Connect with us

Security

Cybersecurity Chaos: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + More Shocking Stories

Published

on

A lot of security still comes down to trusting the wrong screen.

This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.

Some defenses improved. The loose parts still got found first. Anyway, here’s the mess.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

  1. Phishing delivers XWorm

    A cybercrime group known as xplogs22 has been observed targeting Russia and other CIS countries with phishing emails that deliver Xworm. The group, per F6, is believed to have been active since November 2023. Prior attacks mounted by the threat actors leveraged Formbook and Snake Keylogger, before switching to XWorm around July 2025. In recent months, Russian customers of the banking sector have also been targeted by an Android trojan called LunaSpy as part of social engineering attacks. LunaSpy can capture camera streams, record audio and the screen, and collect sensitive data. The malware is disguised as an antivirus application to evade detection.

  2. Custom ransomware targets Russia

    The financially motivated extortion group known as Toy Ghouls (aka Bearlyfy and Labubu) has targeted organizations in the Russian Federation, primarily in the manufacturing, financial services, retail, and technology sectors, with a custom ransomware family called GenieLocker since March 2026. According to Kaspersky, the group previously relied on third-party encryptors like RedAlert, LockBit, and Babuk. “GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software,” Kaspersky said. In at least one case, initial access to the target environment was obtained via an OpenVPN connection originating from an external partner’s network, with the attackers likely exploiting the trusted relationship to breach the target, conduct reconnaissance, deliver additional tools for credential harvesting, and perform lateral movement via RDP and SSH to reach other Windows and Linux hosts. “During the impact phase, the attackers encrypted files on the compromised Windows machines with the PE version of the GenieLocker ransomware,” Kaspersky said. “On the compromised Linux and ESXi servers, they stopped active virtual machines and encrypted their disks using the ELF version of GenieLocker.” Details of the activity were first highlighted by F6 in March 2026.

  3. Crypto-stealing payloads deployed

    The malware loader known as CastleLoader, which has been previously used to deliver CastleStealer and a Python-based remote access trojan (RAT) via ClickFix-style lures, has now been used to distribute two payloads tied to the Needle Stealer framework: a Rust-based desktop wallet spoofer, and a Golang-based malicious browser extension installer. Arctic Wolf said it also identified a new shellcode loader variant spreading via digitally signed installers. The campaign has been codenamed Noidret. The introduction of these new tools is seen as an attempt to focus on cryptocurrency-specific targeting and establish browser-level persistence.

  4. Fileless WebDAV execution

    Speaking of ClickFix, CyberProof said it tracked a ClickFix variant that involves tricking victims into pasting a single command into the Windows Run dialog, which then communicates with a WebDAV endpoint and uses rundll32.exe to load a remote, non-DLL payload and call its first export by ordinal without having to leave any artifacts on disk. “The payload (gc.key, j.pm, or goog.ct) is a file served from the attacker WebDAV share and is not a standard DLL by extension,” CyberProof said. “It is invoked by rundll32.exe through ordinal #1, which runs its primary routine while keeping the export name off the command line.”

  5. Fake Claude guide spreads malware

    Victims searching Google for how to install Claude on a Mac are being served sponsored results that lead them to a weaponized claude.ai/share conversation dressed up as an Apple Support install guide. The “guide” instructs them to open Terminal and paste a single curl command, ultimately leading to execution of MacSync Stealer. “MacSync is a six-stage kill chain, not a smash-and-grab,” Huntress said. “The components are a thin zsh loader, a server-side AppleScript stealer that keeps the valuable logic off the endpoint and behind an api-key gate, a native Mach-O RAT for hands-on access, a separately signed helper built to steal a single TCC permission (Screen Recording), and a set of wallet-app trojans. Each stage sets up the ones that follow.”

  6. Malware, intrusions, and influence ops

    A Russian-speaking threat group is said to be behind an active campaign called Operation STANDOFF that combines commodity-malware distribution, a proxy-botnet that conscripts victims into relay infrastructure, targeted hands-on-keyboard intrusion of enterprise networks, and an AI-driven, multi-channel influence and engagement-manipulation capabilities under one roof. “The operation is materially more than a botnet,” VMRay Labs said. “It couples automated, scaled cybercrime with hands-on-keyboard, targeted intrusion and a coordinated influence capability, all on the same infrastructure and built by a common development team.” The influence apparatus uses networks of fake Telegram accounts and AI-generated personas to artificially boost the visibility of content, push commercial promotions, and drive traffic to gambling and fraud-adjacent services.

The operation involves using a pay-per-install (PPI) loader disguised as software installers to distribute Raccoon Stealer, RedLine, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig cryptocurrency miner. Additionally, a targeted operations layer utilizes a custom, multi-operator command-and-control console for human operators to conduct hands-on-keyboard intrusions on selected victims.

GTIG has announced its decision to maintain the use of UNC (uncategorized) for threat clusters that are still under investigation. This approach allows for the classification of threats that are in the early stages of assessment.

One recent development in the cybersecurity landscape is the emergence of a new remote access trojan (RAT) known as MedusaHVNC. This malware-as-a-service (MaaS) offering includes a hidden virtual network computing (HVNC) module that operates stealthily on a victim’s Windows desktop. By opening a browser on a separate desktop that is out of sight, the malware can access live, logged-in sessions without the victim’s knowledge. The RAT supports various applications such as Chrome, Edge, Brave, Firefox, and Telegram, and utilizes a 5-stage infection chain to carry out its malicious activities.

Another concerning incident involved a DNS hijacking attack targeting CubePilot. Threat actors gained control of the cubepilot[.]org domain DNS settings, allowing them to intercept traffic intended for internal systems and obtain TLS certificates covering all subdomains. This attack resulted in the potential exposure of user credentials entered on the compromised services. CubePilot has since regained control of its domains and revoked the fraudulently issued certificates to mitigate the impact of the breach.

Additionally, Japanese organizations have been targeted by the threat actor APT-C-60 through spear-phishing campaigns delivering SpyGlace malware. Despite changes in infrastructure and updates to the malware itself, the attacker continues to exploit legitimate services to deceive recipients and deploy the malicious payload. The spear-phishing emails now contain a Proton Drive link that leads to the download of SpyGlace via a multi-step process involving an intermediate payload from jsDelivr.

Google has introduced CodeMender, an AI agent designed to scan codebases for security flaws, validate their exploitability, and generate fixes for developers. By simulating attacks in an isolated sandbox environment, CodeMender aims to eliminate false positives and prioritize validated risks for remediation. The tool currently supports multiple programming languages and will expand its support for third-party frontier models in the future.

In a collaborative effort, Europol and its partners have targeted extremist content linked to The Com online ecosystem to disrupt propaganda dissemination and prevent radicalization. A total of 4,340 extremist URLs associated with The Com were flagged for removal, with several European countries participating in the initiative. The Com-affiliated groups engage in various illicit activities, including recruitment, grooming, and distribution of harmful content to attract and manipulate individuals for nefarious purposes.

Lastly, cybercriminals are leveraging fake downloads of games, mods, cracks, and software to distribute malware such as RenPy Loader, which leads to the deployment of Amatera Stealer. This multi-stage infection chain involves the abuse of MSBuild and the EtherHiding technique before delivering the final payload. The versatility of RenPy Loader allows for the distribution of other malware variants, highlighting the evolving tactics used by threat actors in spreading malicious software.

In conclusion, staying vigilant and proactive in addressing cybersecurity threats is crucial to safeguarding sensitive information and mitigating potential risks. By remaining informed about emerging threats and implementing robust security measures, organizations can enhance their resilience against cyber attacks and protect their digital assets effectively.

See also  Case of Mistaken Identity: Russian Tourist Detained in Armenia for Alleged REvil Hacker Activity

Trending