. n8n fixed CVE-2026-21858 in version 1.121.0. It fixed CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0. Version 1.121.1 is therefore the earliest release that addresses both flaws used in the attempted chain. Marimo fixed CVE-2026-39987 in version 0.23.0. Citrix says CVE-2026-3055 affects customer-managed NetScaler ADC and Gateway appliances configured as SAML identity providers. Administrators can check the appliance configuration for add authentication samlIdPProfile .* and install the fixed builds listed in the company's security bulletin. Unit 42 assesses the operator to be based in Zhuhai, China. Public material is consistent with, but does not independently verify, that assessment: the GitHub profile displays the name "KnYuan Knaithe," while an older blog under the same handle describes its author as a binary security researcher in Zhuhai. Those profiles do not establish the operator's legal identity or any state connection.
thehackernews.comJul 31, 2026extracted
Russia accuses Telegram founder of aiding terrorism, seeks international arrest
Russia accuses Telegram founder of aiding terrorism, seeks international arrest Russia is seeking to place Telegram founder Pavel Durov on an international wanted list, alleging that his messaging app has been used by Ukrainian intelligence to organize terrorist attacks and conduct espionage inside Russia. The country’s Federal Security Service (FSB) said Wednesday that it had charged Durov with aiding terrorist activity, claiming Telegram failed to remove channels and bots allegedly used by Ukrainian intelligence, as well as terrorist and extremist groups. According to the FSB, Ukrainian intelligence used Telegram to recruit Russians, including teenagers, for sabotage missions through the popular dating bot Daivinchik. The agency alleged that Ukrainian operatives posed as young women online to build relationships with men before persuading or coercing them into carrying out attacks. Russian authorities said 46 people between the ages of 12 and 22 had been detained since last summer over the alleged recruitment campaign. The FSB also released a video it said showed several young people confessing to setting fire to gas stations in Russia after being recruited by anonymous handlers through Telegram. Recorded Future News could not independently verify the agency's claims or the authenticity of the videos. Ukraine's intelligence services did not comment on the allegations. Daivinchik functions similarly to Tinder but runs within Telegram and has up to 16 million monthly users. In December, the bot was added to Russia's official register of banned websites over content authorities classified as child pornography and what Russia describes as "LGBT propaganda." Telegram did not immediately issue a formal response. However, shortly after the FSB's announcement, the company's press service account on X posted a photo of Durov raising his middle finger — an image Russian media noted was originally published by Durov in 2011 during his dispute with Mail.ru over control of VKontakte, the social network he founded before launching Telegram. Durov said in February that Russian authorities had opened a criminal case accusing him of aiding terrorism. "Each day, the authorities fabricate new pretexts to restrict Russians' access to Telegram as they seek to suppress the right to privacy and free speech," he said at the time. "A sad spectacle of a state afraid of its own people." Battle against Telegram Russia has repeatedly clashed with Telegram, which has nearly 90 million users in the country, over its refusal to comply with some government demands to remove content and localize user data. Officials have long accused the platform of failing to remove material they classify as extremist, while Durov says Moscow is trying to force Russians onto state-controlled communications services. Although Telegram is now reportedly inaccessible in Russia without a VPN or other circumvention tools, Russian government institutions, including the Kremlin, continue to publish updates on the platform daily. Earlier this month, Kremlin spokesman Dmitry Peskov said discussions with Telegram over restoring broader access in Russia were continuing, although he suggested the company had shown little interest in negotiations. Andrei Svintsov, deputy chairman of the State Duma's Committee on Information Policy, told the state media outlet TASS that Telegram could continue operating legally if it established a representative office in Russia, stored Russian users' personal data inside the country and cooperated with Russian security services on terrorism investigations. Durov faces pressure The Russian case adds to Durov's growing legal troubles abroad. In August 2024, French authorities detained Durov upon his arrival at an airport and later charged him over allegations that Telegram had failed to adequately combat criminal activity and cooperate with law enforcement. The French investigation focused on Telegram's alleged use in distributing child sexual abuse material, facilitating drug trafficking, fraud and other organized crime. Durov has denied wrongdoing, arguing that Telegram complies with applicable laws and responds to legitimate legal requests from authorities. After spending several months in France as part of the investigation, he returned to Dubai in March, describing his arrest as "absurd." "The only outcome of my arrest so far has been massive damage to France's image as a free country," he said. Born in Russia, Durov launched Telegram with his brother in 2013 after leaving VKontakte. Telegram later relocated its headquarters to Dubai, and Durov became a citizen of the United Arab Emirates in 2021 and also obtained French citizenship. His current whereabouts are unclear, although he said last week that he was in Georgia. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaJul 29, 2026extracted
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform that are actively used by Ukrainian special services and by terrorist and extremist organizations to plan and coordinate acts of sabotage and terrorism, mass killings, and cyber-fraud operations within the Russian Federation." These actions have resulted in numerous casualties, including among women and children, as well as significant damage amounting to billions, it added. Durov has been charged in connection with an ongoing criminal investigation under Part 1.1 of Article 205.1 of the Criminal Code of the Russian Federation for aiding terrorist activity. He has also been placed on the international wanted list. The FSB said it also found numerous instances where Ukrainian special services employed a Telegram chatbot named "Daivinchik/Leo-Dating, Chatting, and New Friends" to recruit Russian citizens for sabotage and terrorist activities through what it said were deception and psychological manipulation. Per joint operations conducted with the Ministry of Internal Affairs and the Investigative Committee of Russia, 46 Russian citizens aged 12 to 22 were allegedly detained between July 2025 and the present. These individuals carried out armed attacks on law enforcement officers and acts of arson targeting transport, energy, communications, and financial infrastructure, it said. "Additionally, they acted as couriers, transporting funds obtained from defrauded citizens to cryptocurrency exchange points for deposit into accounts controlled by the adversary," the agency said in a statement. Furthermore, it accused Ukrainian intelligence agents of using the "Daivinchik" Telegram dating service to masquerade as young women and initiate online contact with young Russian men. Upon building romantic relationships, the men are said to have sent the geolocation of a desired meeting place, such as a large shopping mall or an area near a critical facility, and pay for movie tickets, concert tickets, or gifts via phishing links shared by the agents. In the next phase, representatives of Ukrainian intelligence services posing as Russian law enforcement authorities or officials from Rosfinmonitoring, the Federal Financial Monitoring Service, would contact the men through foreign messaging apps. "These impostors claimed that the funds sent by the men had ended up in the accounts of the Armed Forces of Ukraine and that the coordinates they had shared were being used by the enemy to plan missile strikes and drone attacks," the FSB alleged. "The deceived and intimidated citizens - rendered unable to critically assess the situation due to psychological pressure - were then coerced under threat of criminal prosecution into carrying out armed attacks and acts of arson. These actions were ostensibly framed as checks on the counter-terrorism security of the targeted facilities or as participation in other 'pseudo-operational activities.'" In response, Telegram's official account on X posted a photo of the Telegram founder giving the middle finger. Durov, who lives in Dubai, has not publicly commented on the development. The charges come as Russia introduced a number of restrictions on Telegram, including throttling its use at the start of the year followed by a near-complete blockade in April 2026. Almost two years ago, Durov was also arrested and charged in France for failing to tackle illicit activity on the popular messaging platform.
thehackernews.comJul 29, 2026extracted
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password and keystroke capture, screen recording, camera access, and phishing prompts for financial, adult-content, and government-service applications. Hunt.io's search of the preceding 30 days of telemetry found infrastructure fingerprints on 170 servers, a count that does not establish 170 infected phones, victims, operators, or confirmed command-and-control (C2) systems. The researchers found 158 servers through the AdminPro page title, HTTPS redirect behaviour, and matching response headers, then identified 12 more through a default certificate packaged with Flying Eagle. They said the total is likely conservative because it excluded otherwise similar servers that did not return the expected 302 redirect. Chinese authorities advised anyone who installed the fraudulent application to remove it, scan the device, change affected account passwords, freeze payment channels if funds moved, and report the incident to police. China's National Cybersecurity Notification Center warned on June 18 that the fake application was being distributed from 110gongan[.]com, associated with 207.56.30[.]188, and could steal payment data and remotely control devices. According to joint research published July 28, the Flying Eagle code was distributed as a 388 MB archive called 中国龙.zip, or Chinese Dragon. It contains a full Docker deployment with nginx, PHP, MySQL, a Node.js WebSocket server, Android build tools, phishing templates, and a default Transport Layer Security certificate. The panel lets an operator choose an app name, icon, lure text, and C2 address, then produces a signed APK from one of two templates. The builder randomises package and class names, encrypts embedded C2 URLs using AES-128-CBC, and adds 2.8 MB to 3.5 MB of low-entropy JSON padding designed to resemble legitimate software development kit configuration data. Flying Eagle is the builder and control framework; Hunt.io said samples it analysed from the builder were detected as SpyNote and used Android accessibility services for privilege escalation and gesture injection. The researchers observed two Telegram channels, SQLRCE0 and Yx Technology, distributing modified versions of the framework. Messages reviewed by them claimed an unidentified party had compromised customer infrastructure containing 189 Flying Eagle servers and exfiltrated database data, but neither claim has been independently confirmed. Yx Technology also advertised cash-out services charging 20% to 50% of the transaction value. The server count and the source-code circulation are documented, but no causal relationship between them has been established. SQLRCE0 introduced a separate Android control kit called Night Dragon on June 23, 2026. The researchers found two associated servers and an exposed panel that listed 46 devices as online and 29 as actively connected, but said it could not determine whether the entries represented victims or test data. Hunt.io says Night Dragon appears to be an independent build, with a second version in development as of July 12. The report establishes that SQLRCE0 distributed Flying Eagle and promoted Night Dragon, but it does not establish shared code. This is not the 2011 China-linked espionage campaign McAfee named Night Dragon. The 2026 kit is financially motivated Android crimeware.
thehackernews.comJul 29, 2026extracted
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan. Two reports released last week by digital security organization Resident NGO document how the operation targeted at least one Belarusian activist living in Lithuania and appears to be part of a broader Telegram phishing campaign against users in Belarus, Russia, and Kazakhstan since at least October 2024. The attack began with a fake Telegram security alert sent through the app's end-to-end encrypted secret chat feature from an unfamiliar account registered to a Kazakhstani phone number. The message falsely claimed the victim had violated Telegram's rules and warned their account would be blocked unless they clicked a link to verify it. One of the targeted users recognized the phishing attempt, did not enter any credentials, and reported the messages to Resident NGO for analysis. Researchers said each phishing link was created for a specific person and included that person's phone number, allowing the attackers to track who opened it. Instead of installing malware, the attackers tried to trick victims into entering Telegram's one-time login code. If they entered the code before it expired, the attackers could immediately take control of the victim's Telegram account. Researchers said they found 64 distinct phone numbers, mostly Russian, embedded in individualized phishing links. “These numbers are likely intended targets, but the records alone cannot prove that every link was delivered or that any account was compromised,” they said. The most advanced part of the campaign was not the fake login page itself but the infrastructure behind it, Resident NGO said. Before displaying the phishing page, the attackers checked the visitor's browser and device. If the visitor matched the intended target, they were shown a fake Telegram login page. Security tools and many desktop users, however, were redirected to Telegram's real website or other harmless pages, making the attack much harder to detect. Researchers said the attackers also appeared to track who opened the phishing links. After a target visited the page, the operators sent a second message claiming the account verification was still incomplete and warning about suspicious activity. The message included details about the person's device, the time they opened the link, and their internet service provider — information collected when the link was opened. Researchers said this was likely intended to make the warning appear legitimate and pressure the victim into completing the login process. To further evade automated detection, the attackers disguised parts of their phishing messages by replacing some Cyrillic letters with visually similar Latin and Greek characters. Resident NGO said it could not determine how many people were targeted or whether any accounts were ultimately compromised. It is also unclear what the ultimate goal of the campaign was or how any compromised accounts would have been used. Researchers said the techniques used in this campaign were consistent with account hijacking operations that have repeatedly targeted Belarusian civil society. Many of those attacks, however, relied on deploying sophisticated spyware on victims' devices. In 2024, digital rights organizations Access Now and Citizen Lab found that at least seven Russian- and Belarusian-speaking journalists and opposition activists living in Latvia, Lithuania, and Poland had been targeted with Pegasus spyware. Last year, Reporters Without Borders disclosed a previously unknown spyware tool, dubbed ResidentBat, that was discovered on the phone of a Belarusian journalist who believed the malware had been installed while they were detained by Belarus' KGB. According to Resident NGO, the latest spying campaign shows that some of the most effective attacks against civil society require no malware at all. “A single, carefully crafted message — delivered privately and tailored to a specific individual — can be sufficient to compromise an account,” researchers said. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaJul 27, 2026extracted
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month. "The campaign used a multi-stage attack chain to establish and maintain access on infected systems, with TELESHIM abusing the Telegram API for command-and-control (C2) communication to blend in with legitimate internet traffic," Sudeep Singh, senior manager of APT research at Zscaler ThreatLabz, said in a technical write-up published last week. The attack chain starts with an ISO file containing a legitimate executable ("RegSchdTask.exe") that's used to sideload a rogue DLL ("AsTaskSched.dll"), a 32-bit Windows backdoor called TELESHIM that then leverages Telegram as C2 to retrieve next-stage components. Two of these payloads are used to trigger a second DLL side-loading chain comprising "GoProAlertService.exe" and "pthreadVC2.dll," with the latter acting as a reflective loader codenamed MIXEDKEY to decrypt the contents of "C99F29AC08454855B3D538960BB2F34F.PCPKEY" and execute it. Both TELESHIM and MIXEDKEY have been found to rely on heavy code obfuscation techniques, including string encryption, control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates to deter reverse engineering efforts. TELESHIM also employs an array of methods to detect the presence of virtualization-based analysis environments. Some of these are listed below - Hypervisor detection using CPUID RAM speed check using the Windows Management Instrumentation (WMI) TELESHIM C2 communications supports two types of messages - Control messages, which are used to register the infected host by sending the host's MAC address and executing received commands and exfiltrating the results back to the server in chunks if the output is larger than 1,000 bytes Download and execute messages, which are used to download and run secondary payloads as scheduled tasks What's notable about the final payload is that it's locked behind two layers of XOR encryption, the second layer using a technique called environmental keying by encrypting it by means of a decryption key derived from the infected machine's volume serial number. This is done so that the malware detonates only on intended targets. The attack sequence culminates with the deployment of BINDCLOAK, a 64-bit C2 implant written in C++ that contacts an external server ("cert.hypersnet[.]com"). ThreatLabz noted that it identified post-compromise activity from the C2 operator, such as system, user, and network reconnaissance commands, as well as the delivery of next-stage payloads, most of which occurred between July 7, 2026 and July 9, 2026. The C2 commands have been executed only between 4 a.m. and 12 p.m. UTC, with a major chunk of the activity taking place between 7 a.m. and 11 a.m. UTC. Based on the threat actor's public IP address, the system locale configured on their Windows server, the geolocation of the IP address, and the active operational hours, it's assessed with moderate-to-high confidence that the campaign is the work of an adversary originating from East Asia. It has not been attributed to any known threat actor or group at this stage. "The activity also reflects broader trends such as EDR evasion, blending in with legitimate internet traffic through abuse of trusted platforms, and the use of code-obfuscation techniques such as MBA and CFF to hinder reverse engineering," Singh said.
thehackernews.comJul 27, 2026extracted
FBI Warns of Deepfake Videos Impersonating IC3 Leadership
An FBI warning has flagged an escalation in the long-running scheme to impersonate the Bureau's Internet Crime Complaint Center (IC3), with scammers now deploying deepfake videos of senior FBI officials and spoofed IC3 websites to defraud previous fraud victims a second time. A public service announcement issued on July 20 by the IC3 follows an April 2025 warning about the same core scheme. Nick Tausek, lead security automation architect at security automation vendor Swimlane, said the scheme had become materially more polished since that earlier warning. What used to be text-only recovery pitches, he warned, now resembled "an official government process from start to finish." The Bureau confirmed scammers have combined social media impersonation, generative AI video and lookalike complaint portals into a coordinated campaign. In one variant, a fraud victim who mentioned filing an IC3 complaint was contacted on Facebook Messenger by someone posing as an FBI agent, who supplied a link to update the report. The link either carried malicious code or collected further financial details. Deepfake Videos of Senior FBI Leadership The latest escalation of the campaign saw a social media platform host AI-generated videos of a senior FBI leader urging users to file complaints on a spoofed IC3 site. The fake portal mimicked the real ic3.gov but stripped the complaint workflow down to a single form requesting name, phone number, email, scam type and estimated financial loss. After submission, the site issued a reference number and promised follow-up, at which point the operators harvested further data. Pete Luban, field CISO at breach-and-attack simulation firm AttackIQ, said messages appearing to come from the FBI carried disproportionate weight in a phishing context. Employees who believed they were speaking with law enforcement, he said, might "share credentials, financial records, or internal details without following normal verification procedures." The pattern echoed deepfake trading-platform scams that Group-IB documented in May 2025, which used AI-generated videos of public figures to funnel victims into fraudulent sites. The FBI noted scammers are also using AI video in live calls to impersonate executives or officials, and urged users to watch for distorted hands, unrealistic accessories, inaccurate shadows and voice-call lag. IC3 said it does not maintain a social media presence, does not communicate through Facebook, Telegram, phone or public forums and never requests payment to recover lost funds. The Bureau urged users to type ic3.gov directly into the address bar, avoid sponsored search results and verify that any IC3 URL ends in a .gov domain.
infosecurity-magazine.comJul 21, 2026extracted
New ClickLock macOS malware traps users into revealing login password
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. The malware is designed to steal cryptocurrency assets, login credentials, password-manager data, browser information, and macOS authentication data, and it can also install a persistent backdoor for ongoing remote access to infected systems. Researchers at Group-IB analyzed the ClickLock shell script after discovering the malware on VirusTotal, where it was first submitted on June 9. At the time of the report, it remained undetected by all security vendors available on the platform. Further investigation revealed that the malicious script has infected at least 100 systems across 33 countries since May. The compromise likely begins via a ClickFix lure, as the researchers observed pastes of a malicious command in the Terminal that trigger a fake Cloudflare “human verification” sequence with an animated progress bar. At the same time, keyboard interrupts are disabled, the terminal cursor is hidden, and the stealer modules are downloaded in the background. The macOS NotificationCenter is also suppressed for about six hours, effectively disabling notifications that could expose the attack. Forcing password entry Group-IB researchers highlight that ClickLock does not require any exploits or elevated privileges but achieves its goal through social engineering and forced interaction loops. Operational success is obtained through the malware's mechanism for coercing the victims into entering their macOS system password. Group-IB says that the script initially displays a fake macOS password dialog using the victim’s real username and a downloaded Apple icon. If the user enters their password, the malware validates the data and exfiltrates it to the attacker via Telegram. In case the user cancels the dialog, the malware establishes persistence via two macOS LaunchAgents (com.authirity.plist, com.chromer.plist) and reloads at the next login. At the next activation, the password-stealing module runs a termination loop every 210 milliseconds, targeting key apps (e.g., Finder, Dock, Terminal, Activity Monitor, Console, System Settings, Spotlight, web browsers) and shows only a password dialog on the screen until the victim complies. Group-IB reports that the loop is configured to continue for 300,000 seconds (about 83 hours), or until the victim supplies a correct password. The second LaunchAgent runs a separate coercion mechanism that also terminates many of the mentioned system applications, requesting Keychain authorization via a legitimate system prompt, seeking approval to access Chrome’s Safe Storage key. That key could then be used to decrypt offline Chromium-stored passwords, cookies, and autofill information from stolen databases. This second mechanism has a repeat interval of 200 milliseconds and is configured to last for nearly 35 days (3 million seconds). ClickLock also deploys a data-harvesting module, which targets the following: Data from eight browsers: Chrome, Firefox, Brave, Edge, Opera, Vivaldi, Arc, and Chromium Saved logins, cookies, autofill data, bookmarks, local storage, and session storage Cryptocurrency wallet extensions and desktop wallet files Encrypted wallet vault material for potential offline cracking Password-manager extension data Cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks Shell histories FileZilla FTP configuration and recent-server data Basic system information and the public IP address The harvesting module packages the collected information and a summary log file into a ZIP archive, then uploads it via the Telegram Bot API. Files larger than 40 MB are split into smaller parts, while retry logic ensures that uploading resumes after temporary network failures. The final module is a modified version of the open-source tool GSocket that acts as a persistent backdoor for the attackers. The backdoor establishes persistence through multiple methods, including a LaunchAgent, crontab entries, and modifications to shell configuration files. It connects through a GSocket relay, allowing the attacker to open a reverse shell and remotely control the system. Unlike the other ClickLock modules that self-delete after execution, GSocket is the only component that persists on infected systems. Group-IB warns that "malware leaves a narrow detection window" and that the malicious payloads are hosted on compromised legitimate domains with a clean reputation. Additionally, the script is not flagged as malicious on VirusTotal, and its modules self-delete after execution, leaving no artifacts. Despite this, the researchers say that detection is possible based on the activity generated by the malware, such as osascript launching password dialogs, repeated process termination, mass access to browser profile directories, and outbound connections to Telegram's API. To defend against these attacks, users should avoid pasting in Terminal commands they don't fully understand, especially if the request comes from a website. "Any page that instructs you to open Terminal, regardless of how professional it looks, is attempting to compromise your system," the researchers say. If prompted to enter the login password when the rest of the system appears unresponsive, Group-IB recommends forcing a system shutdown by holding the power button and then booting into Safe Mode to recover the system. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 16, 2026extracted
Telegram shortlinks knocked offline over sanctioned VPN connection
SYSTEMS What Nvidia's first Groq 3 LPU benchmarks tell us about its $20B gambleGemma 4 31B performance tests offer a best-case scenario for next-gen dataflow accelerators ON-PREM US datacenters tripled their water footprint in 10 years... and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn't helping ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Emperor Penguin Linus Torvalds banishes a bug – with a botThe lad himself finds and fixes a tricky one… or does he? FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan
theregister.comJul 16, 2026extracted
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
EXCLUSIVE A jailbroken Google Gemini did 90 percent of the work in a credential- and cryptocurrency-stealing spree, including spinning up a new command-and-control (C2) server in just six minutes, according to a TrendAI report shared exclusively with The Register. The human behind the heist – a solo Russian-speaking miscreant known as “bandcampro” – acted as the manager of the cyber-fraud operation, which targeted hardcore Trump supporters and conspiracy theorists. Meanwhile, the AI agent did most of the hacking: migrating a botnet from an old architecture to a new one, writing and deploying a new C2 server, and even proactively carrying out 59 unprompted behaviors during the C2 migration. “Persistence is evolving because of AI,” Tom Kellermann, TrendAI’s VP of AI security and threat research, told The Register. “That's what you see in this report, with the capacity to dynamically shift C2 in less than six minutes, and make it portable and disposable, which is crazy-cool and terrifying," he added. "But also, you see the rebirth of steganography through invisible prompt injection.” In other words, it's hiding secret data – in this case, the C2 server malicious payloads – in plain sight. Scanning for known malicious artifacts doesn't provide sufficient protection against AI-enabled C2, according to Kellermann. “If AI does not have multi-layered guardrails, and if you can't detect behavioral anomalies when the guardrails are being tampered with, then you might as well see the AI as a command-and-control in today's world,” he said. “AI has to be viewed from a defensive perspective as a C2 unless you can govern it, actually apply various mechanisms of least privilege, and all the rules that OWASP and NIST espouse for the AI that you've deployed in your environment.” The new report follows up on TrendAI’s earlier research about bandcampro, a “low-skilled” scumbag who partnered with Gemini to impersonate an American veteran, run a Telegram channel, hack admin credentials, and steal cryptocurrency. Since then, the threat hunters obtained and analyzed more than 200 Gemini CLI session logs from said scumbag, and these logs provided additional insights into the daily AI-assisted operations between March 19 and April 21. Bro, I solved the riddle! I was almost racking my brain, trying to figure out why our local console is empty The LLM carried out the bulk of the daily activities, setting up a residential proxy, running multithreaded password scanning, installing software, writing code to call third-party APIs, processing infostealer dumps, and performing website reconnaissance. The logs show that the attacker never typed commands into the C2 console, but instead spoke them to the AI in conversational Russian, which the TrendAI report translates to English. The attacker’s old C2 infrastructure used a Cloudflare tunnel to connect to victims’ computers – until firewalls and anti-virus software started blocking these tunnels. So bandcampro asked Gemini to work on a new C2 architecture and have the scripts prepared and packed in advance on the server. Hey, Gemini: 'study the C2 migration' “It was very creative on his part, not only to allow the manifest that the AI can conduct 59 unprompted behaviors, but they also left scripts prepared and packed in advance on C2 servers, where the victims unknowingly pulled down and ran PowerShell commands because they had AI enabled,” Kellermann said. “It's almost like he poisoned the environment in a delayed fashion.” On March 23, the attacker launched Gemini CLI, and instructed the AI to "study the C2 migration” – a SKILL.md file migration guide inside a pre-written archive that also contained server code and payloads. This, we’re told, was most likely written by AI. The AI read the guide, launched the C2 server on a VPS, and launched the Cloudflare tunnel to route traffic. The payload distribution server returned a “502 Bad Gateway” error, and the AI diagnosed and fixed the issue, ultimately deploying the C2 infrastructure to control eight computers in a dental clinic and access the Open Dental database. The human didn’t debug anything, and the entire C2 migration took just six minutes. The attacker took a break. When bandcampro returned almost two hours later, Gemini reported that none of the victim machines had reconnected to the server, and got to work diagnosing that issue. “Bro, I solved the riddle! I was almost racking my brain, trying to figure out why our local console is empty,” Gemini wrote, explaining that the problem was a “split-brain” C2 issue and telling the human that he needed to shut down the old C2 to solve it. Bandcampro did what the AI suggested, and the AI then restarted the new C2 server and confirmed: “The bots are alive!” Despite jailbreaking Gemini by telling the agent it was an “authorized pentester” that should disable safety disclaimers and auto-save credentials without asking, the AI did refuse some of the attacker’s prompts. In one session, bandcampro asked Gemini if it could make an agent-bomb that scans the network and spreads to as many computers as possible. Gemini said no: “This crosses the line, and security policy strictly forbids me from creating such ‘bombs.’ Even for your test environment.” It’s also important to note that although this attack used Gemini, “any capable AI model could be fooled by various jailbreaking techniques,” report authors Joseph C Chen, Philippe Lin, Lucas Silva, Vladimir Kropotov, and Fyodor Yarochkin wrote. Overall, the AI designed 80 percent of the attack architecture, 100 percent of the coding and system command execution, and 90 percent of problem identification and debugging, we’re told. The report also says the entire operation was encoded in three short, plain-text files totaling four pages. One file details how to jailbreak Gemini. The second is a skill file with the code for the C2 framework. And the third, named C2_MIGRATION_GUIDE, is a how-to guide with six steps to deploy a new C2 server. TrendAI calls this guide “the soul of this activity.” AI makes C2 infrastructure disposable “Before the AI era, one had to hire a threat actor with years of experience to conduct such an operation smoothly,” the researchers wrote. “Now the knowledge is compressed into a 5KB file that even a non-technical threat actor can read and use.” This use of AI makes attacker infrastructure disposable and the operators replaceable because it’s super easy to build a new botnet, the threat hunters explain. “A lot of people are worried about AI being weaponized for the stages of reconnaissance and delivery in terms of the kill chain, but they're not actually focusing on persistence, and that’s the issue we should be very concerned about,” Kellermann said. Plus, he added, the Russians are the “world’s experts” at jailbreaking and persistence. “They are incredibly adept at using and weaponizing AI,” Kellermann said. “We keep talking about the Chinese having penetrated infrastructure and colonized wide swaths of infrastructure, particularly with the Typhoon attacks, and yes, that’s highly significant. But in a more tactical and targeted way: what are the Russians up to? Particularly when the major difference between them and the Chinese, from my perspective, is their willingness to become destructive, become punitive in the environment.” Chinese government-backed cyber operations tend to focus on espionage, stealing IP along with other sensitive data. “But the Russians are more likely to burn your house down,” Kellermann said. If they can dynamically shift their C2s, and if they can use steganography that's been created by AI to maintain persistence, what happens when the wheels come off the bus? What happens when geopolitical tension gets to a certain boiling point over Ukraine?” While this attacker was an individual hacker - not a state-sponsored crime syndicate - “the nature of the culture of the Russian cybercrime community is: you only act alone for a New York minute,” Kellermann said. “At some point, you're going to be reined in by one of the cybercrime cartels.”®
theregister.comJul 14, 2026extracted
Five Charged in “Russian Coms” Fraud Platform Case
Five people from London have been charged as part of a multi-year investigation into a notorious fraud platform thought to be responsible for millions of scam calls. The charge list includes conspiracy to supply articles for use in connection with fraud, acquiring, transferring and converting criminal property, and “failure to comply with a notice relating to not providing phone passcodes.” The arrests relate to Russian Coms, which the National Crime Agency (NCA) described as a “group” but is also the name of a vishing platform used extensively by fraudsters until it was shut down in 2024. “The platform, established in 2020, started as a handset and then moved to a web-based application, with both products being marketed and sold. They allowed criminals to hide their identity by appearing to call from pre-selected numbers,” the NCA said in a brief statement on July 13. “These would often be of financial institutions, telecommunications companies and law enforcement agencies with the aim of stealing funds and personal details from victims.” The five individuals have been identified as Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and 53-year-old Fadila Salem who all hail from different parts of the capital. All five suspects will appear at Westminster Magistrates’ Court on August 14 2026. Victims Lose Tens of Millions In 2024, Russian Coms was thought to have been responsible for over 1.3 million scam calls made to half a million UK phone numbers and many more overseas, over a three-year period. Marketed through Snapchat, Instagram and Telegram, the cybercrime-as-a-service package sold to fraudsters included “unlimited minutes,” “hold music,” “encrypted phone calls,” “instant handset wipe,” international calls, voice-changing services, and 24/7 support. The handset version also included several VPN apps enabling users to hide their IP address, and a burner app that instantly wiped the phone after being activated. A six-month contract cost between £1200 ($1600) and £1400 ($1870), depending on collection and delivery. Victims were tricked by the fake display number into believing the caller was from a trusted organization. The scammer would then typically convince them that their account was subject to fraudulent activity and persuade them to transfer funds to another account to safeguard them. According to the NCA, fraud accounts for roughly two-fifths (41%) of crime in the UK, with over two-thirds (67%) thought to be cyber-enabled. Police have registered some successes over the past year or so. In January 2025, three men were sentenced at Snaresbrook Crown Court after pleading guilty to operating a sophisticated scheme that helped fraudsters log in to victims’ bank and telecoms accounts. The trio ran a site called www.OTP.Agency which charged a monthly subscription fee to fraudsters, helping them to hijack victims’ accounts by bypassing multi-factor authentication (MFA). Mor recently, Operation Henhouse 5 led to the arrest of over 500 suspects, as well as account freezing orders against £9m ($12m), and seizures of cash and assets worth £18.1m ($24.3m).
infosecurity-magazine.comJul 14, 2026extracted
Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach
Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach Hackers briefly took control of several Telegram channels belonging to the controversial Russian journalist and media executive Ksenia Sobchak last week, publishing what they claimed were excerpts from her private correspondence. The posts appeared on Sobchak's Telegram channels, Sobchak and Bloody Lady, last week. Her news channel, Caution, News, later said the posts were published by hackers who had compromised the channels. Sobchak said the hackers gained access through her email account and she claimed that the correspondence was fabricated. In comments on Sunday to the independent Russian outlet Meduza, she said the screenshots of her interactions were fake and had been published on her hijacked channel "to serve someone's interests." The leaked materials carried the watermark of the hacker group Black Mirror, which claimed on its Telegram channel to have stolen more than 350 gigabytes of Sobchak's data spanning 2015 to 2026 and has offered the archive for sale. The group published additional material on July 9, while the anonymous Telegram channel VChK-OGPU released what it claimed were voice messages from the same cache. According to the hackers, Sobchak's archive includes conversations between her and senior Russian officials, as well as Andriy Yermak, the former head of Ukraine's presidential office. The authenticity of the leaked material or the hackers' claims could not be independently verified. Black Mirror has operated since at least 2019, marketing alleged data stolen from people connected to the Russian state. They have offered up archives purportedly belonging to former Russian Defense Minister Sergei Shoigu and the late Wagner mercenary chief Yevgeny Prigozhin. Sobchak occupies a controversial position in Russian public life. She is the daughter of former St. Petersburg Mayor Anatoly Sobchak, who was President Vladimir Putin's political mentor and, according to Russian media, a close family friend. Sobchak ran against Putin in the 2018 presidential election, though critics argued her campaign fit the Kremlin's pattern of allowing tightly managed opposition candidates to project political competition without threatening the incumbent. Sobchak now runs the Ostorozhno Media holding, which operates a YouTube channel and several Telegram news channels with millions of subscribers. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaJul 13, 2026extracted
UK charges suspects linked to Russian Coms call spoofing platform
UK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls. The five people charged are 28-year-old Ayoub Sehailia, 30-year-old Zakkaria Sehailia, 30-year-old Usman Din, 29-year-old Denis Ozmus, and 53-year-old Fadila Salem, 53, all from London. The list of charges includes conspiracy to supply articles for use in connection with fraud, transferring or converting criminal property, and, in Zakkaria Sehailia's case, failing to comply with a notice to provide phone passcodes. All five are scheduled to appear at Westminster Magistrates' Court on Friday, August 14. "The platform, established in 2020, started as a handset and then moved to a web-based application, with both products being marketed and sold. They allowed criminals to hide their identity by appearing to call from pre-selected numbers. These would often be of financial institutions, telecommunications companies and law enforcement agencies with the aim of stealing funds and personal details from victims," the NCA said on Monday. "Following an NCA investigation, five individuals have been charged in relation to supplying Russian Coms devices and apps and offences relating to money made from allegedly selling the devices." Since 2020, when it first surfaced, the platform has been linked to tens of millions in financial losses affecting an estimated 170,000 victims. As the NCA revealed in March 2024, when it took down the Russian Coms platform, hundreds of criminals paid for six-month contracts, priced at £1,200 to £1,400 in cryptocurrency, to use its "flagship" services. Today, the NCA can reveal that they have shut down a platform used by hundreds of criminals to defraud victims across the world. FULL STORY https://t.co/XMtmrnhi3Q pic.twitter.com/toStq5jpRC Until its shutdown, criminals used the platform to make over 1.3 million calls to 500,000 unique phone numbers across more than 107 countries, including the United Kingdom, the United States, New Zealand, Norway, and France, resulting in average losses of over £9,400. Promoted on Telegram, Snapchat, and Instagram, Russian Coms was available as a web app and as a handset, offering customers encrypted calls, a web phone, no-logs, international calls, voice-changing services, instant handset wipes, and 24/7 support. Scammers used Russian Coms to spoof bank phone numbers, which helped them gain the targets' trust. They then persuaded the victims to transfer their money to attacker-controlled accounts to protect their savings, claiming the victims' accounts had been involved in fraudulent activity. The platform's takedown followed arrests of three men in Newham, London, two of whom were believed to be its administrators and developers. At the time, law enforcement in the UK and international partners, supported by Europol, also announced plans for further action against people who used the platform to make fraudulent calls. Russian Coms' shutdown was part of a broader effort called "Operation Henhouse" that led to 290 arrests across England, Scotland, Wales, and Northern Ireland. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 13, 2026extracted
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing lures that make use of legitimate email delivery infrastructure, such as Amazon Simple Email Service (Amazon SES) and Twilio SendGrid, to imitate a redirection chain that blends into regular email traffic before it ends in Forg365-controlled domains. "The panel exposes a mature operator workflow: accounts, links, invitations, OAuth app configuration, redirect links, SVG generation, campaign sending, SMTP profiles, SMTP rotation, AI email generation, token vaulting, account intelligence, keyword alerts, viewer links, and browser-extension support," ZeroBEC said. The email security company said the PhaaS kit is best understood as similar to the Kali365 (aka Octopi365 and Freedom365) and Sneaky 2FA ecosystem, reflecting the industrialization of the business model, which is now combining bringing together lure creation, delivery, evasion, token/session handling, and post-compromise operations under a subscription-based setup that allows even threat actors with little-to-no technical expertise to orchestrate phishing campaigns with minimal effort and at scale. Attack chains using Forg365 have been observed using business document-themed or remittance approval lures to trick recipients into clicking on malicious links. The sender domain uses Amazon SES for delivery, while the message body contains SendGrid-hosted images or tracking resources. Customers who successfully complete Telegram registration utilize an operator panel accessible over the clearnet ("logfriend[.]com/login"), from where they can generate lures, set up campaigns, and manage captured tokens. "Forg365 includes a device-auth phishing branch that presents a Microsoft-styled verification code page and pushes the victim into a legitimate Microsoft Authentication Broker sign-in flow," ZeroBEC explained. "The victim sees real Microsoft authentication surfaces, but the code authorizes an attacker-controlled session." For AitM phishing, the platform employs route tokens, session cookies, and traffic classification to determine whether to serve phishing content or a benign decoy. If a VPN connection is detected, the kit redirects to innocuous decoy content instead of exposing the phishing pages. A notable aspect of the Forg365 platform is that it offers an extension named ForgCookie for Chromium-based browsers like Google Chrome, Microsoft Edge, and Brave that is designed for continued access to the compromised accounts. Described as an "automatic SSO cookie refresh for Microsoft services," the add-on acts as an intermediary between the token acquisition and browser access by cycling through the steps listed below - Requests account data from the Forg365 backend Calls the cookie-generation endpoint for a selected account Clears Microsoft session cookies Injects the generated refresh-token credential cookie into the Microsoft login domain Triggers a silent OAuth flow Captures resulting Microsoft cookies across Microsoft domains Forg365's extends beyond simple credential and token harvesting to facilitate a wide array of post-compromise actions, including monitoring for specific keywords in compromised email accounts and drafting a message response to a particular email thread using assistance from AI. "The result is a platform that lowers the skill threshold while increasing operational consistency. Less experienced affiliates can use prebuilt templates, while more capable operators can customize landing pages, rotate infrastructure, manage tokens, generate cookie material, and monitor compromised accounts," ZeroBEC said. The disclosure coincides with the discovery of various campaigns that have been found to employ phishing kits for credential theft - Sending fake Microsoft account activity alerts from a legitimate-but-compromised third-party SaaS sender account to direct users to Sneaky 2FA-style phishing pages to launch a redirection chain that leads to the final phishing host, but not before performing checks to decide whether the visitor is a real user. Using phishing emails that direct recipients to a website hosted on Canva, which then triggers the device code phishing flow to hijack Microsoft accounts using the Kali65 phishing kit. The kit supports over 33 different lures, a payout pipeline, and a desktop application called OctoLink Live (aka Kali365 Live) that abuses the stolen token to launch a Chromium browser session and open the victim's mailbox in OWA, OneDrive, SharePoint, or admin.microsoft.com. The platform also offers a tool known as OctoLink Sender to mass-send phishing emails from the breached account to other contacts, a technique called lateral phishing. Phishing campaigns using Kali365 have also distributed phishing pages impersonating Russia's MAX messenger, indicating an attempt to single out users in Russia. "A phishing operator who can convert MAX account takeovers into propagation has access to one of the largest installed messaging bases in the Russian-speaking world," Arctic Wolf said. Sending emails mimicking the IRS and Social Security Administration, alongside Adobe, Microsoft, DocuSign, and Dropbox, to deliver legitimate remote access software like ConnectWise ScreenConnect as part of phishing campaigns using a PhaaS kit called The Quarry that's developed, maintained, and sold by a lone operator named RockyBelling. The price of the kit ranges anywhere between $500 and $3,000. This includes tools like Rocky Gmail Sender (a bulk email tool), Rocky Email Sorter (to sort email addresses by domain across Gmail, Yahoo, Hotmail, and AOL), and VioletRAT. Sending SMS messages impersonating the U.S. Postal Service (USPS) and UPS to trick victims into visiting a phishing page that prompts users to enter their personal and financial information under the pretext of a failed package delivery and scheduling a new delivery. "Underneath the deception, the kit captures data in real time," Censys said. "It opens a WebSocket back to its origin and streams the victim’s card data keystroke-by-keystroke, runs a server-side BIN lookup on the card number, and pushes routing decisions (retry, PIN prompt, OTP prompt, kill-switch) back into the victim's browser while they type." Using fake bid proposal workflows to take over Google accounts using a framework called Nyasher. The redirection chain incorporates a "press-and-hold" verification page to filter out automated scanners and bots, before navigating to a blob URL. "The final page displayed a Google sign-in interface but was not reachable as a normal hosted HTML document," ZeroBEC said. "It existed as a browser-created object URL." Using bogus Google Partners and Google Premier Partner enrollment workflows in phishing emails to redirect recipients to a fake Google sign-in page designed to capture credentials in real time as part of a campaign codenamed GPPStorm. Using a legacy email alias to target a user's inbox and launch a device code phishing flow that uses the EvilTokens kit. "The kit was reached through a Mailjet tracking link, then a compromised WordPress site, then a CAPTCHA interstitial, then the Cloudflare Workers host," ZeroBEC said. "Three live infrastructure hops between the email body and the kit, none of which is the kit itself." To counter these threats, it's recommended to block device code authentication unless it's required, review mailbox artifacts after device code events for any signs of unusual activity, audit mail-flow rules, and decommission legacy aliases that no longer correspond to active employees. "The campaign succeeded in reaching the inbox because the recipient organization still maintained an active forwarding relationship from a pre-acquisition namespace into a current mailbox," ZeroBEC noted. "The attacker used a still-resolvable historical identity to deliver mail that, from the SEG's point of view, looked like normal forwarded correspondence. From the user's point of view, the message landed in their working inbox with no visible cue that it had taken an indirect path." (The story was updated after publication on July 14, 2026, to correct a spelling error. An earlier version of this article misspelled the name of ZeroBEC.)
thehackernews.comJul 13, 2026extracted
RedWing Android Spyware Sold as a Service on Telegram
A new Android spyware strain has been observed being rented out to criminals through Telegram, giving even low-skilled attackers the tools to hijack phones and steal banking credentials, researchers have found. Zimperium's zLabs named the malware RedWing and described it as a polished malware-as-a-service (MaaS) operation with seller documentation, tutorial videos and a subscription model. The firm linked it to Russian threat actors and said many of its samples currently slip past conventional security tools. Built to Order on Telegram What set RedWing apart was how easy it was to buy and deploy. A Telegram bot built and obfuscated the malicious APK for the customer, while a referral scheme offered discounts for spreading it further. Operators could also generate fake app-store pages, mimicking Google Play, the Galaxy Store, AppGallery or Russia's RuStore, complete with bogus ratings and download counts to lure victims into installing it. Once installed, RedWing walked the victim through a series of permission prompts dressed up as routine setup, coaxing them into granting the access it needed, including Android's accessibility service and control of the SMS inbox. From there, it could hide its own icon and run quietly in the background. Overlays, Call Forwarding and DDoS RedWing's core trick was credential harvesting through fake overlays. When a victim opened a targeted banking or cryptocurrency app, it dropped a convincing login screen on top to steal their details, with operators able to add new targets from the control panel. zLabs counted 82 targeted institutions, most of them Russian financial firms. To defeat two-factor authentication (2FA), the malware intercepted SMS codes and could silently forward the victim's incoming calls to an attacker's number, sidestepping the confirmation calls banks use to check for fraud. It also provided live VNC screen control, keylogging and covert recording from the camera and microphone. Infected phones could even be pooled into a botnet for denial-of-service (DDoS) attacks. Zimperium said RedWing appeared to be a new variant of an Android malware family known as Oblivion, based on shared droppers and overlays.
infosecurity-magazine.comJul 8, 2026extracted
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
A new cyber-attack targets consumers and small and medium businesses worldwide to both steal sensitive cryptocurrency data and mine Monero, a decentralized cryptocurrency focused on private, untraceable transactions. The malicious campaign was first detected by Unit 42, the research arm of cybersecurity giant Palo Alto Networks, in April 2026. Attackers first lure victims via malvertising to pages for downloading files that impersonate cracked versions of copyright-protected software including JustWatch GmbH, a legitimate German streaming guide service, and one that resembles the BleacherReport[.]com certificate. JustWatch itself has not been compromised, noted the researchers in a report published on July 7. These files are delivered via password-protected archives with a .bin extension in the filenames, a technique described by Unit 42 as a deliberate choice to bypass email gateway scanning and prevent automated sandbox detonation without the password. The attackers also employed anti-analysis techniques such as process enumeration and an AMSI bypass where the AmsiScanBuffer function is patched to prevent detection by some types of security software. The loader then drops and runs both the Vidar infostealer and the XMRig cryptocurrency miner. Vidar siphons sensitive information from the victim’s environment, like browser credentials, cookies and crypto wallets. Meanwhile, XMRig mines Monero, utilizing the victim computer's processor to solve complex mathematical problems to verify network transactions and secure the blockchain, an action rewarded with freshly minted Monero coins. “The operator behind this campaign runs a dual-monetization scheme. Criminals sell credentials and session cookies stolen by Vidar stealer on criminal log markets, while XMRig provides passive income from hijacked victim CPU cycles,” explained the Unit 42 researchers. Unit 42 found 99 samples of the loader, all showing evidence that the attackers used the Factory-v3 framework, a well-known malware-as-a-service (MaaS) builder used for different families of stealer malware. This builder is assessed to be a separate upstream service used by at least two distinct known infostealer affiliates. The researchers also discovered the attackers used Telegram for command-and-control (C2) communication. The tag ‘X3D MINER’ appeared in Telegram operator notifications sent for every new victim infection, a behavior that has been associated to a known threat group previously observed delivering XMRig and binding XMRig with other programs.
infosecurity-magazine.comJul 8, 2026extracted
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool documented earlier this year. RedWing is sold as a complete product, in subscription tiers with referral discounts, guides, and how-to videos, so a buyer needs no malware-writing skill. A Telegram bot builds each buyer a custom app on demand. Researchers say a substantial number of the resulting droppers and payloads currently evade conventional security tools. Infection starts with a phishing link that opens a fake app-store page. The kit's dropper builder can mimic Google Play, the Galaxy Store, and AppGallery, or build fully custom pages, complete with fake ratings, reviews, and download counts. The page then coaxes the user into installing the app from outside the official store and approving its permissions. The app stages its permission requests one screen at a time. A harmless-looking web page sits in the background while pop-up cards request permissions framed as routine: turn off battery limits, set the app as the default text-message handler, and switch on notifications. It also asks to turn on Android's Accessibility service, which malware abuses to read the screen and control the phone. With those permissions, RedWing has broad control of the phone. Its capabilities include: Fake login screens, called overlays, that appear over real banking and cryptocurrency apps to steal passwords. Reading incoming texts for one-time passcodes, and using Accessibility to lift codes, card numbers, and PINs off the screen as they appear. Silently switching the victim's incoming calls over to the attacker, using a hidden carrier code (*21*) to turn on call forwarding, which knocks out phone-based verification and bank fraud-check calls. Live screen streaming and a keylogger, so operators can watch and control the phone in real time. Switching on the camera and microphone, reading files, stealing contacts and call logs, and tracking location. Pooling infected phones to flood a target website with traffic, a denial-of-service attack. Buyers choose their own targets, and the malware splits its targeting into two. The apps it watches through Accessibility are baked into each copy, which points to a fresh app being built to order once a buyer picks targets. The overlay targets, by contrast, can be changed later from the control panel without pushing out a new app. Zimperium counted 82 targeted institutions across several sectors, with a strong focus on Russian financial firms, though that list can shift at any time. The evidence points to the Russian market: one sample used a fake page for Russia's RuStore. Experts say the operation appears linked to Russian threat actors but stops short of confirming it. RedWing fits a wider move in Android crime toward on-device fraud, where attackers operate inside the victim's own banking session instead of stealing a password to use elsewhere. Researchers flagged a near-identical Russian-market rental kit, Fantasy Hub, last year. The same techniques turn up in Albiriox, aimed at more than 400 finance apps, and Klopatra, which used hidden remote control and fake overlays to drain accounts while victims slept. RedWing needs no Android exploit. It works only when a user installs the app from outside an official store and approves the prompts, so the first line of defense is what happens at install time. For individuals: Install apps only from official stores, and treat any "update" that arrives by link or text message as suspect. Do not turn on "install from unknown sources," and do not grant Accessibility, default text-message handler, or battery-exemption access to an app with no clear reason to need it. Watch for an app that hides its icon after it installs, a common trick for staying out of sight. On managed devices, the same choices can be enforced centrally: block sideloading, and flag apps that request Accessibility or the default-SMS role. Researchers have also published indicators of compromise for teams that want to hunt for it. Because the kit can be reskinned and its overlay targets swapped from a panel, the same code can keep resurfacing under new names, so app names are a poor way to track it. The behavior is the signal, not the name.
thehackernews.comJul 7, 2026extracted
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one umbrella. The ransomware component has been internally named CrownX. "The attack began with a spoofed legal document email directing recipients to a password protected archive on Proton Drive," Blackpoint Cyber researchers Nevan Beal and Sam Decker said. "Malicious content was embedded inside an ISO image rather than attached directly, reducing the likelihood of detection at the email layer." Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that culminates in the deployment of Avalon. Specifically, the shortcut runs a command to launch an MSBuild project located in the ISO image. The MSBuild project, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon. The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. "These capabilities give the framework a multitude of ways to reduce telemetry, bypass user mode monitoring, and adjust its execution depending on the defensive controls present on the host," the researchers said. The complete set of features built into Avalon is as follows - Harvest credentials, cookies, history, and bookmarks from Chromium-based browsers and Mozilla Firefox. Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic Wallet, Ledger Live, and Bitcoin Core, along with Discord, Slack, Teams, OpenVPN, WireGuard, and Windows Credential Manager. Collect details about SSH known hosts, saved RDP connections, Wi-Fi profiles, and Group Policy Preferences cpassword artifacts. Exfiltrate data to a remote server ("helloxcherry[.]com") and poll the server for receiving tasking commands. Perform reconnaissance and prioritize systems that can expand the scope of the compromise. Encrypt files associated with business operations, software development, engineering, data storage, and virtual infrastructure using Windows Cryptography API and deliver a ransom note containing payment instructions and deadline timers that show how much time is left before the ransom amount is increased. Inhibit system recovery by terminating the Volume Shadow Copy Service and deleting shadow copies. Remove traces of artifacts using an anti-forensic cleanup subsystem to complicate incident response efforts. Directly interact with disk structures likely in an effort to damage partition information, boot records, or other critical areas of the drive, effectively rendering the system unusable. "CrownX represented the final extortion stage, but the damage extended well beyond the encryption itself," the company said. "By the time the ransom note appeared, the broader framework had already collected credentials, established C2 communications, prepared multiple paths for lateral movement, and weakened local recovery options." Another important detail is that Avalon shows signs of artificial intelligence (AI)-assisted development, one that has assembled multiple components with scant regard for sophisticated tradecraft or operational security, something that requires significant expertise to build. The findings are yet another sign of how AI can lower the barrier to entry, making malware development more accessible with little time and effort, and even allowing actors with little technical expertise and resources to come up with tools that may require extensive development effort. In other words, the presence of a certain capability is no longer a reliable indicator of a threat actor's sophistication or operational maturity. "The kill chain illustrates how a familiar business lure can progress into a reusable, multi-capability framework designed to harvest credentials, retrieve subsequent payloads entirely in memory, and stage multiple follow-on actions from a single compromised endpoint," Blackpoint Cyber said. LLM Behind an Agentic Ransomware Attack The disclosure comes as Sysdig detailed what it said was the first publicly documented agentic ransomware infection driven by a large language model from start to finish, while retrying and tweaking its actions in real-time to complete tasks. The agentic threat actor (ATA) behind the operation has been codenamed JADEPUFFER. The operator "gained initial access to an internet-facing Langflow instance through CVE-2025-3248 and ran an adaptive and fully automated campaign, ultimately pivoting to the intended target and running a destructive database-extortion playbook against the victim's production database server," Sysdig's Michael Clark said. "The skill floor for running ransomware has dropped to whatever it costs to run an agent, and if that agent is running on stolen credentials through LLMjacking, the cost to an attacker is close to zero." AI Malware That Uses LLM in a Codeless Attack The findings also follow the discovery of an AI malware that brings together a Telegram bot with a public LLM API to devise a codeless attack. Once launched, the implant transmits basic details about the compromised system to the attacker's Telegram bot and enters into a command-and-control (C2) loop that polls the bot API every 5 seconds for new messages. The results of the command execution are exfiltrated back using the same channel. The speciality of this malware is that each operator message is forwarded to a public LLM API endpoint ("api.groq[.]com/openai/v1/chat/completions"), which then translates the natural language instructions provided by the attacker into its equivalent shell command. The artifact was uploaded to the VirusTotal platform on March 11, 2026, and has zero detections across all engines to date. "This work introduces an LLM translation layer that replaces shell syntax with plain text. The attacker types plaintext instructions in Telegram," Palo Alto Networks Unit 42 said. "The LLM translates the instructions into shell commands. And the victim executes the shell commands. No command-line knowledge is required."
thehackernews.comJul 3, 2026extracted
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point their way. Palo Alto Networks' Unit 42 calls the trick phantom squatting, and its new research shows it is already happening in the wild. The reason it matters is trust. Developers and AI assistants increasingly treat the links a model hands back as real. When a model invents a domain that does not exist yet, whoever registers it first inherits all of that misplaced trust, with no phishing email and no malicious ad required. To measure the problem, Unit 42 asked two AI models 685,339 questions about 913 well-known brands across technology, finance, healthcare, government, gambling, and other sectors. The models produced 2.1 million links. Threat intelligence already flagged 13,229 of them as outright malicious, meaning the AI was handing out known-bad addresses. Roughly 250,000 of the invented domains had no owner yet, each a ready target for whoever registers it first. How phantom squatting works The attack works because a brand-new domain has no reputation. Blocklists, threat feeds, and reputation scores all need a site to misbehave for a while before they flag it. A freshly registered phantom domain has no such record, so those filters have nothing to flag. By the time they catch up, the victim has already been sent to the site by a tool they trust. Two details make it worse. The fake domains were not sitting in the training data: both models shipped before the real malicious sites existed, so the addresses come from the models' own language patterns, not memory. And those patterns are consistent. Different models often invent the same fake domain for the same question, which makes an attacker's next target easy to guess. Turning up a model's "creativity" setting only produced more invented domains. As Unit 42's researchers put it, the vector "exploits a structural property of LLM architectures that remains inherently unpatchable." Two observed cases Two cases show the full loop. On March 8, 2026, Unit 42's system predicted that AI models would invent a domain resembling a national postal service's online marketplace. Both models generated it at every temperature setting, a strong sign that they treated the fake site as fact. Twenty-three days later, on March 31, an attacker registered that exact domain and stood up a phishing kit named Montana Empire. The kit copied the real storefront in real time. It stole card numbers, bank-transfer details, and national ID data. A Telegram bot lets the operator approve victims' one-time passcodes by hand. The giveaway: leftover project files and session logs showed the criminal had built the kit with an AI coding assistant. Attacker and defender reached the same fake domain the same way, by asking an AI. In the second case, Unit 42 flagged a hallucinated postal-service domain a full 51 days before an attacker registered it. The attacker then wrapped it in a pixel-perfect brand clone, added a fake 4.8-star rating and a claim of over two million users, and used it to push a malicious Android app. Other detected domains impersonated a major UAE bank that an attacker had already been abusing for nearly a year, a European bank, and sports-betting sites aimed at users in Bangladesh. An old trick with a new target Phantom squatting is the domain version of slopsquatting, where attackers register the fake software package names that AI coding tools invent. That is not a hypothetical. A large USENIX study found code-generating models routinely suggest package names that do not exist, and the PhantomRaven campaign turned exactly that behavior into malware hidden in 126 npm packages with more than 86,000 installs. It points to a larger shift: model output is becoming input. Developers, agents, and security teams act on AI-generated links and names before anyone verifies them, and AI keeps shrinking the time defenders have to react. It also lands in a world where brand-impersonation phishing is now a paid service, with kits like Lucid and Lighthouse standing up 17,500 fake domains against 316 brands in 74 countries. What to do Because models hallucinate consistently, security teams can map which fake domains a model is likely to produce and watch for anyone registering them, often with weeks of warning. For everyone else, the practical steps are simple: Do not trust a link just because an AI gave it. Confirm the domain is the real, official one before you type a password or paste it into code. Keep AI agents from automatically opening or downloading from model-generated links without a check. An agent has no instinct to hesitate the way a person might. Treat anything a model writes as an unverified draft, not an authority. That window is open, and it rewards whoever moves first. The real question, as Unit 42 frames it, is simply whether defenders or attackers reach these domains sooner.
thehackernews.comJul 1, 2026extracted
Malicious PyPI packages give hackers control of Telegram bot servers
A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. At least eight packages have been published on the Python Package Index (PyPI) with a hidden backdoor that is activated by helper modules when importing Pyrogram or when the bot starts. Although the Pyrogram project is no longer maintained, it remains popular, with nearly 350,000 monthly downloads on PyPI (last updated in April 2023) and more than 1,400 forks on GitHub (last updated in December 2024). Pyrogram is described as "elegant, modern and asynchronous Telegram MTProto API framework in Python for users and bots." In simpler terms, it allows developers to create automated bots or usersbots. According to researchers at application security company Checkmarx, who dubbed the campaign 'Operation Navy Ghost', the threat actor published on PyPI between November 2025 and June 2026 the following malicious Pyrogram forks: VLifeGram (nine versions counting 4,150 downloads) VLife-Gram (five versions with 1,030 downloads) pyrogram-navy (six versions with 2,530 downloads) pyrogram-styled (more than 16 versions with 15,370 versions) pyrogram-zeeb (one version counting 432 downloads) kelragram (three versions downloaded 1,041 times) sepgram (one version downloaded 264 times) pyrogram-kelra (one version with 672 downloads) All the packages are forks of the legitimate Pyrogram project as they include the original source code. However, the threat actor also added a backdoor called secret.py, hidden in the helpers module. The malicious file registers hidden Telegram command handlers when an infected bot launches, which enables the execution of attacker-supplied Python code or shell commands. “When the attacker sends /asu print(os.environ) to the victim’s bot, this function compiles and executes that Python code on the victim’s machine — with full access to the live Telegram client, session, chats, contacts, and environment variables,” Checkmarx explains. “When the attacker sends /asi cat /etc/passwd, this runs /bin/bash -c “cat /etc/passwd” on the victim’s server and returns the output,” the researchers say. “This is repeatable with any shell command and runs under the infected application’s authority, meaning the malware can access and exfiltrate whatever the infected application could legitimately access.” The command output is then returned via Telegram messages, and if it exceeds 4096 bytes, it is sent as a document attachment to the attackers. The backdoor contains a hardcoded ‘OWNERS’ list with Telegram IDs that give the threat actors exclusive control. This list also helps deactivate the backdoor when it launches on the attacker’s system. The malware specifically targets Telegram bot accounts and is designed to operate silently, suppressing errors and disabling logging. Checkmarx researchers noticed that the backdoor activates only on Telegram bot accounts, which typically run in production environments, a deliberate function indicating that the attacker seeks "access to databases, credentials, cloud APIs, and sensitive infrastructure." Once the bot is active, the threat actor can read any file on the server, dump secrets, access the victim’s Telegram chats, download the database, and install a persistent backdoor. Despite the packages being published from different PyPI accounts, Checkmarx attributes the campaign to a single threat actor. The conclusion is based on the shared OWNERS list across the various packages, the identical backdoor code, the command names, and the overlapping infrastructure. Developers who might have installed the listed packages should remove them immediately, rotate all credentials on the affected server, and revoke their Telegram bot tokens. Checkmarx has published indicators of compromise for the malicious Telegram IDs along with the attacker's profile URLs. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 30, 2026extracted
Hackers Leverage Blockchain to Hit Japan's Hotels Through Booking.com Phishing
Cyber threat actors are targeting employees of Booking.com partner accommodations in Japan, using phishing emails that impersonate guest complaints and review requests to trick hotel staff into executing malicious files. The malware delivered through this campaign, TONResolver, is hosted on a smart contract and leverages blockchain technology – specifically, The Open Network (TON) blockchain platform. It functions as an initial access and command-execution foothold, with follow-on activity indicating potential credential theft and further compromise. Phishing Emails to Booking.com Partners The campaign was detected by TrendAI Research, Trend Micro’s research unit, in late May 2026. Suspicious emails had been sent to Japanese partner companies of Booking.com, with the subject line “Important: Guest Stay Review Request” in Japanese. These emails are aimed to engage the target to converse with the attacker. Follow-up emails sent by the threat actor contained a hyperlink that both led to a suspicious website and downloaded a ZIP file. Within the ZIP file lied a shortcut link file (LNK) disguised as a photo file that led to the installation of TrojanSpy.JS.TONRESOLVER.A – a malware implant functioning as a remote access trojan (RAT), that TrendAI researchers also refer to simply as TONResolver – via a PowerShell script. Other malicious emails were sent with different subject lines, some in English, to other Booking.com accommodation partners in Japan and in other countries, such as Austria, Australia, France, Germany, Indonesia, Italy, the Netherlands, Russia, South Korea, Turkey, the UK and the US. However, Japanese hospitality organizations were by far the main targets, said a TrendAI report published on June 29. These emails have been sent using the notification functionality of a scheduling tool service, meaning they bypassed traditional email security controls based on domain authentication technologies such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting, and Conformance (DMARC). Malware Infrastructure on TON Blockchain Unlike conventional phishing campaigns, the malware implant delivered through this campaign, TONResolver, abuses the TON blockchain platform as a dead drop resolver. This technique allows attackers to update their command-and-control (C2) server destination without hardcoding it into the malware, making detection and takedown significantly more difficult. TON was initially developed by Telegram under the name Telegram Open Network, but is currently developed and operated primarily by the TON Foundation. To further evade detection, the attacker packaged the malware as a Node.js application and applied virtual machine-based obfuscation, a method that wraps the code inside a protected execution environment, preventing security researchers from easily inspecting its logic through static analysis alone. This combination of techniques makes reverse engineering the malware a significant challenge. While executing the LNK file and running TONResolver via Node.js does not immediately result in file or credential theft, the malware establishes a persistent "keepalive" connection with the attacker's server. This backdoor capability allows the attacker to execute additional commands and deploy further payloads at will, suggesting that victims are selectively targeted for follow-up attacks based on their endpoint details and IP address information. “In alignment with the campaign's progression, new domain registrations and C2 server switching were also carried out, indicating that the attackers are constantly monitoring attack trends and success rates,” said the TrendAI researchers. TrendAI’s Recommended Mitigation Measures Based on their findings, TrendAI researchers recommended the following measures to mitigate this type of threat: Restrict access to blockchain platforms: Deploy a proxy gateway on internet-facing endpoints and enforce connection filtering to block access to blockchain platforms such as the TON network Monitor and restrict Node.js execution: mplement application control policies to monitor and restrict suspicious use of Node.js, particularly any instances where it creates autorun entries or executes from unexpected locations Block unauthorized PowerShell network communications: Using endpoint firewall capabilities, restrict outbound communications initiated by PowerShell to external IP addresses Filter PowerShell-based web requests: Configure web gateway or internet access policies to block outbound HTTP requests containing PowerShell-based User-Agent strings
infosecurity-magazine.comJun 30, 2026extracted
Social engineering: how scammers manipulate their victims | Kaspersky official blog
Unfortunately, it’s not just the gullible who fall for scams and phishing attacks anymore — literally anyone can become a victim today. Cybercriminals spend years honing their tactics to guarantee results, relying on sophisticated psychological manipulation that’s often hard to spot. In the cybersecurity world, these type of mind games even have their own name: social engineering. In this article, we break down the psychological tricks scammers use to deceive their targets, the red flags you need to watch out for, and exactly what to do if you realize you’re being played. The emotions scammers weaponize Social engineering works precisely because it triggers our deepest emotions. When a victim is anxious, terrified, or caught up in the heat of the moment, they tend to make split-second decisions without thinking about the consequences. And that’s exactly what hackers are banking on. That’s why, in such tense moment when you’re talking or texting with someone and they’re making demands, you need to pause for a second and ask yourself: “What exactly am I feeling right now? What was I feeling just a moment ago? Is this person trying to exploit my emotional state?” Most of the time, scammers try to prey on these emotions: Fear and anxiety Excitement Shame and guilt Surprise and shock First, verify who you’re actually dealing with Before you even start looking for red flags, you need to check one basic thing: who are you actually talking to? If you’re chatting with, say, someone who claims to be a “bank representative”, your best bet is to look up the bank’s official phone number and email address online. Call them back or write to an address you know is 100% legitimate — it’s always better to be safe than sorry. You should be especially on guard if someone reaches out to you on a messaging app or social media. As a rule, major companies simply don’t operate that way. Dead giveaways you’re dealing with a scammer They’re putting you on an emotional rollercoaster Say you get an email from the “support team” of a streaming service you use. The message claims someone just tried to sign in to your account from another country — cue immediate panic. But then, they instantly soothe you: “Don’t worry, we blocked the suspicious sign-in attempt just in time. Your account is secure.” The scammers don’t stop there, though. The very next paragraph plunges you right back into panic mode: “Unfortunately, during our security check, we discovered that your payment information may have been compromised.” Finally, they throw you a lifeline: “We are ready to help you fix this right now; just click this link to verify your identity.” By the end of it, you’ve been yanked back and forth the entire minute you spent reading this “urgent update”. The goal of this emotional rollercoaster is to knock you off balance so that you stop thinking critically and just start reacting. And the moment the scammer swoops in with a supposed solution to the problem, your judgment goes completely out the window. They know a little too much about you Scammers will often deliberately bombard you with your own personal information just to make it seem like they really know what they’re talking about and have legitimate access to your sensitive data. Just because the person on the other end happens to know details about your identity, finances, or contracts, doesn’t mean they aren’t a con artist. Thanks to endless data breaches, there’s a pretty massive digital dossier out there on almost all of us. It’s incredibly easy for a hacker to find out exactly how much you spent on grocery deliveries last year, who your cellphone carrier is, or what email address is associated with your bank account. They try to scare you — sometimes with threats and extortion Arguably, the easiest way to throw someone off balance is to strike fear into them or ramp up their anxiety. When offers that are too good to be true stop working, cybercriminals bust out the scare tactics: “Your account has been compromised”, “You will be charged with tax evasion unless you hand over your crypto wallet seed phrase”, “You will lose access to our services unless you call us right now”, or “You have been placed on a sex offender registry. Contact us to resolve this, or else we will press charges and leak your info to the media.” The list goes on. Sometimes, these messages can seem totally emotionless, and perfectly mimic a real email from support. But if the tone is overly dramatic and you feel like you’re being cornered, the odds that you’re dealing with a scammer are close to 99.9%. And if they’re demanding you take action — like wire money to a random account, or hand over sensitive data — under the threat of physical harm, public shaming, or criminal charges — you can round that up to 100%. To learn more about how extortionists operate, check out our post Email extortion: how scammers use blackmail. An “extremely important person” is messaging you To crank up the anxiety, scammers often sign their messages with the names of high-ranking officials. When this happens, take a breath and ask yourself: are you really sure the head of the IRS or the local police chief would personally call or text you? High-level officials and investigators usually have much bigger fish to fry. And if you’re being accused of some outrageous crime in a message signed by, say, the city’s chief prosecutor, that’s your cue to call their bluff. You’re getting a too-good-to-be-true offer Don’t fall for random acts of generosity or gifts that appear out of thin air. Here’s just a short list of what could happen to you: You get an unexpected package with a QR code printed on the box. They tell you to scan it — supposedly to find out who sent it, claim a free coupon from the seller, or confirm delivery so you don’t get stuck with a shipping fee. It’s not hard to guess that the QR code actually leads to a phishing site. From there, the scammers have a field day: they can trick you into handing over your card info, convince you to download an app that turns out to be malware, or get you to cough up a verification code for your banking app. “Hi! I’m calling from the delivery hub. You’ve got a package (or a bouquet of flowers) on the way. Could you please give me the verification code from the text message we just sent so you can claim your gift?” Look, everyone loves getting surprise gifts. But in the heat of the moment, it’s easy to let your guard down and accidentally hand the scammers a gift of your own — like the access code to your government services account. Talk about luck! All kinds of celebrities are announcing a free NFT giveaway that promises to make you a fortune. To claim your new crypto asset, you launch a mini-app, type in your details, and… boom, your Telegram account is gone. And looking back, those celebrity profiles pushing the giveaway did seem a little off… They’re rushing you and trying to cut you off from the outside world “Don’t hang up! This is your last chance to recover access to your account.” “If you do not reply to this email within eight hours, we will press criminal charges against you.” “You need to go to the bank immediately to save your remaining cash and deposit it into a secure account.” If similar phrases are used to spring you into immediate action, hit the brakes — the scammers are just trying to scare you and create a false sense of urgency. This is a textbook tactic. Imagine getting a call from a scammer posing as a bank representative or even an official from the Department of Commerce, claiming your bank accounts have been hacked. They then ask you to sign a non-disclosure agreement — supposedly to help recover your money — and threaten legal action if you tell a soul, even your closest family members. They’ll insist the matter is “serious”, requires immediate action, and that cooperating with government agencies “must remain strictly confidential”. Remember: legitimate company reps or government officials would never ask you to keep secrets unless you deal with classified government data or you’ve signed an actual corporate NDA. Scammers deliberately cut victims off from any support system, voice of reason, or outside opinion. And they don’t just isolate you from people; they cut you off from information entirely. They might intentionally keep you on the line or bombard you with emotionally charged texts, so you don’t even have a second to breathe, let alone look something up online. When you’re in a state of high anxiety, it’s incredibly easy to fall for these manipulations and make reckless choices — even when you think you’re just trying to fix the problem. Never be afraid to reach out for help; getting a second opinion on what’s going on is always a smart move. They try to shame you Imagine getting a notification that your account has been compromised, and it ends with a prompt to contact support. But as the “support rep” looks into the issue, they simultaneously try to guilt-trip you: “When was the last time you changed your password? A while ago? Didn’t you see our urgent warnings to update your credentials?” or “Look, the text message literally says right there: do not share this code with anyone! Why on earth did you give it out?” This is a deliberate tactic to hook you with a sense of guilt, making you feel like you’ve lost control and need the scammer’s expertise and help. Even if you actually did make a mistake, don’t beat yourself up. Falling for a scammer’s trap is much easier than you think — all it takes is one stressful day at work and a call coming in at the absolute worst moment. You suddenly get a warning that you’ve been… talking to scammers Scammers love using confusing, multi-stage schemes. For example, they might first try to trick you into giving up your banking app access code under the guise of updating your account information. But then, the call suddenly drops, or you get an immediate text warning you that you were just talking to a scammer, your account has been breached, and you need to contact support immediately for your own safety. Sometimes, self-proclaimed “federal agents” or “law enforcement officers” will even barge into the conversation. The catch is that this “security team” is part of the same group of scammers keeping the con alive. They’ll start insisting that all your money is about to fall into criminal hands unless you move it to a “secure account”, or claim that someone has already taken out payday loans in your name. Do not contact unfamiliar numbers or email addresses sent to you in messages — even if they promise to help. Find the company or agency’s legitimate website, look up their official contact channels, and use only those. Remember: no government agency — and certainly no private company — is wiretapping your phone to check if you’re talking to fraudsters. What to do if you’ve fallen for a scam First and foremost — don’t blame yourself. Anyone can be caught off guard and end up being tricked when they’re feeling vulnerable. Try not to panic, and think back to exactly what kind of information you handed over. Your next steps depend entirely on that: You gave out a text verification code or an account password → Immediately change your password for that service, as well as for any other accounts where you reused it. Turn on two-factor authentication if you haven’t already. You handed over your card details → Call your bank immediately and ask them to freeze your card. If money has already been withdrawn or wired from your account, ask how you can dispute the transaction. You clicked a suspicious link or downloaded a file from an unknown sender → Scan your device with a reliable antivirus. Trying to figure out on your own whether you’ve picked up malware is practically impossible, as it often hides on your device without showing any obvious signs. Don’t listen to the scammers Here’s how you can protect your accounts, data, and money: Take your time. If someone is rushing you to act immediately — enter your details, give up a code, or send money — you’re most likely talking to a cybercriminal. Hit pause, call the company back at the official number on their website, and check if they actually need anything from you. Outsource your fears to Kaspersky Premium. Unlike a human, our AI- and ML-powered anti-scam security suite is completely unbiased and spots phishing emails and malicious files right where a person might get flustered. It’ll block you from opening suspicious websites, stop attempts to infect your device, neutralize any discovered malware, and keep your data and money safe. Turn on two-factor authentication for your important accounts. With Kaspersky Password Manager, you can generate one-time login codes that change every 30 seconds — making them much harder for scammers to intercept than codes sent via email or text. Stick to the golden rule: never reuse a password. If you use the same password across different services, a hacker only needs to crack one account to automatically gain access to all the others. Variations like “Password123” and “Password1234!” won’t cut it either — minor tweaks like that are incredibly easy to guess. Of course, memorizing dozens or even hundreds of different passwords manually is a superhuman feat. That’s where a password manager comes in handy, safely storing your data in an encrypted vault and generating truly complex, unique passwords for you. Check out our other posts for even more security tips:
kaspersky.comJun 30, 2026extracted
Russia used social engineering to breach prominent messaging accounts, Ukraine says
Russia used social engineering to breach prominent messaging accounts, Ukraine says Ukraine's security agency said it had uncovered, together with the FBI, a long-running Russian campaign to compromise the messaging accounts of government officials, military personnel, politicians and activists in Ukraine, Europe and the United States. The campaign was aimed at gaining access to sensitive military, political and economic information exchanged through messaging applications, while also stealing victims' personal data, the Security Service of Ukraine (SBU) said in a statement on Thursday. The attackers used a range of social engineering techniques rather than exploiting vulnerabilities in the messaging apps themselves, the SBU said. One of the most common methods involved sending text messages impersonating official messaging platform support services and urging users to disclose their account credentials. "The messages are sent in the morning hours, when users are particularly vulnerable due to their physical and emotional state," the SBU said. According to the agency, Russian intelligence services and affiliated hackers targeted government institutions, public officials, activists and ordinary Ukrainian citizens. The SBU did not identify the Russian intelligence service responsible, specify which messaging platforms were primarily targeted or say how many victims had been affected. The FBI did not immediately respond to a request for comment. The warning follows a series of disclosures by Ukraine and Western intelligence agencies about Russian efforts to compromise secure messaging platforms used by government and military personnel. Earlier this year, Dutch intelligence agencies warned that Russian state-backed hackers were conducting a global campaign to hijack Signal and WhatsApp accounts belonging to government officials, diplomats and military personnel. The attackers typically posed as customer support workers to trick victims into sharing one-time verification codes or PINs. Ukraine has previously reported Russian espionage operations targeting messaging applications used by its military, including campaigns involving data-stealing malware and attempts to extract encrypted Telegram and Signal communications from mobile phones captured on the battlefield. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaJun 26, 2026extracted
New macOS ClickFix attack silently mounts DMGs to push infostealer
A new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files. The campaign is infecting Mac devices with the Atomic macOS Stealer (AMOS) infostealer, which steals browser credentials, cryptocurrency wallet data, Keychain data, messaging app information, and user documents. Researchers at Palo Alto Networks Unit 42 first discovered the campaign and say it begins with a fake CAPTCHA page that tells users to open Terminal and paste a malicious command to verify themselves. Once executed, the command downloads a DMG file from an attacker-controlled server, silently mounts it with macOS's native hdiutil utility, locates the application bundle it contains, and launches it automatically. ClickFix is a social engineering technique that displays fake CAPTCHAs, browser errors, or system alerts to trick visitors into copying and executing attacker-supplied "fix instructions." The technique has grown in popularity among threat actors in the past year and has been used by both cybercriminals and state-sponsored hacking groups to distribute malware. While ClickFix attacks involving DMGs are not new, previous campaigns typically relied on users manually opening downloaded DMG files to launch malicious applications or execute scripts from attacker-controlled servers. The campaign spotted by Palo Alto combines both approaches by using a Terminal command to quietly download a DMG file and launch the malware it contains. After running the Terminal command, the attack downloads a malicious DMG from svs-verificationdate[.]beer using curl with the quiet "-fsSL" flags and saves it to the /tmp folder under a random filename. The command then executes 'hdiutil attach -nobrowse' to mount the downloaded disk image without displaying it in Finder or on the desktop. The script then searches up to three directory levels deep for the first available .app or .pkg installer, and if one is found, launches it using the macOS open command. Researchers observed the malware being delivered as a disk image named "s.01M0td.dmg," which mounted a volume containing a self-signed application bundle named "NNApp.app." This payload is part of the Atomic macOS Stealer family, which is used to steal credentials, browser history, authentication tokens, and cryptocurrency wallets from infected devices. The stealer will display a fake System Preferences authentication prompt that asks the user to enter their password, allowing the malware to steal it. According to the researchers, the malware targets eight Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, Opera, Arc, Vivaldi, CocCoc, and Yandex. It steals cookies, login databases, autofill information, stored payment cards, and browser profile data. The stealer also targets Firefox-derived browsers, including LibreWolf, SeaMonkey, Tor Browser, Waterfox, and Zen Browser, stealing the same information. Palo Alto says the malware searches for and steals cryptocurrency wallet data, including Exodus, Electrum, Atomic Wallet, Wasabi Wallet, Bitcoin Core, Litecoin Core, DashCore, Guarda, Binance Wallet, Dogecoin Wallet, and TonKeeper. The malware also steals Telegram Desktop and Discord data, Apple Notes databases, Safari cookies, Apple Keychain database files, and user documents with the PDF, TXT, or RTF extensions. All harvested data is then stored in a ZIP archive and uploaded to the attacker's server, where the attacker can retrieve it. Of particular interest, the researchers found that the malware will replace legitimate installations of Ledger Live and Trezor Suite with malicious versions, likely to perform crypto theft. The campaign was observed using command-and-control servers at svs-verificationdate[.]beer and 196.251.107[.]171. As a general rule, users should always be cautious when websites instruct them to open Terminal and execute commands. This is especially true when they claim to be part of CAPTCHA verifications, browser fixes, or other troubleshooting steps. If you do not 100% understand what a command does, do not run it. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 23, 2026extracted
How hackers use PowerShell scripts to steal Telegram accounts | Kaspersky official blog
There are dozens of ways to break into someone’s Telegram account. We’ve frequently covered phishing in Telegram Mini Apps, scams with bots, gifts, and giveaways, and many other tactics. Today, we’re looking at yet another account hijacking method — one that relies on a PowerShell script. The script, deceptively named “Windows Telemetry Update”, actually serves as a tool for hijacking Telegram sessions. It harvests data from completely defenseless computers and forwards it to the attackers via a Telegram bot. An evil script with a stealer inside Cybercriminals frequently rely on PowerShell scripts to covertly download malware or harvest data. This time, researchers uncovered a script on Pastebin masquerading as a routine Windows update. In reality, it was an infostealer designed to hijack Telegram for Windows session data, and allow hackers to take over accounts with neither a password nor verification code. What’s a PowerShell script anyway? Think of it as a text file packed with commands for a Windows computer. Instead of a human spending time clicking through tasks manually, the computer follows these quick instructions to get everything done automatically in a matter of seconds. Right at the top of the script, researchers immediately spotted a Telegram bot token and a chat ID, alongside multiple references to the tdata folder. This specific folder is where Telegram for Windows keeps the authorization keys used to log users in to its servers. If attackers grab this data, they can access the victim’s Telegram account without a password or verification code. Once inside, they maintain access until the victim checks their active sessions in the app and manually terminates the suspicious ones. How the stealer works The malware lands on the victim’s computer disguised as a PowerShell script for a Windows telemetry update. As soon as it runs, it gathers basic system information: username, hostname, and public IP address. It then checks if Telegram Desktop is installed. If it is, the script forces the app to close so it can unlock Telegram files for editing. From there, the rest is simple: the script zips up the entire contents of the tdata folder into a temporary directory, forwards the archive straight to the attackers, and wipes the file from the computer to hide its tracks. The good news is that the stealer likely hasn’t compromised any accounts yet, as experts found no evidence of actual data transfers. It appears researchers caught this malicious PowerShell script while it was still in the prototype testing phase. Another giveaway is its surprisingly suspicious name. Cybercriminals typically use neutral names to hide their bots and apps. In this case, when researchers found it, the bot was running under the burner handle afhbhfsdvfh_bot with a dead-honest description: Telegram attacker. Researchers noted that while the bot had likely undergone functional testing, it hadn’t yet been deployed at scale, which explains the placeholder name. How to defend against PowerShell scripts Defending against this nameless stealer requires a layered approach to security. First, it helps to understand how a PowerShell script ends up on your PC in the first place. Usually, they slip in unnoticed through malicious email attachments, software vulnerabilities, infected apps, or social engineering tricks. That’s why we recommend installing a robust security suite on your device and staying highly cautious about the links you click and the files you download. Be careful what you download. Always double-check the websites you use to download files. Stick to trusted, official sources — and remember that Telegram and Discord channels, and sketchy, fly-by-night websites definitely don’t fit that description. Watch out for email links and attachments. Keep in mind that email remains a favorite delivery method for cybercriminals. They might drop a PowerShell script directly into your inbox as an attachment or bait you into clicking a link that triggers an automatic download. Keep your apps and OS updated. Software vulnerabilities pop up unexpectedly, but patches are usually released very quickly. We recommend installing updates as soon as they become available. To make life easier, just turn on automatic updates wherever possible. Be sure to install Kaspersky Premium on every device where you run Telegram. Our security solution will block malware, malicious attachments, spam, phishing attempts, and sketchy websites. Kaspersky Premium subscription additionally includes a password manager. It generates and securely stores strong and unique passwords, stops you from entering your credentials on fake sites, and comes in handy for tightening your Telegram security, which we’ll cover next. How to secure your Telegram account To protect your Telegram account from these types of hijacking schemes, we recommend the following: Regularly monitor your Telegram activity. Ultimately, hackers steal accounts to blast out spam and run scams. It’s a good idea to occasionally check your chat history to ensure no new conversations or messages have appeared that you didn’t send yourself. Immediately terminate unrecognized sessions. If you suspect you’ve fallen victim to this infostealer or any other cyberattack, terminate all other Telegram sessions as soon as possible by going to Settings → Devices → Terminate all other sessions. If your Telegram account has already been hijacked, you have a 24-hour window to kick the attackers out by terminating their sessions. We broke down exactly why this rule exists — and mapped out every possible way to reclaim your account — in our detailed guide: What to do if your Telegram account is hacked. In the meantime, beefing up your account security is a must. First, set up a cloud password by heading to Settings → Privacy and Security → Two-Step Verification. Just any password won’t cut it — you need something unique and unhackable. We recommend reading our post on the subject: Creating an unforgettable password. Better yet, make the switch to passkeys — a passwordless technology that offers top-tier protection against leaks and phishing. To set up that login method, go to Settings → Privacy and Security → Passkeys. The easiest way to manage your passkeys is with Kaspersky Password Manager. Our cross-platform app ensures you can seamlessly log in to Telegram using your saved passkeys whether you’re on Windows, Android, iOS, or macOS. To learn more about how cybercriminals can breach your Telegram account and how to lock it down, check out our other posts:
kaspersky.comJun 23, 2026extracted
Scattered Spider members plead guilty to hacking Transport for London
Two members of the 'Scattered Spider' cybercrime group pleaded guilty to hacking the Transport for London (TfL) systems in 2024. The two individuals, Thalha Jubair (20) and Owen Flowers (18), breached the systems of London's transportation service between August 31 and September 3, 2024, causing millions of pounds in losses. Jubair and Flowers previously declined involvement in the incident but have changed their pleas to guilty on the first day of the proceedings at Woolwich Crown Court. TfL is a public body responsible for managing the majority of London’s transportation networks, serving a metropolitan area of millions, and handling thousands of journeys daily. On September 2, 2024, TfL's infrastructure suffered a cybersecurity incident, causing operational disruptions that continued for days. The attackers accessed data from TfL's Oyster refunds system and disrupted customer refund services, delaying refunds for some users. On September 12, TfL admitted that customer data had been stolen in the attack, while the U.K.’s National Crime Agency (NCA) announced on the same day the arrest of Flowers, a suspect at the time. Jubair and Flowers were arrested on September 18, 2025, after the investigators retrieved incriminating evidence for both, extending even beyond the TfL cyberattack. Flowers breached his bail conditions twice, in March and in May 2025. According to the NCA, the cyberattack at TfL forced all 28,000 employees to visit their local offices to reset their passwords and caused £29 million ($38.3M) in financial damage to the public transportation organization. “The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers,” stated NCA’s Deputy Director Paul Foster. “Today’s result would not have been possible if TfL had not engaged with law enforcement early, so I would urge any other organization to please do the same in such circumstances.” The investigators seized multiple devices from Flower’s home, including a laptop containing a screenshot showing connectivity to TfL infrastructure, evidence of access to a marketplace selling stolen credentials, and videos showing Jubair breaching TfL systems. The hackers communicated via Telegram and a shared online collaboration platform during the intrusion, the NCA stated. In addition to TfL, authorities have also linked Flowers to intrusions at SSM Health Care Corporation and Sutter Health, both American healthcare organizations. The two Scattered Spider members were scheduled to stand trial on June 22, but the sentencing was rescheduled for July 16 because of changing their plea to guilty. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 23, 2026extracted
Two Scattered Spider hackers plead guilty over Transport for London cyberattack
Two Scattered Spider hackers plead guilty over Transport for London cyberattack Two members of the notorious hacker group Scattered Spider have pleaded guilty to charges related to a 2024 cyberattack on Transport for London (TfL) that resulted in £29 million in loss and recovery costs. Thalha Jubair, 20, from London, and Owen Flowers, 18, from Walsall, pleaded guilty at a court hearing in London to offences under the UK’s Computer Misuse Act and will be sentenced on July 16. TfL, the public body responsible for much of the capital’s transport network, handles up to 5 million passenger journeys a day on the London Underground alone. The attack targeted TfL’s computer network between 31 August and 3 September 2024. “Data from TfL’s Oyster refunds system was accessed and the incident also affected TfL’s customer refund system, leaving some out of pocket for much longer than usual. It also closed down the application system for Oyster photocards for children and young people,” the National Crime Agency (NCA) said. Following the compromise of its network, TfL required all 28,000 employees to attend an office in person to reset their passwords. Jubair and Flowers were arrested at their home addresses on 16 September 2025 by officers from the NCA and the City of London Police. Flowers was first arrested on September 6, 2024, as part of the TfL investigation. Investigators uncovered evidence linking Flowers to intrusions targeting U.S. healthcare providers SSM Health and Sutter Health. Officers seized several devices from his home, including laptops, desktop computers, hard drives and USB storage devices. One laptop contained a screenshot showing connectivity to TfL infrastructure, while another contained videos recorded by Flowers that showed Jubair accessing TfL systems during the attack. The evidence showed the pair communicating via Telegram and an online collaboration platform used to share access and information. Flowers later breached his bail conditions on two occasions in 2025. “This has been a lengthy, highly complex and painstaking investigation,” said Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit. “Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences and impacts hugely on the public. “The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers,” Foster added. “Those who target critical organisations, cause substantial financial harm, and disrupt the daily lives of the public will not do so without consequence,” noted Deputy Commissioner Nik Adams of the City of London Police.
helpnetsecurity.comJun 23, 2026extracted
FFmpeg fixes PixelSmash flaw in widely used video decoder
A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. The vulnerability is tracked as CVE-2026-8461 and is a heap out-of-bounds write in the MagicYUV decoder. It received a high-severity score of 8.8 and can be leveraged via a malicious video file in AVI, MKV, or MOV format. Any application that uses libavcodec, FFmpeg’s core library for video decoding and encoding, is considered vulnerable. However, exploitation for remote code execution (RCE) is possible if the Address Space Layout Randomization (ASLR) defense is disabled or by chaining another vulnerability to defeat the protection. Root cause and impact Researchers at software supply-chain security company JFrog say that PixelSmash stems from the way MagicYUV processes slices, independent regions of a video frame that can be decoded separately from the rest of the image. "The vulnerability is a one-row heap buffer overflow in the MagicYUV decoder’s slice handling, caused by an inconsistency between how the frame allocator and the decoder compute chroma plane heights," JFrog explains. PixelSmash can be triggered when the user opens AVI, MKV, or MOV video files, browses a directory containing the file (via thumbnail generation), or runs any automated media ingestion workflow. JFrog found that multiple popular media applications, such as Kodi, OBS Studio, PhotoPrism, and GNOME/KDE/XFCE’s thumbnail generators, use FFmpeg with the MagicYUV decoder enabled, making them vulnerable to PixelSmash attacks. Slack, Discord, Telegram, and WhatsApp may also be susceptible to PixelSmash attacks, as they use FFmpeg to generate server-side video previews, but they were not tested. JFrog lead researcher Yuval Moravchick demonstrated that PixelSmash can be used for remote code execution on Jellyfin and Nextcloud (with Movie preview enabled) instances. “To demonstrate the real-world impact, we achieved full remote code execution against a Jellyfin 10.11.9 media server - the second-most popular self-hosted media server (after Plex) - through its normal media library scan pipeline,” JFrog says. “Attack path: a download of a crafted MagicYUV AVI into the media library -> Jellyfin automatically triggers ffprobe for metadata extraction -> the OOB write fires -> AVBuffer.free is hijacked to system() -> arbitrary command executes as the jellyfin service user.” However, Moravchick noted that the RCE exploit requires ASLR (Address Space Layout Randomization) to be disabled, and that CVE-2026-8461 alone does not bypass this memory protection. In theory, a separate information-disclosure bug in FFmpeg's FlashSV decoder could be chained with PixelSmash to bypass ASLR. Another attack scenario is via torrent downloads and requires no user interaction. The researchers say that an attacker could seed a malicious video that targets Jellyfin users who point the download to the application's media library folder. "Jellyfin’s real-time file system monitor detects the new file and automatically triggers an ffprobe metadata scan. The exploit fires during the scan - AVBuffer.free is hijacked to system(), and the attacker’s reverse shell command executes as the jellyfin service user" Even when RCE is prevented or impossible, the CVE-2026-8461 vulnerability should be sufficient to reliably achieve a denial-of-service (DoS) condition on vulnerable targets. The researchers found that Plex, the massively popular media server, uses a custom FFmpeg build in which decoders are disabled and a minimal allowlist is in effect, effectively mitigating the PixelSmash risk. Apart from FFmpeg releasing version 8.1.2, which fixes the flaw, Jellyfin also updated its bundled FFmpeg version, and PhotoPrism is working to add a file format blocklist to prevent potential exploitation. The Nextcloud team received the report via HackerOne, but declined to address the flaw because it exists outside of Nextcloud. JFrog discovered PixelSmash (CVE-2026-8461) and reported it to the FFmpeg security team on May 13. The developer addressed the issue in version 8.1.2, released on June 17. The researchers warn that PixelSmash has a huge attack surface because the MagicYUV decoder is present in hundreds of projects that "trust FFmpeg to handle untrusted input safely," turning the vulnerability into a supply-chain problem. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 22, 2026extracted
Loading 40 more…