Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 231 results
Active filter:tag: #campaign✕ clear
StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentialshighperson_alertThreat Actor
person_alertThreat Actor

StubMaker Campaign Deploys 16 Typosquatted RubyGems to Steal Credentials

StubMaker is a typosquatting campaign tracked by OpenSourceMalware researchers, discovered on August 15, 2026. The campaign operators published 16 malicious RubyGems packages under user accounts "mod8rz41mje" (Riley Miller) and "rbq95bwt6q" (Alex Dav…

RubyGems18 Aug · 09:20 UTC
Evooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot botnet exploits 18 CVEs to turn edge devices into SOCKS5 proxies

Internet-facing Linux-based edge devices including routers (NETGEAR, Tenda, D-Link, TP-Link, Zyxel), IP cameras (Hikvision), enterprise appliances (Alcatel OmniPCX, Mitsubishi ME-RTU, Telesquare SDT-CW3B1/TLR-2005KSH), and servers running vulnerable…

The Hacker News17 Aug · 07:29 UTC
Large-scale DDoS campaign disrupts Threema encrypted messaging servicehighbug_reportVulnerability
bug_reportVulnerability

Large-scale DDoS campaign disrupts Threema encrypted messaging service

Threema secure messaging service (cloud-hosted instances). Users in Switzerland, India, and China reported outages. Threema On-Prem customers unaffected as they use independent infrastructure. Colocation partner Nine also targeted.

Threema16 Aug · 15:29 UTC
AmnesiaStealer malware hijacks macOS browser sessions via live remote controlhighbug_reportVulnerability
bug_reportVulnerability

AmnesiaStealer malware hijacks macOS browser sessions via live remote control

macOS users targeted via ClickFix campaigns using fake GitHub pages. Affects 16 Chromium-based browsers including Chrome, Edge, Brave, Opera, Vivaldi, Arc, and Chromium.

BleepingComputer16 Aug · 13:07 UTC
Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

Evooo1Bot: Mirai-based botnet targets Linux gateways as SOCKS5 proxies

Internet-facing Linux gateway devices (routers, firewalls, edge appliances). Specific vendors and models not disclosed. Mirai-based malware with modular architecture targeting devices with weak credentials or known vulnerabilities.

BleepingComputer15 Aug · 12:14 UTC
Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Jewelbug APT Conducts Dual-Track Espionage and Crypto Fraud

Jewelbug (also tracked as Earth Alux and REF7707) is a China-based threat actor conducting parallel espionage and financially-motivated operations. The group targets government and military entities across the Middle East, Southeast Asia, and South A…

BleepingComputer13 Aug · 16:15 UTC
City-Forum Campaign Targets Salesforce and ServiceNow Portalshighperson_alertThreat Actor
person_alertThreat Actor

City-Forum Campaign Targets Salesforce and ServiceNow Portals

City-Forum is an ongoing data theft campaign, not a formally attributed threat actor group. The campaign has been active since at least March 2025 and is characterized by consistent infrastructure use—a single IP address (158.220.87.79) hosted by Ger…

Salesforce12 Aug · 21:07 UTC
WindRelay NFC relay malware + SpyNote RAT steal cards, take loanshighbug_reportVulnerability
bug_reportVulnerability

WindRelay NFC relay malware + SpyNote RAT steal cards, take loans

Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.

BleepingComputer12 Aug · 20:22 UTC
737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxieshighbug_reportVulnerability
bug_reportVulnerability

737 fake Chrome VPN extensions route traffic through attacker SOCKS5 proxies

Google Chrome Web Store users who installed any of 737 malicious extensions impersonating VPN/proxy services (Proton VPN, NordVPN, Surfshark, ExpressVPN, Cloudflare 1.1.1.1). Approximately 75,000 downloads recorded, primarily Russian users.

Google12 Aug · 16:54 UTC
Cybercriminals Target Social Media Accounts for Sexual Exploitationhighperson_alertThreat Actor
person_alertThreat Actor

Cybercriminals Target Social Media Accounts for Sexual Exploitation

Unattributed cybercriminals conducting coordinated account compromise campaigns targeting social media and online service accounts belonging to adults, children, and student-athletes in the United States.

BleepingComputer12 Aug · 12:15 UTC
Sandworm deploys trojanized WireGuard VPN via fake IT job offershighperson_alertThreat Actor
person_alertThreat Actor

Sandworm deploys trojanized WireGuard VPN via fake IT job offers

Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries.

BleepingComputer11 Aug · 19:07 UTC
Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprintinghighperson_alertThreat Actor
person_alertThreat Actor

Kimwolf v7 Botnet Adds HTTP/2 DDoS with Browser Fingerprinting

Kimwolf (also tracked as AISURU) is an Android and IoT botnet operation active since at least mid-2024. The threat actors behind Kimwolf have demonstrated continuous evolution in their tooling, targeting Android TV boxes since August 2025 and Linux I…

Palo Alto Networks11 Aug · 17:36 UTC
UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UAC-0145 Targets Ukrainian IT Workers via Fake Job Recruitment Campaign

UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence.…

The Hacker News11 Aug · 16:36 UTC
Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolutionhighbug_reportVulnerability
bug_reportVulnerability

Kimwolf v7 botnet targets Android IoT with HTTP/2 DDoS, ENS C2 resolution

Android TV boxes and set-top boxes with unauthenticated Android Debug Bridge (ADB) exposed on port 5555. Primarily affects devices accessible via residential proxy services. ARM-based Android IoT devices running vulnerable configurations.

Unit 42 (Palo Alto)11 Aug · 08:00 UTC
Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructurehighbug_reportVulnerability
bug_reportVulnerability

Aeternum botnet uses Polygon blockchain for decentralized C2 infrastructure

Windows systems infected with Aeternum C++ botnet loader (Build.exe). The malware targets Windows environments and uses Polygon blockchain smart contracts for command and control, making traditional domain/IP-based blocking ineffective.

Unit 42 (Palo Alto)10 Aug · 20:00 UTC
The Com cybercrime collective member sentenced for sextortionhighperson_alertThreat Actor
person_alertThreat Actor

The Com cybercrime collective member sentenced for sextortion

The Com (short for "Community") is a loose-knit online cybercrime collective that targets children and teenagers through multiple specialized subgroups.

BleepingComputer10 Aug · 10:56 UTC
Head Mare Exploits TrueConf Flaws to Deploy PhantomCore Backdoorhighperson_alertThreat Actor
person_alertThreat Actor

Head Mare Exploits TrueConf Flaws to Deploy PhantomCore Backdoor

Head Mare is a threat actor conducting targeted intrusion operations against Russian organizations across critical infrastructure and technology sectors.

TrueConf10 Aug · 09:33 UTC
ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychainhighbug_reportVulnerability
bug_reportVulnerability

ClickFix attacks deliver macOS stealer targeting crypto wallets and Keychain

macOS systems (all CPU architectures). Users tricked into pasting malicious commands into Terminal. Targets cryptocurrency wallets (Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, XRP), browser passwords, Apple iCloud Keychain, and cached credentials.

Apple7 Aug · 16:29 UTC
UNC6671 Conducts Vishing Attacks to Steal SaaS Credentialshighperson_alertThreat Actor
person_alertThreat Actor

UNC6671 Conducts Vishing Attacks to Steal SaaS Credentials

UNC6671 is a financially motivated data extortion group that emerged in early January 2026. The actor operates multiple extortion brands including Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182), and previously operated under the BlackFil…

The Hacker News7 Aug · 16:16 UTC
Two H1 2026 campaigns use compromised email and clipboard hijackinghighbug_reportVulnerability
bug_reportVulnerability

Two H1 2026 campaigns use compromised email and clipboard hijacking

Campaign 1: Users in Czechia, Slovakia, Poland, and Lithuania targeted by GepyS banking malware via compromised corporate email accounts. Campaign 2: Cryptocurrency users globally affected by Rust-based clipboard hijacker monitoring 21 blockchain typ…

BleepingComputer7 Aug · 12:00 UTC
AitM phishing campaign targets Microsoft 365 for payroll email thefthighbug_reportVulnerability
bug_reportVulnerability

AitM phishing campaign targets Microsoft 365 for payroll email theft

Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.

Microsoft7 Aug · 08:38 UTC
ClickFix campaign delivers Go-based macOS stealer targeting crypto walletshighbug_reportVulnerability
bug_reportVulnerability

ClickFix campaign delivers Go-based macOS stealer targeting crypto wallets

macOS users across all versions; targets cryptocurrency wallets (Bitcoin, Ethereum, Litecoin, Dogecoin, Monero, XRP), browser password databases, Apple Keychain, and cached browser credentials.

BleepingComputer6 Aug · 20:37 UTC
UNC6671 extortion group targets financial sector via vishing attackshighperson_alertThreat Actor
person_alertThreat Actor

UNC6671 extortion group targets financial sector via vishing attacks

UNC6671 is a financially motivated extortion group tracked by Google Threat Intelligence Group (GTIG) that operates under multiple public brands including BlackFile, Redact, Pink, Helix, and Falcon.

BleepingComputer6 Aug · 18:07 UTC
Cybercriminals Steal AI API Keys via Token Jacking for Resalehighperson_alertThreat Actor
person_alertThreat Actor

Cybercriminals Steal AI API Keys via Token Jacking for Resale

Cybercriminals targeting the AI development ecosystem are motivated by financial gain through the theft and resale of API keys (tokens) for premium AI platforms.

Unit 42 (Palo Alto)6 Aug · 08:00 UTC
ClickFix Campaign Uses Browser Fingerprinting to Target macOS Usershighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Campaign Uses Browser Fingerprinting to Target macOS Users

ClickFix is a macOS-focused social engineering campaign tracked by Microsoft Threat Intelligence. The operators remain unidentified, but the campaign demonstrates sophisticated evasion capabilities through server-side browser fingerprinting across mo…

Apple5 Aug · 16:44 UTC
Poipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operationshighperson_alertThreat Actor
person_alertThreat Actor

Poipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operations

The Poipet scam network is a Cambodia-based organized criminal operation originating from Poipet, a city with extensive ties to scam compounds and human trafficking.

OpenAI5 Aug · 16:33 UTC
Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAThighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign exploits COLDCARD wallet fears to deploy ScreenConnect RAT

COLDCARD hardware wallet users targeted via phishing emails. Attack delivers ConnectWise ScreenConnect remote access tool via malicious batch file (Coldcard_Diagnostic_Tool.bat) hosted on GitHub.

COLDCARD5 Aug · 15:49 UTC
macOS ClickFix campaign adds fingerprinting to evade detectionhighbug_reportVulnerability
bug_reportVulnerability

macOS ClickFix campaign adds fingerprinting to evade detection

macOS users targeted via 250+ algorithmically generated domains (e.g., filecopperbasket, apricotfilepoint[.]com). Campaign delivers MacSync and Atomic Stealer (AMOS) infostealers. All macOS versions susceptible to social engineering technique.

Apple5 Aug · 13:48 UTC
Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firmshighperson_alertThreat Actor
person_alertThreat Actor

Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms

Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…

Microsoft5 Aug · 09:43 UTC
Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentralhighperson_alertThreat Actor
person_alertThreat Actor

Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral

Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.

Microsoft4 Aug · 19:45 UTC