Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 258 results
Active filter:tag: #campaign✕ clear
RedWing Android MaaS enables bank fraud via credential thefthighbug_reportVulnerability
bug_reportVulnerability

RedWing Android MaaS enables bank fraud via credential theft

Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.

The Hacker News7 Jul · 15:10 UTC
DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishinghighperson_alertThreat Actor
person_alertThreat Actor

DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing

DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.

Microsoft7 Jul · 13:14 UTC
Phishing campaign targets marketing professionals via fake job interviewshighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets marketing professionals via fake job interviews

Marketing professionals with Google accounts; campaign impersonates 30+ brands including Adobe, Netflix, Coca-Cola, OpenAI. Credential theft targeting Google accounts specifically.

Adobe6 Jul · 18:27 UTC
Attackers impersonate IT support on Teams calls to deploy EtherRAThighbug_reportVulnerability
bug_reportVulnerability

Attackers impersonate IT support on Teams calls to deploy EtherRAT

Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.

Microsoft6 Jul · 18:23 UTC
China-nexus actor targets Indian finance sector via DcRAT malwarehighperson_alertThreat Actor
person_alertThreat Actor

China-nexus actor targets Indian finance sector via DcRAT malware

A suspected China-nexus threat actor is conducting Operation DragonReturn, a targeted espionage campaign against Indian taxpayers and finance professionals.

The Hacker News6 Jul · 08:58 UTC
NetNut Residential Proxy Network Disrupted After Compromising 2M Deviceshighperson_alertThreat Actor
person_alertThreat Actor

NetNut Residential Proxy Network Disrupted After Compromising 2M Devices

NetNut operated a residential proxy network that leveraged approximately 2 million compromised Android devices to provide unauthorized proxy services. The actor monetized access to infected devices including smart TVs and streaming boxes, selling res…

Google3 Jul · 15:50 UTC
EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platformhighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform

EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.

Microsoft3 Jul · 12:12 UTC
Armored Likho targets government and energy sectors with BusySnakehighperson_alertThreat Actor
person_alertThreat Actor

Armored Likho targets government and energy sectors with BusySnake

Armored Likho is a previously undocumented threat actor attributed by Kaspersky to cyber attacks targeting government agencies and the electric power sector.

The Hacker News3 Jul · 11:36 UTC
PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Managerhighperson_alertThreat Actor
person_alertThreat Actor

PamStealer: macOS Info Stealer Masquerades as Maccy Clipboard Manager

PamStealer is a newly discovered macOS information stealer malware family identified by Jamf Threat Labs. The malware is distributed through social engineering, masquerading as a legitimate Maccy clipboard manager application to deceive users into in…

Apple3 Jul · 06:03 UTC
NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBIhighperson_alertThreat Actor
person_alertThreat Actor

NetNut (Popa) Residential Proxy Botnet Disrupted by Google, FBI

NetNut, also tracked as Popa, operates a residential proxy network built on approximately 2 million compromised home devices. The actor monetizes this infrastructure by selling proxy services that route malicious traffic through legitimate residentia…

Google2 Jul · 16:54 UTC
ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token thefthighbug_reportVulnerability
bug_reportVulnerability

ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft

Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.

Microsoft2 Jul · 12:00 UTC
FortiBleed Campaign Linked to INC and Lynx Ransomware Operationshighperson_alertThreat Actor
person_alertThreat Actor

FortiBleed Campaign Linked to INC and Lynx Ransomware Operations

The FortiBleed campaign is a financially-motivated credential theft operation attributed to actors associated with the INC and Lynx ransomware groups. The campaign focuses on exploiting FortiGate devices to harvest credentials, which are subsequently…

Fortinet2 Jul · 06:00 UTC
Fake GitHub PoC repos deliver ChocoPoC trojan to security researchershighbug_reportVulnerability
bug_reportVulnerability

Fake GitHub PoC repos deliver ChocoPoC trojan to security researchers

Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.

GitHub2 Jul · 05:24 UTC
INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Thefthighperson_alertThreat Actor
person_alertThreat Actor

INC and Lynx Ransomware Groups Exploit FortiBleed for Credential Theft

INC and Lynx are ransomware threat actors linked to the FortiBleed credential theft campaign. These groups operate with the primary motivation of financial gain through ransomware deployment.

Fortinet1 Jul · 19:37 UTC
Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchershighbug_reportVulnerability
bug_reportVulnerability

Trojanized GitHub PoC exploits deliver ChocoPoC RAT to researchers

Cybersecurity researchers and security teams downloading proof-of-concept exploit code from GitHub repositories. ChocoPoC is a Python-based remote access trojan with command execution and data exfiltration capabilities.

BleepingComputer1 Jul · 18:08 UTC
Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnecthighperson_alertThreat Actor
person_alertThreat Actor

Massive SEO-Poisoned Campaign Distributes AsyncRAT via ScreenConnect

The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, consistent with commodity RAT deployment for access brokering, credential theft, or follow-on ransomware operations.

OBS Studio1 Jul · 15:53 UTC
VEIL#DROP campaign delivers PureLogs stealer via Blogger pageshighperson_alertThreat Actor
person_alertThreat Actor

VEIL#DROP campaign delivers PureLogs stealer via Blogger pages

VEIL#DROP is a multi-stage malware delivery campaign identified by Securonix researchers. The campaign employs social engineering tactics and abuses legitimate Blogger platform infrastructure to distribute PureLogs, an information-stealing malware.

Google Blogger1 Jul · 15:18 UTC
Password-spray campaign hits Microsoft 365 with 81M login attemptshighbug_reportVulnerability
bug_reportVulnerability

Password-spray campaign hits Microsoft 365 with 81M login attempts

Microsoft 365 environments (Exchange Online, Azure AD/Entra ID, SharePoint, Teams). All organizations using M365 cloud services are potential targets. Attack focuses on user authentication endpoints.

Microsoft1 Jul · 14:38 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet1 Jul · 13:26 UTC
RustDuck Botnet Targets IoT Devices for DDoS Operationshighperson_alertThreat Actor
person_alertThreat Actor

RustDuck Botnet Targets IoT Devices for DDoS Operations

RustDuck is a two-stage malware family written in Rust, designed to compromise Internet of Things (IoT) devices including home routers, IP cameras, Android set-top boxes, and inadequately secured servers.

Generic routers30 Jun · 15:45 UTC
Fake Perplexity AI Chrome extension hijacks search traffic on Web Storehighbug_reportVulnerability
bug_reportVulnerability

Fake Perplexity AI Chrome extension hijacks search traffic on Web Store

Google Chrome users who installed the malicious Perplexity AI impersonator extension from the Chrome Web Store. Affects organizations and individuals using Chrome browser seeking AI productivity tools.

Google30 Jun · 13:46 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google30 Jun · 13:40 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News30 Jun · 09:30 UTC
236K+ malicious sites use DCloud Uni-App templates for crypto scamshighbug_reportVulnerability
bug_reportVulnerability

236K+ malicious sites use DCloud Uni-App templates for crypto scams

Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.

DCloud29 Jun · 09:57 UTC
Microsoft removes 119 malicious Edge extensions hiding malware via steganographyhighbug_reportVulnerability
bug_reportVulnerability

Microsoft removes 119 malicious Edge extensions hiding malware via steganography

Microsoft Edge browser users who installed any of 119 malicious extensions from the official Microsoft Edge Add-ons store. Campaign active since at least 2021, affecting unknown number of users globally.

Microsoft29 Jun · 06:32 UTC
Russian Intelligence Services Target Messaging Accounts via Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Messaging Accounts via Phishing

Russian intelligence services conducted a long-running credential harvesting campaign targeting messaging platforms. The operation, uncovered jointly by Ukraine's Security Service (SSU) and the FBI, focused on stealing authentication credentials from…

The Hacker News27 Jun · 15:27 UTC
Russian Intelligence Services Target Signal Users in Phishing Campaignhighperson_alertThreat Actor
person_alertThreat Actor

Russian Intelligence Services Target Signal Users in Phishing Campaign

Russian intelligence services are conducting a phishing campaign targeting Signal messaging application users. The operation is attributed by the FBI and CISA, indicating state-sponsored activity aimed at compromising secure communications.

Signal26 Jun · 20:06 UTC
SharkLoader malware deploys Cobalt Strike in attacks on Asian governmentshighbug_reportVulnerability
bug_reportVulnerability

SharkLoader malware deploys Cobalt Strike in attacks on Asian governments

Diplomatic and government organizations in Indonesia and Taiwan. SharkLoader is a newly identified malware family used to deliver Cobalt Strike Beacon payloads in the StrikeShark campaign.

The Hacker News26 Jun · 16:17 UTC
Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firmshighperson_alertThreat Actor
person_alertThreat Actor

Unknown Actors Exploit OpenAI Tenants to Phish Cybersecurity Firms

The threat actors behind this campaign remain unattributed. Their motivation appears to be intelligence gathering and corporate espionage, leveraging the trust associated with OpenAI's platform to deceive employees of cybersecurity companies.

BleepingComputer26 Jun · 15:49 UTC
Phishing campaign targets hotel front desks with Node.js implanthighbug_reportVulnerability
bug_reportVulnerability

Phishing campaign targets hotel front desks with Node.js implant

Hotel and hospitality organizations in Europe and Asia. Front-desk systems targeted via photo-themed ZIP file attachments containing Node.js-based malware. Campaign active since April 2026.

Microsoft26 Jun · 07:27 UTC