Threat Actors

Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Cybersecurity
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
CERT-UA attributes a Sandworm-linked UAC-0145 social engineering campaign using fake job interviews and trojanized WireGuard VPN clients against Ukraine.
Cybersecurity
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
Palo Alto Unit 42 documents Kimwolf v7 using HTTP/2 C2 to mimic legitimate browsing, evade DDoS detection, and expand across Android and IoT devices worldwide.
Cybersecurity
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Head Mare hacktivists exploited TrueConf servers and replaced client installers with backdoored versions carrying PhantomCore and PhantomGraph backdoors.
Cybersecurity
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
Google Threat Intelligence ties hedge fund vishing attacks to UNC6671 (BlackFile), an extortion group rebranding across Redact, Pink, Helix, and Falcon.
Cybersecurity
TeamPCP Tied to Redis Attacks Dating Back to 2020
Oligo Security researchers tied the TeamPCP cluster to Redis attacks dating back to April 2020 and to its later evolution into the ShadowRay 2.0 campaign.
Cybersecurity
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation
A federal judge in Virginia sentenced Belarusian Maksim Silnikau, the creator of Ransom Cartel, to 16 years for running a ransomware-as-a-service operation.
Cybersecurity
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
Connor Riley Moucka pleaded guilty in Seattle federal court to intrusions into 165 Snowflake customers that exposed records of more than 100 million people.
Cybersecurity
US Water Sector Attacks Hit 12 States, Georgia Confirmed
Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton County pump station disruption.
Cybersecurity
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.