Medium

VerdaCrypt: The PowerShell Ransomware That Thinks It’s a Philosophy Professor

VerdaCrypt is a sophisticated PowerShell-based ransomware that blends technical stealth with psychological manipulation. Active since April 2025, it operates filelessly and delivers ransom notes filled with philosophical musings.
April 28, 2025

APT36 Uses “Pahalgam Terror Attack” Lure in Targeted Phishing Against Indian Defense Personnel

APT36 weaponized a fake "Pahalgam Terror Attack" report to lure Indian government and defense personnel. The phishing emails contained links mimicking legitimate Indian government domains, leading to the download of CrimsonRAT.
April 28, 2025

IntelBroker: A closer look into a Prolific Cybercrime Threat Actor

IntelBroker is a prolific cybercriminal who transitioned from ransomware operations to data brokering and forum administration, notably BreachForums, between August 2024 and January 2025.
January 24, 2025

GamaCopy Imitates Gamaredon APT, Uses Military-Themed Baits to Launch Attacks on Russia

GamaCopy’s operations leverage military-related documents as bait to entice victims. These documents, embedded in 7z self-extracting (SFX) archives, deliver payloads using obfuscated scripts.

AiTM Phishing, Hold the Gabagool: Analyzing the Gabagool Phishing Kit

The threat actor would initially compromise the user’s mailbox and begin sending phishing emails to other employees. These emails prompt recipients to view an image attached to the email.
July 26, 2024

Patchwork Group Found Using Brute Ratel C4 and an Enhanced Version of PGoShell Backdoor

Patchwork hackers targeted Bhutan using the advanced Brute Ratel C4 tool, along with an updated backdoor called PGoShell. This marks the first time Patchwork has been observed using the red teaming software.

DeepKeep Secures $10M in Seed Funding to Boost GenAI Protection Endeavors

Founded in 2021 by Rony Ohayon, DeepKeep specializes in AI-Native Trust, Risk, and Security Management (TRiSM). The platform caters to large corporations reliant on AI, GenAI, and LLM technologies for risk management and growth protection.

Russian Consular Software Installer Backdoored to Deploy Konni RAT

This activity is linked to actors from North Korea targeting Russia. The trojan is being distributed through backdoored software installers and is capable of file transfers and command execution.

Kimsuky APT Disguises as a Korean Company to Distribute Troll Stealer

Troll Stealer's similarities to known malware families linked to Kimsuky, such as AppleSeed and AlphaSeed, raise concerns about the group's offensive cyber operations and its targeting of South Korean entities.

'Dormant Colors' Campaign Uncovered With Over 1 Million Data Stealing Extension Installations

The “Dormant Colors” is yet another vast campaign of malicious extensions with millions of active installations worldwide, this time with a color-related theme and full of deception all through the chain.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags