Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

30 / 78 results
Active filter:tag: #campaign✕ clear
ClickFix campaigns deploy three malware loaders via fake updateshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaigns deploy three malware loaders via fake updates

Education and financial sector organizations targeted by ClickFix social engineering campaigns delivering BabaDeda Loader, Lorem Ipsum Loader, and Potemkin malware loaders through fake software update lures.

The Hacker News15:41 UTC
GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scanshighperson_alertThreat Actor
person_alertThreat Actor

GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans

GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…

Microsoft12:17 UTC
SprySOCKS malware expands to Windows in government-targeted attackshighbug_reportVulnerability
bug_reportVulnerability

SprySOCKS malware expands to Windows in government-targeted attacks

Government organizations in at least four countries. Windows systems now targeted alongside previously known Linux variants. Specific Windows versions and attack vector not disclosed.

BleepingComputer07:00 UTC
Contagious Interview targets developers via recruitment-themed phishinghighperson_alertThreat Actor
person_alertThreat Actor

Contagious Interview targets developers via recruitment-themed phishing

Contagious Interview (also tracked as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, and DEV#POPPER) is a North Korean-aligned threat actor cluster that specializes in social engineering attacks against software developers and technology secto…

The Hacker News17:32 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer12:36 UTC
Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Chinese Cybercrime Network Weaponizes Google Gemini AI for SMS Phishing

A Chinese cybercrime network operating a phishing-as-a-service (PhaaS) platform called Outsider. The group weaponizes Google's Gemini AI to craft and conduct SMS-based phishing attacks (smishing) targeting American victims.

Google16:59 UTC
UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC1151/Ghostwriter Targets Polish Gmail Accounts in Phishing Campaign

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities.

Google09:00 UTC
INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL arrests Guedz, admin of Sniper Dz phishing-as-a-service platform

Guedz is identified as the primary administrator of Sniper Dz, a phishing-as-a-service (PhaaS) platform that operated for approximately a decade across the Middle East and North Africa (MENA) region.

The Hacker News06:52 UTC
NFCShare Android malware distributed via GitHub as fake banking app updateshighbug_reportVulnerability
bug_reportVulnerability

NFCShare Android malware distributed via GitHub as fake banking app updates

Android mobile users, particularly customers of targeted banking applications. Malware distributed through GitHub repositories posing as legitimate banking app updates.

BleepingComputer20:11 UTC
NSO Group linked to WhatsApp spear-phishing campaignshighperson_alertThreat Actor
person_alertThreat Actor

NSO Group linked to WhatsApp spear-phishing campaigns

NSO Group is an Israeli cyber intelligence firm that develops and sells commercial surveillance technology, primarily the Pegasus spyware platform. The company markets its tools to government clients for lawful interception and intelligence gathering…

WhatsApp16:40 UTC
UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusionhighperson_alertThreat Actor
person_alertThreat Actor

UNC3753 Conducts Data Theft Extortion via Vishing and Physical Intrusion

UNC3753 is a financially motivated threat actor attributed by Mandiant. The group conducted a data theft extortion campaign targeting dozens of organizations in the United States between January and May 2026.

The Hacker News05:39 UTC
Silent Ransom Group targets U.S. legal sector via fake IT supporthighperson_alertThreat Actor
person_alertThreat Actor

Silent Ransom Group targets U.S. legal sector via fake IT support

Silent Ransom Group is a threat actor conducting social engineering-driven intrusions against U.S. legal services and professional services organizations.

BleepingComputer12:09 UTC
Asin Android spyware targets Arabic-speaking users via fake appshighbug_reportVulnerability
bug_reportVulnerability

Asin Android spyware targets Arabic-speaking users via fake apps

Android devices used by Arabic-speaking populations. Malware distributed through fake applications impersonating news sources, PDF utilities, and war-related content. Active campaigns identified since early 2025.

Android12:53 UTC
FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malwarehighperson_alertThreat Actor
person_alertThreat Actor

FBI Warns of FIFA World Cup 2026 Fraud Campaign with Banking Malware

This is a cybercrime campaign leveraging the FIFA World Cup 2026 tournament as a lure, rather than a single named threat actor. The campaign involves multiple financially motivated threat actors exploiting public interest in the tournament to distrib…

The Hacker News05:01 UTC
PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Networkhighperson_alertThreat Actor
person_alertThreat Actor

PCPJack Hijacks 230+ Cloud Servers for Covert SMTP Relay Network

PCPJack is a threat actor focused on compromising cloud infrastructure to establish illicit email relay networks. The actor has demonstrated capability to breach business servers across major cloud service providers (AWS, Google Cloud, Microsoft Azur…

Amazon Web Services03:34 UTC
DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaignshighperson_alertThreat Actor
person_alertThreat Actor

DriveSurge Distributes Malware via ClickFix and FakeUpdate Campaigns

DriveSurge is a threat actor conducting large-scale malware distribution operations. The actor leverages compromised website infrastructure at scale, utilizing thousands of sites to host and deliver malicious payloads.

BleepingComputer20:14 UTC
Meta AI bot exploited to hijack high-profile Instagram accountshighbug_reportVulnerability
bug_reportVulnerability

Meta AI bot exploited to hijack high-profile Instagram accounts

Meta Instagram platform, specifically the AI-powered customer support bot used for account recovery. High-profile accounts including Obama White House and U.S. Space Force Chief Master Sergeant were compromised.

Meta15:32 UTC
Malware campaign infects 2,000 WordPress sites using Steam profiles for C2highbug_reportVulnerability
bug_reportVulnerability

Malware campaign infects 2,000 WordPress sites using Steam profiles for C2

Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).

WordPress15:04 UTC
Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2highperson_alertThreat Actor
person_alertThreat Actor

Operation Dragon Weave targets Czech and Taiwan entities with AdaptixC2

Operation Dragon Weave is a cyber espionage campaign linked to China-aligned threat actors. The campaign's motivation appears to be intelligence collection targeting government officials, researchers, academics, and professionals in the Czech Republi…

The Hacker News09:54 UTC
Dutch authorities dismantle botnet controlling 17M infected deviceshighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities dismantle botnet controlling 17M infected devices

At least 17 million infected devices globally including computers, tablets, smartphones, and IoT devices. Over 200 command-and-control servers located in the Netherlands were seized.

The Hacker News10:22 UTC
Threat actors abuse ChatGPT sharing to host fake OpenAI outage pageshighbug_reportVulnerability
bug_reportVulnerability

Threat actors abuse ChatGPT sharing to host fake OpenAI outage pages

OpenAI ChatGPT users globally. Threat actors exploit ChatGPT's legitimate content-sharing feature (chatgpt.com shared links) to host convincing phishing pages that impersonate OpenAI outage notifications and distribute malware posing as the ChatGPT d…

OpenAI16:21 UTC
Dutch authorities disrupt 17M-device botnet, seize 200+ servershighbug_reportVulnerability
bug_reportVulnerability

Dutch authorities disrupt 17M-device botnet, seize 200+ servers

Approximately 17 million infected devices globally; over 200 servers seized from a Dutch hosting provider. Specific botnet malware family and affected device types not disclosed.

BleepingComputer12:26 UTC
Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentialshighperson_alertThreat Actor
person_alertThreat Actor

Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials

Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…

npm01:04 UTC
GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malwarehighperson_alertThreat Actor
person_alertThreat Actor

GreyVibe Targets Ukraine with AI-Generated Lures and Custom Malware

GreyVibe is a threat cluster assessed with moderate confidence to be linked to Russian interests, based on targeting patterns and geopolitical alignment.

BleepingComputer20:24 UTC
BTMOB Android RAT offered as MaaS with custom phishing builderhighbug_reportVulnerability
bug_reportVulnerability

BTMOB Android RAT offered as MaaS with custom phishing builder

Android devices targeted by BTMOB remote access trojan. No specific vendor or version restrictions; affects users who install malicious APKs distributed through phishing campaigns.

BleepingComputer19:10 UTC
FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cuphighperson_alertThreat Actor
person_alertThreat Actor

FBI warns of FIFA-impersonating fraud sites targeting 2026 World Cup

Unknown fraud operators are conducting financially motivated cybercrime campaigns targeting fans and consumers interested in the 2026 FIFA World Cup. These actors leverage social engineering and brand impersonation tactics to establish fraudulent web…

BleepingComputer17:08 UTC
Arctic Wolf exploits FortiClient EMS flaw for credential thefthighperson_alertThreat Actor
person_alertThreat Actor

Arctic Wolf exploits FortiClient EMS flaw for credential theft

Arctic Wolf is a threat actor exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware.

Fortinet13:26 UTC
JINX-0164 Targets Cryptocurrency Orgs with macOS Malwarehighperson_alertThreat Actor
person_alertThreat Actor

JINX-0164 Targets Cryptocurrency Orgs with macOS Malware

JINX-0164 is a previously undocumented threat actor with a financial motivation focused on digital asset theft. The group demonstrates technical sophistication through the development of custom macOS malware and operational tradecraft centered on soc…

The Hacker News05:54 UTC
Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malwarehighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and AI chatbots for GPU malware

High-performance systems with GPUs accessed via search engines and AI chatbot platforms. No specific vendor or product vulnerability; targets users searching for legitimate software or information through poisoned search results and manipulated chatb…

BleepingComputer19:31 UTC
Banking trojans Grandoreiro and BTMOB target LATAM and Europehighbug_reportVulnerability
bug_reportVulnerability

Banking trojans Grandoreiro and BTMOB target LATAM and Europe

Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.

Windows14:10 UTC