Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 39 results
highperson_alertThreat ActorStreamRat Android Banking Trojan Spread via Meta Ads to EU Users
ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed.
criticalperson_alertThreat ActorDark Web Service Sells 153M+ Driver Licenses from Identity Verification Breach
The threat actor operates "Nexus," a dark web identity theft service launched on the Russian cybercrime forum Exploit in August 2025. The operator claims to have continuously exfiltrated data for over a year from an alleged breach at a major Louisian…
highperson_alertThreat ActorBreeze Comet Targets Brazilian Financial Sector for Payment Fraud
Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.
highperson_alertThreat ActorVenezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure
This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.
highbug_reportVulnerability19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates
19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.
highperson_alertThreat ActorINTERPOL Operation Jackal IV Targets Black Axe and West African Crime
Black Axe and associated West African organized crime groups are transnational criminal networks responsible for a significant share of global cyber-enabled financial fraud.
highbug_reportVulnerabilityZombie Card attack revives expired Visa contactless cards via NFC relay
Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.
highperson_alertThreat Actor€30M Bank Fraud via Service Provider Exploit Targets Commerzbank
An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.
highbug_reportVulnerabilityWindRelay NFC relay malware + SpyNote RAT steal cards, take loans
Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.
highperson_alertThreat ActorUNC6671 Conducts Vishing Attacks to Steal SaaS Credentials
UNC6671 is a financially motivated data extortion group that emerged in early January 2026. The actor operates multiple extortion brands including Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182), and previously operated under the BlackFil…
highperson_alertThreat ActorUNC6671 extortion group targets financial sector via vishing attacks
UNC6671 is a financially motivated extortion group tracked by Google Threat Intelligence Group (GTIG) that operates under multiple public brands including BlackFile, Redact, Pink, Helix, and Falcon.
highperson_alertThreat ActorPoipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operations
The Poipet scam network is a Cambodia-based organized criminal operation originating from Poipet, a city with extensive ties to scam compounds and human trafficking.
criticalbug_reportVulnerabilityCOLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin
COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.
criticalbug_reportVulnerabilityColdcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes
Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).
highperson_alertThreat ActorFraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin
The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.
highperson_alertThreat ActorSourTrade Campaign Delivers Malware via Browser-Assembled Executables
SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…
highbug_reportVulnerabilityMalvertising campaign targets crypto users with in-memory malware assembly
Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.
highbug_reportVulnerabilityInsurance phishing evolves to real-time account hijacking via OTP relay
Insurance providers globally, with primary focus on Saudi Arabia; additional activity in Europe, US, and India. Affects customers of multiple insurance brands using online portals for policy management, claims, and payments.
highbug_reportVulnerabilityMalicious npm and PyPI packages impersonate Paysafe payment SDKs
Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…
highbug_reportVulnerabilityRedWing Android MaaS enables bank fraud via credential theft
Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.
highbug_reportVulnerabilityOusaban banking trojan targets Spain and Portugal via phishing
Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…
highperson_alertThreat ActorSilent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions
Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…
highperson_alertThreat ActorPre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors
The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.
highbug_reportVulnerability236K+ malicious sites use DCloud Uni-App templates for crypto scams
Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.
highbug_reportVulnerabilityPolymarket frontend compromised via third-party vendor; $3M stolen
Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.
highbug_reportVulnerabilityClipboard-stealing malware spreads via USB, targets crypto wallets
Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.
highbug_reportVulnerabilityWindows cryptocurrency clipper campaign uses USB worms and Tor C2
Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.
highbug_reportVulnerabilityCryptocurrency clipper malware with worm propagation targets Windows
Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.
highbug_reportVulnerabilityRokarolla Android banking trojan targets 217 banking and crypto apps
Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.
highperson_alertThreat ActorFBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform
Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…