Yanluowang initial access broker pleaded guilty to ransomware attacks

A Russian national will plead guilty to acting as an initial access broker (IAB) for Yanluowang ransomware attacks that targeted at least eight U.S. companies between July 2021 and November 2022.

APT37 hackers abuse Google Find Hub in Android data-wiping attacks

North Korean hackers are abusing Google’s Find Hub tool to track the GPS location of their targets and remotely reset Android devices to factory settings. The attacks are primarily targeting South Koreans.
November 11, 2025

Lazarus Group Deploys Weaponized Documents Against Aerospace & Defense

Security researchers at ENKI have uncovered a sophisticated espionage campaign targeting aerospace and defense organizations, in which the Lazarus Group is weaponizing a new variant of the Comebacker backdoor to infiltrate high-value targets.
November 11, 2025

Researchers Expose Deep Connections Between Maverick and Coyote Banking Malware

Security researchers at CyberProof have uncovered critical connections between two sophisticated banking trojans Maverick and Coyote that are actively targeting Brazilian users through WhatsApp.

From Log4j to IIS, China's Hackers Turn Legacy Bugs into Global Espionage Tools

Multiple Chinese state-linked threat actors are exploiting legacy bugs in widely used software to conduct cyberespionage. These target government, non-profit, and private sector organizations across the U.S., Asia, Europe, and Latin America.
November 7, 2025

Cavalry Werewolf Launches Cyberattack on Government Agencies to Deploy Network Backdoor

A sophisticated cyberattack campaign has been attributed to the threat actor group Cavalry Werewolf, targeting government agencies with the intent to steal sensitive data and establish persistent access within critical infrastructure networks.

MuddyWater Uses Compromised Mailboxes in Global Phishing Campaign

A newly uncovered phishing campaign attributed to the Iran-linked threat actor MuddyWater has targeted international organizations using compromised email accounts. The campaign aimed to gather foreign intelligence and distribute Phoenix v4 backdoor.

The Rise of Collaborative Tactics Among China-aligned Cyber Espionage Campaigns

“Premier Pass-as-a-Service” describes the emerging trend of advanced collaboration tactics between multiple China-aligned APT groups, notably Earth Estries and Earth Naga, that are making modern cyberespionage campaigns even more complex.

Russian hackers evolve malware pushed in "I am not a robot" captchas

The Russian state-backed Star Blizzard hacker group has ramped up operations with new, constantly evolving malware families (NoRobot, MaybeRobot) deployed in complex delivery chains that start with ClickFix social engineering attacks.

Russian State-Sponsored COLDRIVER Group Deploys New Malware After Exposure of LOSTKEYS

Following the public disclosure of its LOSTKEYS malware in May 2025, the Russian state-sponsored threat group known as COLDRIVER, also tracked under aliases such as UNC4057, Star Blizzard, and Callisto, has rapidly evolved its cyber operations.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags