Connect with us

Security

ThreatsDay: Self-Rewriting Agents, Patched Flaws, and Insider SIM Swaps – A Roundup of 22 New Stories

Published

on

into plain text. The ransomware group Settra has been expanding its attacks by using MeshAgent remote access software in two intrusions analyzed by Huntress. While the initial access method is still unknown, both attacks followed a similar pattern of deploying RMM tools for persistence, encrypting files, dropping ransom notes, clearing event logs, and disabling recovery options. This shows a concerning trend of ransomware groups becoming more sophisticated in their tactics and targeting a wider range of organizations.

The group was involved in a plot to jackpot ATMs by using malware to manipulate the machines and dispense cash illegally. The guilty pleas indicate that they acknowledged their involvement in the scheme to steal money from ATMs in the United States.

ATM Jackpotting: A Growing Threat

ATM jackpotting, a sophisticated form of cybercrime, has been on the rise in recent years. In December 2025, the U.S. Justice Department reported that a group of defendants traveled from Indiana to Kansas with the intention of stealing cash from ATMs in Wamego and Manhattan using jackpotting techniques. Their plan involved physically installing malware into the ATMs to remotely activate a command that would dispense cash for them to collect. However, their attempts were unsuccessful as law enforcement responded to the alarm triggered during the installation process. Surveillance cameras captured the incidents, leading to the arrest of the perpetrators a few days later. This case is just one of many, with the FBI recording 1,900 jackpotting incidents since 2020, including over 700 incidents in 2025 alone, resulting in losses exceeding $20 million.

See also  Emergency Response: Zendesk Ticket Systems Under Siege in Global Spam Attack

Eight-Year Sentence for ATM Jackpotting

In a separate incident, Juan Manuel Gouveia-Aguilera, a 27-year-old from Venezuela, received an eight-year prison sentence for his involvement in a conspiracy to deploy Ploutus malware and steal millions of dollars from ATMs in the U.S. Gouveia-Aguilera was found responsible for over $3.5 million in losses, resulting in the longest federal sentence for an individual in an ATM jackpotting case. The malware used in such attacks includes ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus, highlighting the evolving tactics employed by cybercriminals in targeting ATMs.

Nearly $13 Billion Associated with Suspected Crypto Scams

According to the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN), approximately $12.7 billion in financial activity has been linked to suspected digital asset investment scams between September 2023 and December 2025. These scams, orchestrated by overseas scam centers, often involve fraudulent schemes where perpetrators impersonate potential partners or create fake investment platforms to deceive victims. The use of guarantee marketplaces to facilitate illicit services further complicates the landscape of digital asset scams, highlighting the need for enhanced regulatory measures and enforcement actions.

The recent surge in ATM jackpotting incidents and digital asset scams underscores the evolving nature of cyber threats and the importance of proactive cybersecurity measures. It is crucial for organizations and individuals to regularly assess and secure their systems, addressing vulnerabilities and implementing robust security protocols to mitigate risks. By staying informed about emerging threats and adopting best practices in cybersecurity, stakeholders can better safeguard against malicious activities and protect their assets from potential harm.

See also  Google Security Engineer Accused of Insider Trading on Polymarket

As technology continues to advance, the security landscape will inevitably evolve, presenting new challenges and opportunities for cybercriminals. By remaining vigilant and proactive in addressing cybersecurity risks, individuals and organizations can enhance their resilience against emerging threats and safeguard their digital assets effectively.

Ultimately, cybersecurity is a shared responsibility that requires collective efforts to combat cyber threats and uphold the integrity of digital ecosystems. By prioritizing cybersecurity awareness and investing in comprehensive security measures, stakeholders can contribute to a safer and more secure online environment for all.

Trending