Tag: organized-crime
All entries tagged organized-crime.
- AFPA (France's national adult vocational-training agency) confirms a data extraction potentially affecting up to 1.7 million people, traced to a flaw in a third-party-hosted accommodation-management tool
- Talos finds AI-generated Python wiper and mass-deployment scripts in a Qilin-affected environment, identified by step-numbered comments and consistent per-step logging
- The Gentlemen's open-directory attack toolchain: mounting a victim's own VHDX backup files to pull ntds.dit and SAM offline, then chunked-rclone exfil to Wasabi
- A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
- Recorded Future's H1 2026 Malware and Vulnerability Trends: two clusters reuse an identical post-exploitation tool stack across thirteen and ten unrelated initial CVEs
- ChimeraZ claims France's Département de l'Aveyron employment platform, exposing 20,000+ people's data including 1,499 CVs, a customer account without MFA, an IDOR flaw and a misconfigured Odoo database, per one of two trackers who reviewed the leak
- A Teams helpdesk-impersonation campaign installs a Node.js implant (Microsoft detection name: EtherRatz) via a silent MSI, then pivots over WinRM straight to domain controllers and certificate authorities
- MoiClient: an invoice-themed backdoor chains an RPC-based UAC bypass with a vulnerable Lenovo PC Manager driver to kill security products and steal browser credentials
- Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network
- ValleyRAT (Winos 4.0) hides inside a re-signed Chinese wallpaper app: DLL sideloading, a self-restoring svchost injection, and a Windows Defender kill switch
- TerminalFix: a ClickFix variant that pastes into Terminal or PowerShell instead of Windows' Run dialog, then chains DLL sideloading, steganographic payload delivery and a custom reverse-tunnel implant
- A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with the first board-level victim confirmation
- Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida
- TA4922 adds PackClient, a Telegram-sold modular RAT/C2 framework, to its toolkit, dual-channel C2, registry-resident configuration, and tax-themed lures against mainland China and India
- Kudelski Security: North Korean IT-worker infrastructure overlaps a Bismarck-linked gambling-platform operation and the FakeCalls Android banking trojan
- AFP-FBI-WAPF disrupt TeamPCP: two Western Australia men charged over the npm/GitHub supply-chain worm operation AFP estimates compromised 1,000+ organisations, 500,000+ credentials and 300+ GB of data
- SynkLoader: a Teams message from a lookalike tenant, an MSI called 'PowerShell Cleaner', and a six-module toolkit whose fake lock screen harvests the domain password its own tunnel then uses from the victim's IP
- An intrusion crew's AI-written playbook records why time-based blind testing fails against ViewState deserialization, and that a successful exploit returns HTTP 500, which is what most error-rate alerting is tuned to ignore
- SPECTRE unlinks EDR's kernel callbacks one at a time using a two-driver BYOVD toolkit and an offset table for thirteen Windows builds, and its Linux half hides through ftrace rather than the syscall table
- A malware stager is reading its next instruction out of an FTP server's pre-login greeting, and the researchers who found it point out this is the rare command channel that is easier to catch, not harder
- Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
- Spain's Castilla-La Mancha regional government confirms a cyberattack after the Panzer extortion group lists it; the government confirms the intrusion, not the group's data claims
- Grandoreiro's loader decides it is in a sandbox when it finds seven ordinary desktop shortcuts, an inverted environment check, behind a two-hop DLL sideload
- "Ransom Busters" emails ransomware victims before their incident is public, offering to delete the stolen data for a fee, and the tooling says it is the same affiliate who took it
- StopAndProtect runs its whole operation off other people's WordPress sites, a must-use plugin that never appears in the plugin list, a hidden REST route that accepts PHP, and an installer that deletes itself
- Medusa's joint advisory update puts a number on the patch race: affiliates weaponise newly announced flaws within 24 hours, and the agencies find no sign the group develops any of them itself
- Zurich District Court opens the LockerGoga / MegaCortex / Nefilim trial: four named Swiss victims, CHF 100m+ in damage, and an indictment that describes the intrusion pattern step by step
- The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned
- JWR: a phishing kit that puts a live operator on an encrypted WebSocket into the victim's session, reading card and code digits as they are typed and choosing which one-time-code channel to demand
- France's tax authority cut the intruders' accounts in June and July and found no data theft, it took the criminal's sale listing two months later to establish that 678,000 records had already gone
- WindRelay, a purpose-built Android NFC-relay malware installed silently by a companion remote-access trojan during the fraud call itself, with per-victim app names carrying the victim's own name
- MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion, and because it is a processor, not a controller, the people affected cannot be told directly
- Gunra ransomware-as-a-service: a joint six-agency advisory documents FortiOS edge exploitation, a persistent MFA backdoor built from one fixed OTP value, and a Linux encryptor whose keys can be reconstructed
- Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site
- Connor Moucka pleads guilty over the 2024 SaaS-tenant mass-extortion campaign, 165+ victim organisations reached with stolen credentials and no vulnerability in the platform
- An intruder used pam_rootok to move between low-privileged identities as a deliberate forensic smokescreen, inverting what a responder infers from the authentication trail
- Interlock ran Volatility3 and WinPmem against a live endpoint to harvest credentials, the responder's own memory-forensics toolkit used in place of a commodity dumper
- Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people
- UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
- Talos analyses threat actors' own AI coding-assistant prompt logs: guardrails fell to unverified permission claims, and the operator's skill (not model access) decided what got built
- ByteToBreach hits Hungary's State Treasury after Romania's land registry; the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
- CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable
- GenieLocker; a Windows and ESXi ransomware built to leave no ransom note on disk, gated behind a hashed command-line secret so it will not run in a sandbox
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated
- Talos IR Trends Q2 2026: ransomware operators ran their command-and-control through legitimate RMM agents, authentication abuse hit two-thirds of engagements, and missing logs stopped root-cause determination outright
- STAC4749 runs Teams helpdesk vishing from attacker-owned .top domains into certificate-pinned Golang implants and Chaos ransomware in under 17 hours
- An exposed WebDAV delivery lab shows industrialised .url/.lnk lure testing against CVE-2025-33053, with LLM-written tooling and ClickFix pages
- FakeAgent, malvertising hosts a fake AI-desktop-app download page on the vendor's own trusted domain, delivering SectopRAT by DLL side-loading
- German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns
- BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file
- Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'
- Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million, the Swiss rail manufacturer refuses to pay
- Cruciferra: a crypter-as-a-service using kernel-aware process ghosting and BYOVD EDR termination, tied to China-nexus TA4922
- Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware
- TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
- Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
- Cisco Talos: UAT-11795 deploys the Python-based Starland RAT and a bespoke PowerShell C2 implant (WLDR), resolving fallback C2 through a Polygon blockchain dead-drop
- CVE-2026-15409, SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited
- GodDamn ransomware (Beast/Monster rebrand) blinds EDR with 'PoisonX', a malicious kernel driver Microsoft signed
- WP-SHELLSTORM: an exposed webshell-brokerage toolkit reveals 27 weaponized CVEs fired at 1.4M WordPress/Joomla sites plus a parallel Nacos/Spring Boot credential-theft track
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
- ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
- Deutsche Bank confirms a third-party vendor incident after 'Unsafe' ransomware group posts alleged employee data
- Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours, four keys from four accounts used from one source in the same second
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records, claim unverified and contradicted by the filing
- Kairos data-theft-only extortion, a US county paid ~$1M with no ransomware encryptor ever recovered
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach, 2.5 months after containment
- Bumblebee → AdaptixC2 → Akira: a full SEO-poisoning-to-ransomware kill chain with a parallel Swiss intrusion
- NYT investigation gives first named attribution for the Jaguar Land Rover ransomware attack, a Russian state-linked criminal group
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- "The Gentlemen" ransomware claims 478 victims and adds worm propagation, Switzerland the second-most-targeted European country
- Microsoft: "Photo ZIP" phishing laundered through Calendly drops Node.js TonRAT against European hospitality front desks
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paid
- ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
- Edgecution: abusing the Chrome/Edge Native Messaging API as a browser-sandbox-to-host bridge
- "Mistic" backdoor: signed-Defender DLL sideloading and in-memory tradecraft by access broker Woodgnat/KongTuke
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
- WhatsApp-borne VBScript silently installs a ManageEngine RMM agent for living-off-the-land remote control
- PostCSS npm typosquats deliver a Nuitka-compiled Python RAT with Chrome DPAPI credential theft
- Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion
- Prinz Eugen: a Go-based encryptor that targets recent files first and leaves no ransom note
- Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed
- Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor
- Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane
- The Gentlemen (Storm-2697) claims OT-adjacent Mackay Sugar attack; operator attributed to a Russian national
- Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
- Nintendo employee data stolen from third-party HR-survey SaaS (TinyPulse), not Nintendo's own systems
- Sophos X-Ops: underground AI adoption is cautious but concrete, LLM-assisted packers, LLM C2 orchestration, NLP-triaged leak markets
- ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework
- Operation Endgame expands to SocGholish/TA569, 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites
- Crypto clipboard-hijacker campaign weaponises VirusTotal community reputation to suppress detection
- China arrests 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network
- DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
- Zimperium: Rokarolla Android banking trojan targets 217 apps with full device takeover
- iRhythm discloses data theft via social engineering of a third-party-hosted application (SEC 8-K)
- Conti loader developer Oleksii Lytvynenko pleads guilty in US federal court after extradition from Ireland
- Google sues China-based "Outsider" PhaaS network for weaponising Gemini to mass-produce phishing pages
- "Atomic Arch" supply-chain attack hijacks 400+ AUR packages to drop a credential stealer and eBPF rootkit
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named
- AudiA6 ransomware crypto-laundering service dismantled, two charged, Switzerland among the participating countries
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion pattern
- NCSC-CH Week 23: coordinated surge in job-seeker targeting, fake interviews, reshipping identity theft, and LinkedIn-to-GitHub infostealer delivery
- TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative
- Microsoft Threat Intelligence: AI-brand impersonation drives Lumma Stealer and Vidar delivery via signed binaries
- Magecart family runs its skimmer out of Stripe, payload in customer metadata, stolen cards exfiltrated back through api.stripe.com
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services
- Unit 42 Operation FlutterBridge: notarized macOS backdoor hides its logic in a remote WebView and exfiltrates documents through an "AI summarise" feature
- Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and Italy with native-language lures and DLL-side-loaded Atlas RAT
- Sophos 2026 Active Adversary Report: identity is the dominant intrusion root cause
- Sophos finds an attacker-built, AI-orchestrated EDR-evasion testing lab during incident response
- GoDaddy documents WordPress malware using Steam profile comments as a Unicode-steganography C2 resolver
- SmartApeSG ClickFix stages an unnamed RAT that pivots to a weaponised NetSupport Manager
- Ghost Stadium PhaaS, 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain fan credentials before June 11 kickoff
- The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS
- Wiz CIRT names JINX-0164, LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
- Dutch Police + NCSC dismantle Asocks residential-proxy botnet (~17 M devices, 200 NL-hosted servers seized)
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brands
- SANS ISC, Akira ransomware kill chain reconstructed entirely from SSLVPN syslog and Windows EVTX, no EDR
- FBI FLASH CSA 260526, Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails
- CrowdStrike, Google and Shadowserver simultaneously sever all four C2 channels of the GlassWorm developer-targeting botnet (not to be confused with the Nx Console / TanStack GitHub-publish chain in § 5), Russia-attributed, active since early 2025
- ShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
- Google's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage
- Check Point Research March-April 2026 AI Threat Landscape Digest: a single operator runs two AI platforms in parallel to breach nine Mexican government agencies
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident
- FBI PSA260521, Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture
- Megalodon mass-poisons 5,561 GitHub repos in a 6-hour window; SysDiag + Optimize-Build workflows exfiltrate cloud credentials and OIDC tokens
- Kimwolf / "Dort" DDoS-for-hire operator arrested, 30+ Tbps IoT botnet, U.S. DoD-range targeting, AISURU variant
- Netherlands FIOD arrests two over EU sanctions evasion for Stark Industries front; 800 servers seized; NoName057(16) DDoS plumbing dismantled
- Operation Saffron dismantles First VPN, 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed
- B1ack's Stash carding marketplace publicly releases 4.6M card records, SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks
- Storm-2949 SSPR-to-Key-Vault Azure kill chain
- TheGentlemen RaaS lists Czech university and Swiss engineering firm on leak site
- Cisco Talos: "demo.pdb" BadIIS variant now a commodity MaaS IIS ISAPI backdoor; lwxat developer alias, builder tool recovered
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
- Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected
- INTERPOL Operation Ramz, 13-country MENA cybercrime sweep: 201 arrests, 53 servers seized, Algerian PhaaS server takedown
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- Tycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 365
- THORChain GG20 Threshold Signature Scheme vault drain, ~$11M across nine chains; Switzerland-based protocol
- BKA arrests Dream Market lead administrator "Speedstepper" in Germany, cryptocurrency-to-physical-gold OPSEC failure after seven years at large
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
- The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub
- GemStuffer, an OpenAI autonomous-agent swarm gained RCE on RubyGems' companion documentation-build service RubyDoc.info, then tried to steal other users' API keys, and OpenAI never reported it under the EU AI Act
- Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain
- TrickMo "TrickMo C", Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware
- TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
- BKA and ZIT dismantle relaunched Crimenetwork darknet marketplace; German operator arrested in Mallorca on European Arrest Warrant
- SMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering
- Groupe 3R (Réseau Radiologique Romand), Akira ransomware claims 48 GB; 20 imaging centres across seven Swiss cantons, second attack in twelve months
- Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed