Threat Actors

Cybersecurity
Fengwo Group Ad-Fraud Uses TV Sticks That Spoof as Phones
Bitsight found generic TV streaming sticks spoofing as phones and clicking ads on AI-generated sites in a Fengwo Group ad-fraud network worth $50,000 a day.
Application Security
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Amazon attributed debug and chalk npm hijack to North Korea's Sapphire Sleet, elevating a supply chain attack previously seen as financially motivated.
Application Security
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Cybersecurity
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
Cybersecurity
Nine-Year Fraud Campaign Cloned Russian Company Sites for Payments
Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.
Cybersecurity
Nimbus Manticore Deploys NightLedger Backdoor Across Three Regions
Iran-linked Nimbus Manticore deployed the new NightLedger backdoor and WebSocket tunnelers against targets in the Middle East, Africa, and South Asia.
Cybersecurity
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
Cybersecurity
Operation BlueDash Delivers RMM Tools via Fake Teams Lures
Operation BlueDash deploys Level RMM and ScreenConnect against enterprises through fake Microsoft Teams and Zoom pages linked to a Nigerian threat actor.
Cybersecurity
ShinyHunters Claims Ernst & Young Breach via Third-Party System
ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed client tax and financial data.
Cybersecurity
TELESHIM Backdoor Hits Middle East Governments via Telegram C2
Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern governments.