Cisco Talos

Spam campaign targeting Brazil abuses Remote Monitoring and Management tools

A spam campaign that has been active since at least January 2025 is targeting Portuguese-speaking users in Brazil. The campaign abuses free trials of commercial RMM tools, including N-able and PDQ Connect, to gain unauthorized access to systems.

UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants

A spear-phishing campaign attributed to Russian-speaking threat actors targeted the UK Ministry of Defence (MOD) in late 2024. The attackers deployed a RomCom malware variant known as Damascened Peacock.

Unmasking the new XorDDoS controller and infrastructure

Cisco Talos observed an existing DDoS malware known as XorDDoS, continuing to spread globally between November 2023 and February 2025. A significant finding shows that over 70 percent of attacks using XorDDoS targeted the U.S.

Gamaredon Campaign Abuses LNK Files to Distribute Remcos Backdoor

Cisco Talos reported an ongoing campaign targeting Ukrainian users with malicious LNK files, which run a PowerShell downloader, since at least November 2024. The file names use Russian words related to the movement of troops in Ukraine as a lure.

Chinese Threat Actor UAT-5918 Targets Critical Infrastructure Entities in Taiwan

Typical tooling used by UAT-5918 includes networking tools such as FRPC, FScan, In-Swor, Earthworm, and Neo-reGeorg. Credential harvesting is accomplished by dumping registry hives, NTDS, and using tools such as Mimikatz and browser data stealers.

Attackers Leverage Cascading Style Sheets for Evasion and Tracking

Cybersecurity experts have uncovered how hackers use CSS to deceive spam filters and monitor user behavior. This sophisticated technique allows malicious actors to remain under the radar while gaining insights into user preferences and actions.

Miniaudio and Adobe Acrobat Reader Vulnerabilities Discovered

CVE-2024-41147 is an out-of-bounds write vulnerability in Miniaudio. CVE-2025-27163 and CVE-2025-27164 are out-of-bounds read vulnerabilities in the font functionality in Adobe Acrobat, which can lead to information disclosure.

Lotus Blossom Espionage Group Targets Multiple Industries With Different Versions of Sagerunex and Hacking Tools

Cisco Talos uncovered two new variants of the Sagerunex backdoor, which were detected during attacks on telecommunications and media companies, as well as many Sagerunex variants persistent in the government and manufacturing industries.

New TorNet Backdoor Seen in Widespread Campaign Targeting Europe

Cisco Talos discovered an ongoing malicious campaign operated by a financially motivated threat actor since as early as July 2024 targeting users, predominantly in Poland and Germany, based on the phishing email language.

Threat Actors Use Copyright Infringement Phishing Lure Against Taiwanese Users to Deploy Info-stealers

Cisco Talos has identified a phishing campaign targeting Facebook business users in Taiwan, using emails disguised as legal notices to trick recipients into downloading malware.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags