Tag: organized-crime
All entries tagged organized-crime.
- ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
- Deutsche Bank confirms a third-party vendor incident after 'Unsafe' ransomware group posts alleged employee data
- Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours — four keys from four accounts used from one source in the same second
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records — claim unverified and contradicted by the filing
- FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces
- Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews
- Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered
- Kairos data-theft-only extortion — a US county paid ~$1M with no ransomware encryptor ever recovered
- Google, FBI, Lumen and Shadowserver disrupt the NetNut (Popa) residential-proxy botnet
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containment
- Bumblebee → AdaptixC2 → Akira: a full SEO-poisoning-to-ransomware kill chain with a parallel Swiss intrusion
- Operation Endgame
- The Gentlemen
- ShinyHunters / UNC6240 Oracle PeopleSoft campaign
- ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report
- Attribution and accountability: Jaguar Land Rover and Scattered Spider
- Social engineering and SSO abuse opened the highest-profile intrusions
- npm supply-chain worms — a sustained wave across the week
- ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week
- Klue / Icarus Salesforce OAuth-integration breach — from nine named victims to ~24, then the attacker gets hacked
- NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall
- NYT investigation gives first named attribution for the Jaguar Land Rover ransomware attack — a Russian state-linked criminal group
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- Miasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages
- "The Gentlemen" ransomware claims 478 victims and adds worm propagation — Switzerland the second-most-targeted European country
- Klue/Icarus Salesforce breach widens to ~24 firms; the attacker is itself hacked and a second extortion actor emerges
- Microsoft: "Photo ZIP" phishing laundered through Calendly drops Node.js TonRAT against European hospitality front desks
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paid
- ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
- Edgecution: abusing the Chrome/Edge Native Messaging API as a browser-sandbox-to-host bridge
- "Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
- 8x8 confirms Klue/Icarus Salesforce exfiltration in an SEC 8-K Item 1.05 filing
- WhatsApp-borne VBScript silently installs a ManageEngine RMM agent for living-off-the-land remote control
- PostCSS npm typosquats deliver a Nuitka-compiled Python RAT with Chrome DPAPI credential theft
- Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion
- SocGholish / TA569 — Operation Endgame seized 106 servers, but seven delivery clusters remain operational
- Check Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany named
- Threat actor: INC ransomware's Rust rewrite and BYOVD evolution
- Research: ClickFix matured into a productised malware-as-a-service supply chain
- Law-enforcement momentum — Operation Endgame expands, Silver Fox mass-arrest, Conti loader plea
- The Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator named
- ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure
- Prinz Eugen: a Go-based encryptor that targets recent files first and leaves no ransom note
- Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed
- Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor
- Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
- The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian national
- Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
- Nintendo employee data stolen from third-party HR-survey SaaS (TinyPulse), not Nintendo's own systems
- Sophos X-Ops: underground AI adoption is cautious but concrete — LLM-assisted packers, LLM C2 orchestration, NLP-triaged leak markets
- ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework
- Operation Endgame expands to SocGholish/TA569 — 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites
- Crypto clipboard-hijacker campaign weaponises VirusTotal community reputation to suppress detection
- China arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network
- DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
- Novo Nordisk — FulcrumSec claims authorship, $25M demand refused, data offered for private sale
- Zimperium: Rokarolla Android banking trojan targets 217 apps with full device takeover
- Council of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaign
- iRhythm discloses data theft via social engineering of a third-party-hosted application (SEC 8-K)
- Conti loader developer Oleksii Lytvynenko pleads guilty in US federal court after extradition from Ireland
- Google sues China-based "Outsider" PhaaS network for weaponising Gemini to mass-produce phishing pages
- "Atomic Arch" supply-chain attack hijacks 400+ AUR packages to drop a credential stealer and eBPF rootkit
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named
- AudiA6 ransomware crypto-laundering service dismantled — two charged, Switzerland among the participating countries
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion pattern
- NCSC-CH Week 23: coordinated surge in job-seeker targeting — fake interviews, reshipping identity theft, and LinkedIn-to-GitHub infostealer delivery
- TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative
- Microsoft Threat Intelligence: AI-brand impersonation drives Lumma Stealer and Vidar delivery via signed binaries
- Magecart family runs its skimmer out of Stripe — payload in customer metadata, stolen cards exfiltrated back through api.stripe.com
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services
- ShinyHunters extortion campaign adds DentaQuest — 234 GB published after refusal to pay, 2.6 M dental-benefit records exposed
- Unit 42 Operation FlutterBridge: notarized macOS backdoor hides its logic in a remote WebView and exfiltrates documents through an "AI summarise" feature
- Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and Italy with native-language lures and DLL-side-loaded Atlas RAT
- Sophos 2026 Active Adversary Report: identity is the dominant intrusion root cause
- Sophos finds an attacker-built, AI-orchestrated EDR-evasion testing lab during incident response
- ShinyHunters publishes the Charter Communications dataset after ransom refusal
- GoDaddy documents WordPress malware using Steam profile comments as a Unicode-steganography C2 resolver
- TA4922 — China-nexus cybercrime cluster expands from Japan into Germany, UK and Italy with native-language lures and Atlas RAT
- Sophos 2026 Active Adversary Report — identity the dominant intrusion root cause; Impacket and AnyDesk most-observed post-exploitation
- ShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit records
- Luna Moth / UNC3753: vishing-to-physical-USB data-theft extortion reaches ~$20 M suppression payment and DNS fast-flux C2
- Finance / payments — Stripe-abusing Magecart and OFAC Iran sanctions
- Healthcare — HIPAA breach + healthcare supply-chain exposure
- SmartApeSG ClickFix stages an unnamed RAT that pivots to a weaponised NetSupport Manager
- Ghost Stadium PhaaS — 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain fan credentials before June 11 kickoff
- The Gentlemen ransomware — Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS
- Wiz CIRT names JINX-0164 — LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
- Dutch Police + NCSC dismantle Asocks residential-proxy botnet (~17 M devices, 200 NL-hosted servers seized)
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands
- SANS ISC — Akira ransomware kill chain reconstructed entirely from SSLVPN syslog and Windows EVTX, no EDR
- FBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails
- CrowdStrike, Google and Shadowserver simultaneously sever all four C2 channels of the GlassWorm developer-targeting botnet (not to be confused with the Nx Console / TanStack GitHub-publish chain in § 5) — Russia-attributed, active since early 2025
- ShinyHunters Salesforce campaign — Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
- Google's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage
- UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown "under this name", rebrand probable
- ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized
- The Gentlemen / Storm-2697 — internal "Rocket" backend leaked by a rival; KELA and Check Point dissect the operator inner circle
- Check Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivot
- Asocks residential-proxy botnet — Dutch Police + NCSC dismantle ~17M-device infrastructure hosted in the Netherlands
- Finance — Iberian retail-banking pressure from Grandoreiro plus a parallel Android MaaS
- ShinyHunters lists Charter Communications (Spectrum) — telco victim in the Salesforce-credential campaign
- Check Point Research March-April 2026 AI Threat Landscape Digest: a single operator runs two AI platforms in parallel to breach nine Mexican government agencies
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident
- FBI PSA260521 — Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture
- Megalodon mass-poisons 5,561 GitHub repos in a 6-hour window; SysDiag + Optimize-Build workflows exfiltrate cloud credentials and OIDC tokens
- Kimwolf / "Dort" DDoS-for-hire operator arrested — 30+ Tbps IoT botnet, U.S. DoD-range targeting, AISURU variant
- Netherlands FIOD arrests two over EU sanctions evasion for Stark Industries front; 800 servers seized; NoName057(16) DDoS plumbing dismantled
- Operation Saffron dismantles First VPN — 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed
- TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause
- B1ack's Stash carding marketplace publicly releases 4.6M card records — SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks
- Storm-2949 SSPR-to-Key-Vault Azure kill chain
- TheGentlemen RaaS lists Czech university and Swiss engineering firm on leak site
- Cisco Talos: "demo.pdb" BadIIS variant now a commodity MaaS IIS ISAPI backdoor; lwxat developer alias, builder tool recovered
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
- Grafana Labs CoinbaseCartel breach — victim confirms source-code-only theft, no customer data, ransom rejected
- TeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud services
- INTERPOL Operation Ramz — 13-country MENA cybercrime sweep: 201 arrests, 53 servers seized, Algerian PhaaS server takedown
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- Law-enforcement infrastructure takedowns — Operation Saffron (Switzerland JIT), FIOD/Stark Industries, Kimwolf, INTERPOL Ramz
- The Gentlemen RaaS — Czech university and Swiss engineering firm listed; comms overhaul continues
- Fox Tempest — Microsoft DCU disrupts the malware-signing service feeding Rhysida, INC, Qilin and Akira
- Check Point Research March–April 2026 AI Threat Landscape Digest — operator-run AI platforms breach government agencies
- THORChain — ~$11M cross-chain vault drain on a Switzerland-based protocol
- Rhysida claims Stuttgart municipal data — city denies a confirmed incident
- Grafana Labs / CoinbaseCartel — source-code-only theft confirmed; ransom rejected; detected by canary token
- 7-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records
- TeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this week
- Tycoon2FA after the March 2026 takedown — OAuth Device Authorization Grant abuse on Microsoft 365
- THORChain GG20 Threshold Signature Scheme vault drain — ~$11M across nine chains; Switzerland-based protocol
- BKA arrests Dream Market lead administrator "Speedstepper" in Germany — cryptocurrency-to-physical-gold OPSEC failure after seven years at large
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
- TeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS apps
- The Gentlemen RaaS — backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub
- GemStuffer — RubyGems weaponised as a one-way exfiltration channel scraping UK local-authority ModernGov portals; new abuse pattern targets the asymmetric monitoring gap between package pull and push
- Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain
- TrickMo "TrickMo C" — Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware
- TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
- BKA and ZIT dismantle relaunched Crimenetwork darknet marketplace; German operator arrested in Mallorca on European Arrest Warrant
- BKA — Dream Market lead administrator "Speedstepper" arrested in Germany
- Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation
- Qilin / Agenda RaaS — April 2026 lead at 15% of global ransomware activity, Germany 5% of global victims
- "The Gentlemen" RaaS — operations continue post-leak, decryptor published, FortiOS / Erlang SSH initial access CVEs confirmed
- TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence
- Check Point April 2026 ransomware analysis — Qilin leads at 15%, Germany at 5% of global victims
- BKA Dream Market arrest — "Speedstepper" detained in Germany after seven years at large
- Foxconn — Nitrogen ransomware confirmed against North-American manufacturing sites
- Manufacturing
- Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited
- SMS-blaster smishing establishing itself in Switzerland — portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering
- Canvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9
- Groupe 3R (Réseau Radiologique Romand) — Akira ransomware claims 48 GB; 20 imaging centres across seven Swiss cantons, second attack in twelve months
- Canvas/Instructure extortion — Oxford, Cambridge, Liverpool issue public statements; 44 Dutch universities confirmed; May 12 deadline active
- Inditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
- Akira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victims
- The Gentlemen RaaS — Europe-skewed operation surged approximately 448% QoQ; 32% of Q1 2026 victims in Europe; FortiGate CVE-2024-55591 initial-access funnel
- Akira ransomware — Swiss healthcare case confirmed; broader European playbook unchanged
- TeamPCP → PCPJack — cloud-worm successor evicting prior operator artefacts
- ShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)
- Google Threat Intelligence Group — Europe data-leak landscape 2025
- Europol IOCTA 2026
- Media and political (HU, DE)
- Education (NL, UK, DE)
- Healthcare (CH, NL)
- Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects
- ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas
- Akira ransomware on Groupe 3R — 20 Swiss medical-imaging centres across seven cantons; second cyberattack on the same operator within twelve months