<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/malware" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Malware ]]></title>
                <link>https://www.itpro.com/security/malware</link>
        <description><![CDATA[ All the latest malware content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 24 Jul 2026 08:23:13 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ NCSC issues alert over 'zero-click' phishing campaign hitting enterprises ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises</link>
                                                                            <description>
                            <![CDATA[ Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TBMSiPEYprpUySAU2QTRDj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 08:23:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has issued an alert over a new ‘zero-click’ threat campaign being waged by Russian state-backed hackers.</p><p>The advisory, published in collaboration with international partners, warned ‘beehive’ attacks by the ‘Laundry Bear’ threat group aim to steal email correspondence at organizations operating across a range of critical sectors. </p><p>This includes organizations in the defense, education, energy, and technology industries, as well as law enforcement and government agencies. </p><p>Attacks against these organizations all have a common theme, according to the NCSC, mainly the use of Zimbra Collaboration Suite (ZCS) software. Targeting focuses specifically on those using vulnerable versions of the software, the advisory noted. </p><p>Rather than requiring users to click a link or open a file, zero-click attacks mean users only have to view a malicious email to be compromised. </p><p>The NCSC urged organisations that use ZCS to follow mitigation advice, patch immediately, and “improve network monitoring capabilities”. </p><p>Crucially, analysis of the campaign found these techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations. </p><p>“This <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said NCSC chief operating officer (COO) Beth Hopkins.</p><h2 id="ukrainian-organizations-used-in-testing">Ukrainian organizations used in testing </h2><p>According to the NCSC, the techniques used by Laundry Bear were “extensively trialled” on Ukrainian victims before use against other Western nations. The security agency noted this is part of a growing trend among Russian threat groups.</p><p>Notably, technical analysis of the campaign also highlighted the use of AI in development of a “simple codebase” used during operations. </p><p>Zero-click attacks have surged in frequency over the last 12 months, research shows, with threat actors accelerating efforts to capitalize on vulnerabilities. </p><p><a href="https://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/" target="_blank"><u>Analysis from Rapid7</u></a> found that vulnerability exploitation has now surpassed social engineering as the “largest initial access vector”, accounting for more than one-third (38%) of all attacks. </p><p>More than 50% of all exploited vulnerabilities involved zero-click attacks, rather than network-facing vulnerabilities, the study noted, highlighting evolving techniques by threat actors. </p><p>“These types of vulnerabilities require no authentication and no user interaction, giving attackers rapid pathways into exposed systems and edge infrastructure,” Rapid7 noted. </p><p>Dray Agha, senior manager of security operations at Huntress, said these types of exploits are a “worst-case scenario for defenders” as potential victims are only required to view malicious emails. </p><p>“Simply viewing the email in a vulnerable client triggers the compromise,” he explained. “This completely bypasses traditional employee security training and gives state-backed hackers a silent, invisible backdoor into sensitive communications without the victim ever making a mistake.”</p><p>Agha said the rise of these techniques mean organizations need to place a greater focus on regular patching to avoid falling prey. </p><p>“This is why defense-in-depth is advised, as where the human security layer is porous, the technical defensive layer can step in,” he said. </p><p>“Organizations shouldn’t just rely on their staff acting as a ‘human firewall’. Rapid software patching, coupled with layered technical defenses, is the only reliable safety net against modern state-sponsored threats.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are posing as Interpol to target small businesses – here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-posing-as-interpol-to-target-small-business-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Small businesses are warned to think twice before clicking on links ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dfEYQHdzwBELh5bxQfdbGS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jul 2026 10:58:23 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Jul 2026 21:36:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Criminals are posing as Interpol cyber crime investigators to target small businesses across Europe, Asia, the Middle East, and North America.</p><p>According to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-interpol-emails-serve-ransomware" target="_blank"><u>new research from Bitdefender</u></a>, the phishing messages claim to contain evidence that the recipients are carrying out suspicious activity, pressuring them into opening a password-protected archive.</p><p>"Based on information that has come to our attention, there may be activities involving accounts, systems or services associated with your organization that warrant further examination. We have obtained information and video material that may assist in your assessment of the matter," the emails read. </p><p>"We recommend conducting an internal review to determine whether any unauthorized, suspicious or potentially fraudulent activities have occurred. Prompt attention to such matters may help mitigate potential financial operational, reputational or regulatory risks."</p><p>Upon opening the link, recipients are directed to a <a href="https://www.itpro.com/security/proton-is-launching-its-own-private-alternative-to-google-workspace-and-microsoft-365">Proton </a>Drive-hosted file that delivers a ransomware payload hidden within multiple archive layers. Once executed, researchers said the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>seeks to encrypt files across available drives and presents victims with a ransom message.</p><p>The campaign is targeting organizations across multiple industries, including food and agriculture, legal services, pharmaceuticals, media, technology, and finance.</p><p>The ransomware is relatively simple, according to Bitdefender researchers. The code contains hardcoded values, including the password used during encryption and decryption, and lacks many of the features typically associated with large <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>operations.</p><p>Interestingly, victims are instructed to contact the attackers through a Tox chat channel to negotiate a ransom, rather than through the more usual dedicated negotiation portal or victim site.</p><p>This, researchers noted, is another indication that this is likely a custom-built operation, perhaps assembled using publicly available code and tools rather than the work of an established ransomware group.</p><h2 id="what-small-businesses-need-to-know">What small businesses need to know</h2><p>Javvad Malik, Lead CISO advisor at <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">KnowBe4</a>, said that impersonating Interpol – or law enforcement in general – is specifically designed to trigger a “rapid emotional response” and dupe victims into ignoring red flags. </p><p>"What is interesting about this campaign is that it targets small business,” he said. “These are often understaffed and have no security or even IT expertise on hand, so it's not difficult to see why people would easily fall victim to these kinds of attacks."</p><p>Bitdefender has warned small businesses to be on the alert, urging them to verify all unsolicited correspondence by reaching out through official channels to confirm whether the communication is legitimate.</p><p>"One of the biggest red flags in this campaign is the delivery method itself," researchers said. "While the attackers impersonate Interpol, legitimate law enforcement agencies don't send unsolicited emails containing Proton Drive links to password-protected files and ask organizations to review alleged evidence of wrongdoing."</p><p>They should treat password-protected archives with caution, especially when the password is included in the email. Showing file extensions on Windows devices will make it easier to spot executables masquerading as videos or documents, and <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">multi-factor authentication (MFA)</a> should be used wherever possible.</p><p>Elsewhere, the company urged small businesses to ensure staff are trained to help spot tell-tale signs that communications are fraudulent. </p><p>"Small businesses are often viewed as easier targets than large enterprises," the researchers warned.</p><p>"Many operate without dedicated IT teams or cybersecurity staff. Security responsibilities are often shared among employees who already wear multiple hats, and limited budgets can make it difficult to invest in advanced security measures or ongoing training."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Opera browser thinks it has the solution to stopping ClickFix malware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/opera-browser-thinks-it-has-the-solution-to-stopping-clickfix-malware-attacks</link>
                                                                            <description>
                            <![CDATA[ The browser company is targeting a growing source of malicious links with its new Paste Protect feature ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zmogiYJmaz796YaNZebPmc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UDuhGC7MnuUYb7yMAeLjkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Jul 2026 13:53:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UDuhGC7MnuUYb7yMAeLjkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Opera browser logo and branding pictured on a smartphone screen placed on desk with pencils and art utensils.]]></media:description>                                                            <media:text><![CDATA[Opera browser logo and branding pictured on a smartphone screen placed on desk with pencils and art utensils.]]></media:text>
                                <media:title type="plain"><![CDATA[Opera browser logo and branding pictured on a smartphone screen placed on desk with pencils and art utensils.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UDuhGC7MnuUYb7yMAeLjkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Opera has started to block ClickFix-style attacks in the browser by blocking malicious clipboard copy-and-paste techniques. </p><p>ClickFix pairs social engineering with a malicious code injection attack by fooling users into clicking a link, such as a fake CAPTCHA or similar familiar popup, starting a string of events that could compromise the device. </p><p>Opera cited a report by <a href="https://www.huntress.com/resources/2026-cyber-threat-report" target="_blank"><u>Huntress</u></a> showing that ClickFix-style social engineering attacks make up 53% of all malware loader activity worldwide, underlining the scale of the threats faced by web users.</p><p>Last year, <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers"><u>Proofpoint warned</u></a> that state-sponsored hackers were turning to ClickFix techniques to target governments in particular. </p><p>To help battle that, Opera has introduced Paste Protect, a browser-native feature designed to prevent such attacks by stopping malicious code from being copied onto the clipboard, and notifying users when that happens. </p><p>"This means that if you’re accessing a website that is trying to copy something potentially harmful into your clipboard (or luring you into doing so), Opera will detect it, prevent it, and let you know about it," the company said in a <a href="https://blogs.opera.com/news/2026/07/opera-introduces-paste-protect-to-keep-you-safe-from-clipboard-attacks/" target="_blank"><u>blog post</u></a>. </p><p>Opera said it is the first major browser to add this level of protection, though Microsoft Defender does notify users of ClickFix landing pages and there are extensions that do a similar job. </p><p>"Opera had already been protecting users from paste hijacking for half a decade — it made sense to expand that protection to address one of the most increasingly serious online threats," said Mohamed Salah, Senior Director of Product at Opera. </p><p>"Paste Protect gives your browser a robust early warning system that can alert less experienced users while still enabling more control for more tech-savvy users or developers."</p><h2 id="the-rise-of-clickfix">The rise of ClickFix</h2><p>ClickFix attacks work by fooling a user into clicking a box on a malicious popup, often by pretending to be a CAPTCHA or a "verify you're a human" box. That lets the dodgy website copy to the clipboard and open another window. </p><p>"When this prompt appears, the website has already 'copied' something to your clipboard, and now it instructs you to open the Windows Run dialog box (Win+R), then use 'Ctrl + V' to paste the malicious code, and then click 'OK'," the blog post noted. "This would execute the code and compromise your device, and the data on it."</p><p>Instead, Opera's Paste Protect examines the content being copied, and if concerned, blocks the code from being copied to the clipboard and notifies the user. They can then close the window without interacting. </p><p> "<a href="https://www.itpro.com/security/cyber-attacks/malicious-urls-overtake-email-attachments-as-the-biggest-malware-threat">ClickFix attacks</a> succeed because they turn the user into the weapon," said Pawel Kurzelewski, Head of Security at Opera.</p><p>"The clipboard is the last point before a malicious command is run, so that's where we built our defense. With Paste Protect, we're stopping these attacks at the exact moment they would normally succeed."</p><p>The Paste Protect system does mean that the Opera browser is scanning everything copied to the clipboard for potential threats or harmful commands. When those are spotted, the system displays a red warning icon. </p><p>Websites can be individually approved to circumvent these warnings if safe, and users can still check to see if a mistake has been made. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Hacking groups have the transport network firmly in their sights’: Network Rail is battling a torrent of cyber threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hacking-groups-have-the-transport-network-firmly-in-their-sights-network-rail-is-battling-a-torrent-of-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ FoI requests have revealed that the rail operator is under increasing attack, as cyber criminals set their sights on the transport sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RoW86jKhaGNwz8fh2EZQkX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 29 Jun 2026 11:26:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:description>                                                            <media:text><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:text>
                                <media:title type="plain"><![CDATA[Network Rail logo and branding pictured on a glass partition at a waiting room in London Euston railway station.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rUvp25YMvPTLYowbCM5HSC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Network Rail is fighting off millions of cyber attacks every month, according to new research, as experts warn of a rising tide of threats facing public services. </p><p>Freedom of information (FoI) requests show the organization blocked over 7.1 million malicious emails between December 2025 and March this year.  </p><p>Of the 7,129,314 email attacks blocked by Network Rail, 331,352 were phishing emails, 1,412 were <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>-laden emails, 2,066,392 were spam emails, and 4,730,158 were edge blocked emails. </p><p>This all adds up to an average of more than 800,000 attacks per day, including around 37,000 <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attempts.</p><p>“With so many people in the UK depending on public transport for their daily lives, a successful cyber attack could cause significant disruption, such as potentially stopping people from getting to work," warned Simon Edwards, CEO of SE Labs. </p><p>"Therefore, it’s vital that our public sector organizations have a dedicated cyber strategy put in place and ensure rigorous testing to identify any security holes and keep hackers at bay.”</p><p>Just last week, two members of the hacking group known as Scattered Spider pleaded guilty over their <a href="https://www.itpro.com/security/cyber-attacks/duo-accused-of-role-in-tfl-cyber-attack-plead-guilty-after-lengthy-highly-complex-and-painstaking-investigation">involvement in an attack on Transport for London (TfL) systems</a>. </p><p>The attack forced all 28,000 employees to attend a TfL office for a password reset and led to a reported £29 million in losses and recovery costs.</p><p>"As we've seen from the recent Scattered Spider convictions, hacking groups have the transport network firmly in their sights. A single successful cyber attack on the rail network could drive Britain to a halt, operationally and economically," said Graeme Stewart, head of public sector at Check Point. </p><p>"The transport network is also a treasure trove of personal and financial data, something unscrupulous criminals are eager to get their hands on. That’s why it's vital that our roads, rail and aviation systems are fully protected with the latest cyber defenses to keep hackers locked out."</p><h2 id="what-happened-with-the-network-rail-cyber-attack">What happened with the Network Rail cyber attack?</h2><p>In 2024, Network Rail suffered a <a href="https://www.itpro.com/security/network-rail-confirms-cyber-attack-on-wi-fi-systems-at-uk-train-stations"><u>cyber attack</u></a> on its WiFi systems that saw commuters who logged in at affected stations receive information pertaining to terrorist attacks in Europe, as well as a message stating “we love you Europe”. </p><p>The attack is believed to have taken place through a third-party service provider, Telent, which managed Network Rail's WiFi services.</p><p>More recently, train operator LNER said a <a href="https://www.itpro.com/security/cyber-attacks/lner-warns-customers-to-remain-vigilant-after-personal-data-exposed-in-cyber-attack"><u>cyber attack</u></a> had led to unauthorized access to files managed by an unnamed third-party supplier.</p><p>Travel networks, particularly rail services, are among the top targets for cyber criminals and state-sponsored groups due to the critical role they play in the British economy, according to research conducted last year. </p><p>The UK's Department for Science, Innovation and Technology (DSIT) released a <a href="https://assets.publishing.service.gov.uk/media/69144f259d50fc2fe816163a/Economic_impact_of_a_systemic_cyber_incident_rail_sector_scenario.pdf" target="_blank"><u>report</u></a> from KPMG that concluded a major attack on the rail network could cost £1.8 billion for a one-week period of disruption.</p><p>The direct financial cost to Network Rail would, it concluded, cost around £123 million, with the cost to passengers due to delays adding up to about £281.3 million. </p><p>Notably, the impact on Gross Value Added (GVA) could be as much as £1.397 billion, representing approximately 2.8% of the UK’s weekly GDP and 0.05% of annual GDP.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘This operation marked a shift in strategy’: Three notorious malware networks have been taken down using RICO legislation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/this-operation-marked-a-shift-in-strategy-three-notorious-malware-networks-have-been-taken-down-using-rico-legislation</link>
                                                                            <description>
                            <![CDATA[ The action involved the use of US racketeering laws to treat two malware families as part of a single conspiracy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QqZTCnjPCtnP5zoZTXKiUS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 Jun 2026 09:38:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:description>                                                            <media:text><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:text>
                                <media:title type="plain"><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Europol has taken down the criminal networks behind the SocGholish, Amadey, and StealC malware strains as part of an operation involving Microsoft and a host of security firms. </p><p>The latest move in <a href="https://www.itpro.com/security/ransomware/its-been-a-bad-week-for-ransomware-operators">Operation Endgame</a>, the action saw 326 servers and 142 domains neutralized, as well as 27 million compromised data sets recovered. More than €41 million in criminal crypto assets were seized, the agency revealed.</p><p>"By taking down these tools simultaneously, the collaboration between law enforcement and private parties has increased friction for cyber criminals, making it harder for attacks to succeed, spread, or recover," said Europol.</p><p>"This operation marked a shift in strategy: instead of focusing solely on individual threats, Europol, law enforcement and judicial authorities, as well as private industry partners disrupted the entire chain that allows cyber attacks to scale."</p><p>In the first two weeks of May alone, more than 140,000 PCs globally were infected with one of the three cybercrime as a service malware strains, which were used as a tool for the initial infection of targeted systems.  </p><p>SocGholish, a so-called dropper/loader, helped criminals gain access to computer systems by distributing fake browser updates via compromised websites. This works by hacking websites built with WordPress and infecting them with malware for digital extortion.</p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>strain is linked to the Russian cyber criminal group <a href="https://www.itpro.com/security/cyber-crime/nca-sanctions-members-of-evil-corp-cybercrime-gang">Evil Corp</a>, the group behind the Zeus and Dridex malware and associated with several large‑scale ransomware and money laundering operations. </p><p>StealC, a stealer with dropper function, was spread in a variety of ways, and is designed to extract sensitive information such as passwords, stored access data, and digital identities from compromised computers for data trading and fraudulent use.</p><p>Meanwhile, the Amadey dropper/loader is spread mostly through phishing campaigns, introducing extra malware into compromised systems and retrieving sensitive data.</p><h2 id="rico-legislation-used-in-amadey-stealic-takedowns">RICO legislation used in Amadey, StealIC takedowns</h2><p>Amadey and StealC were targeted by Microsoft’s Digital Crimes Unit (DCU) as a pair, thanks to their interconnected roles – although they were developed by separate cyber criminals, they relied on the same infrastructure. </p><p>Both were shut down through a mix of court orders, domain seizures, registrations, and provider notifications. </p><p>This action involved a broader use of the Racketeer Influenced and Corrupt Organizations Act (RICO), a US law designed to target organized crime.</p><p>Steven Masada, assistant general counsel in Microsoft’s Digital Crimes Unit, said investigators relied on <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a>, particularly <a href="https://www.itpro.com/technology/artificial-intelligence/microsoft-copilot-review-ai-baked-into-your-apps">Copilot</a>, as part of the operation, using the technology to analyze malware strains.  </p><p>"That helped surface key details, uncover hidden data, and test findings in a fraction of the time, turning what would have taken hours or days into minutes and enabling the team to spot connections faster," he said.</p><p>"Those insights allowed the legal team to treat both malware families as part of a single conspiracy. Instead of going after each tool separately, as we have done in the past, we used RICO to charge multiple complicit enablers involved across the operation."</p><p>The action against SocGholis involved cleaning infected WordPress sites and notifying victims, urging them to update their platforms and strengthen login credentials.</p><p>WordPress users are being encouraged to change their login credentials, enable multi‑factor authentication, delete any unknown additional WordPress accounts and keep their WordPress site up to date in the future.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Developers urged to remain vigilant amid continued Miasma malware risks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/miasma-malware-developer-warning-github-compromise</link>
                                                                            <description>
                            <![CDATA[ The Miasma malware package uses legitimate OIDC tokens, making it indistinguishable from routine code updates ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sEQsB4i9tWQiomWw9SBdR9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JWEkqhzHMUwvx8eF9JTxjM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Jun 2026 10:38:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JWEkqhzHMUwvx8eF9JTxjM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware concept image showing laptop with computer virus symbol on screen, with green tentacles emerging from screen and enveloping device.]]></media:description>                                                            <media:text><![CDATA[Malware concept image showing laptop with computer virus symbol on screen, with green tentacles emerging from screen and enveloping device.]]></media:text>
                                <media:title type="plain"><![CDATA[Malware concept image showing laptop with computer virus symbol on screen, with green tentacles emerging from screen and enveloping device.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JWEkqhzHMUwvx8eF9JTxjM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security firms are warning that self-replicating malware known as Miasma has spread to 73 Microsoft GitHub repos across environments, including Microsoft Azure and Durable Task.</p><p>Miasma is a new and improved variant of Mini <a href="https://www.itpro.com/security/cyber-attacks/shai-hulud-malware-is-back-with-a-vengeance-and-hit-more-than-19-000-github-repositories-so-far-heres-what-developers-need-to-know">Shai-Hulud</a> from the threat group TeamPCP, and, according to Cloudsmith, initially struck the @redhat-cloud-services npm namespace by compromising a Red Hat employee’s GitHub account. </p><p>"By pushing unreviewed orphan commits to internal repos, the threat actors injected a minimal workflow that requested GitHub’s OIDC tokens. This registry poisoning workflow in early June executed an obfuscated payload that published 32 malicious package versions to the npm registry," <a href="https://cloudsmith.com/blog/miasma-worms-path-of-destruction" target="_blank"><u>said the firm</u></a>. </p><p>"Crucially, because it used legitimate OIDC tokens, the malicious releases carried valid SLSA provenance attestations. To standard registry scanners, the malicious updates were entirely indistinguishable from legitimate, routine code updates."</p><p>It's not known how many times the affected tools have been downloaded, but Microsoft said it's notified a 'small number' of customers who may have done so.</p><h2 id="under-the-hood-of-miasma-malware">Under the hood of Miasma malware</h2><p>What's special about the Miasma worm, said Cloudsmith, is that it doesn't exploit any software vulnerability in <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>or npm, but instead exploits the underlying trust model of the modern engineering ecosystem.</p><p>Compromised developer credentials led to a legitimate GitHub OIDC token being requested, followed by a malicious build being published with valid SLSA provenance. </p><p>This ultimately led to conventional scanners seeing it as a routine trusted update. </p><p>On top of this, because Miasma generates a uniquely encrypted payload for each individual infection, traditional hash-based IOCs are functionally useless for broad detection, as the file signature changes with every single package version.</p><p>"While previous iterations of the Mini Shai-Hulud malware have focused purely on local secret scraping, the Miasma worm appears to have advanced data collectors specifically engineered for cloud identities in GCP and Azure," the researchers said. </p><p>"It attempts to harvest every cloud identity the infected developer machine and <a href="https://www.itpro.com/business/digital-transformation/cicd-comes-into-focus-as-enterprises-ramp-up-application-modernization-efforts">CI/CD </a>runners have access to, proving a clear intent from the threat actors to leverage access away from the codebase and directly into live cloud environments."</p><h2 id="how-to-protect-your-organization">How to protect your organization</h2><p>If your company operates within the Azure or Red Hat ecosystems, Cloudsmith said to assume secrets exposure and rotate. </p><p>Miasma specifically hunts for developer credentials, meaning that everything on a compromised machine or CI/CD pipeline may have been been leaked.</p><p>"Developers are high-value targets because they sit at the intersection of source code, cloud infrastructure, AI platforms and production systems. Compromising a trusted package or development workflow can give attackers access that is far harder to obtain through traditional intrusion methods," commented Ilkka Turunen, field CTO at Sonatype.</p><p>With this incident having reached users of platforms such as Claude and Gemini, Turunen noted it shows how "interconnected modern software ecosystems have become" and should serve as a warning. </p><p>"An attack that begins with a seemingly insignificant open source package can quickly cascade across organizations, platforms and users," Turunen commented. "Organizations need to treat the software supply chain as part of their security perimeter. The attackers already do.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Claude users beware, hackers are using a fake website to dupe developers and deliver malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/claude-users-beware-hackers-are-using-a-fake-website-to-dupe-developers-and-deliver-malware</link>
                                                                            <description>
                            <![CDATA[ 'Beagle' is deployed through a Dynamic Link Library (DLL) sideloading chain, and gives attackers remote access to the system ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QFnS23ZWZmYxkq5Kk2FrWd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 May 2026 09:32:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:description>                                                            <media:text><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:text>
                                <media:title type="plain"><![CDATA[Red warning symbol imposed over computer code denoting a data security compromise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/P5BaAXwkDNyHNyRDcZNx5E-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A fake Claude AI website is spreading a trojanized 'Claude‑Pro' Windows installer that secretly distributes a newly-identified backdoor.</p><p>The domain mimics the official site for <a href="https://www.itpro.com/software/development/claude-code-flaws-left-ai-tool-wide-open-to-hackers-heres-what-developers-need-to-know">Anthropic’s Claude AI tool</a>, and visitors who download the ZIP archive are sent a copy of Claude that appears to install and runs as expected. </p><p>However, <a href="https://www.malwarebytes.com/blog/scams/2026/04/fake-claude-site-installs-malware-that-gives-attackers-access-to-your-computer" target="_blank"><u>researchers at Malwarebytes</u></a> found it deploys a PlugX-like <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>chain, dubbed Beagle, that gives attackers remote access to the system.</p><p>The ZIP contains an MSI installer that installs to a path designed to mimic a legitimate Anthropic installation, complete with a reference to Squirrel, the update framework that real Electron-based applications like Claude use. </p><p>A tell-tale giveaway for developers is that this contains a misspelling: ‘Cluade’.</p><p>While the legitimate application runs in the foreground, the VBScript quietly copies three files from the SquirrelTemp directory into the Windows Startup folder.</p><p>"This is a textbook DLL sideloading attack, a technique catalogued by MITRE as T1574.002. NOVUpdate.exe is a legitimately signed G DATA antivirus updater. When it executes, it attempts to load a library called avk.dll from its own directory," researchers explained.. </p><p>"Normally, this would be a genuine G DATA component, but here the attacker has substituted a malicious version. Signed sideloading hosts like this can complicate detection because the parent executable may appear benign to endpoint security tools. </p><p>Victims are kept in the dark, because after deploying the payload files, the VBScript writes a small batch file called <em>~del.vbs.bat</em> that waits two seconds, then deletes both the original <a href="https://www.itpro.com/software/development/farewell-vbscript-microsoft-confirms-plans-to-begin-phasing-out-the-programming-language-later-this-year">VBScript </a>and the batch file itself. </p><p>"This means the dropper is gone from disk by the time a user or analyst goes looking for it. The only artifacts that persist are the sideloading files in the Startup folder and the running NOVUpdate.exe process," Malwarebytes said. </p><p>"The script also wraps the entire malicious payload section in an On Error Resume Next statement, silently swallowing any errors so that failures in the deployment do not produce visible error dialogs that might alert the victim."</p><h2 id="what-is-dll-sideloading">What is DLL sideloading?</h2><p>DLL sideloading is a technique favored by PlugX, a malware family that Sophos has been tracking for 14 years.</p><p>As the firm <a href="https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor" target="_blank"><u>points out</u></a>, PlugX has multiple variants and has been associated with several threat actor groups, meaning that attribution isn't clear-cut. </p><p>On top of this, ShadowPad, another backdoor employing DLL sideloading, has a number of code overlaps with PlugX, to the extent that it could be considered an evolution of it.</p><p>"Most of the techniques described here are relatively well known and have been seen before, from spoofing a legitimate installer website to side loading using a signed executable. Interestingly enough what is unusual is that it also installs a working copy of Claude which is rather large," said Max Gannon, cyber intelligence team manager at Cofense.</p><p>"The installation and usage of a program that is resource intensive can also help to disguise other ongoing background activity. The use of a legitimate program, cleanup utilities, running in memory, and persistence mechanisms all indicate that the threat actors distributing this malware intend it for long term persistence and use."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ North Korean hackers are duping freelance developers with fake interviews to steal cryptocurrency and deliver malware — Sophos warns the 'Nickel Alley' group is using LinkedIn, Upwork, and Fiverr to target victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/north-korean-hackers-are-duping-freelance-developers-with-fake-interviews-to-steal-cryptocurrency-and-deliver-malware-sophos-warns-the-nickel-alley-group-is-using-linkedin-upwork-and-fiverr-to-target-victims</link>
                                                                            <description>
                            <![CDATA[ A fake interview process uses coding tests and repo downloads to deliver malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VLS4GwTGb87a7DRvRmQrAm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Apr 2026 11:06:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">North Korean hackers</a> are targeting software developers in a new malware campaign that uses a fake interview process to steal cryptocurrency.</p><p>The campaign targets developers, especially those in the finance and technology industries, with profiles on freelance websites such as Upwork or Fiverr. It offers well-paid job opportunities and targets specific, high-value individuals.</p><p>It uses typosquatting or compromised legitimate npm repositories that victims are persuaded to inadvertently download and execute. </p><p>Researchers at the Sophos Counter Threat Unit have attributed the campaign to Nickel Alley, a threat group operating on behalf of the North Korean government. </p><p>"The group notoriously targets professionals in the technology sector by advertising fake job opportunities, deceiving prospective candidates through a fake job interview process, and ultimately delivering malware," the company said in an <a href="https://www.sophos.com/en-us/blog/nickel-alley-strategy-fake-it-til-you-make-it" target="_blank"><u>advisory</u></a>.</p><p>As part of its attacks, Nickel Alley often creates a fake LinkedIn company page to build credibility, with a coordinating <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>account for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>delivery. </p><p>The website homepage is generic and advertises 'tech talent' and managed service solutions. However, different domains are included on the LinkedIn company page and the GitHub account – which researchers noted shows inconsistency and lack of attention to detail. </p><h2 id="nickel-alley-ramping-up-operations">Nickel Alley ramping up operations</h2><p>The advisory from Sophos comes after a June 2025 X post warned of a campaign involving targeted emails promoting job opportunities at the fake Astra Byte Sync company. </p><p>The threat actors hadn't actually built the website at the time the emails were sent, meaning that the site simply displayed the hosting provider’s default page. </p><p>Over the last year, the group has used the popular <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix </a>tactic to deliver PyLangGhost RAT malware via fake job skills assessment tasks. </p><p>This involved the attacker-controlled web interface presenting an error informing the victim that they must run a command locally to fix the issue – a command that instead initiated a series of actions leading to PyLangGhost RAT. </p><p>It previously used a GoLang-based version known as GoLangGhost RAT. </p><p>Meanwhile, in October, Sophos analysts uncovered a targeted attack where the threat actors convinced a victim to download, or clone, the content of a GitHub repository and execute the code locally using the 'npm install' and 'npm start' commands. </p><p>The GitHub account masquerades as a software development company specializing in full stack web development and blockchain solutions, and contains links to an 'official' company website and a <a href="https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks">fake LinkedIn company page</a>. </p><p>While the main aim of these attacks appears to be cryptocurrency theft, Sophos said the threat group has also made it clear that it plans to use initial access for further supply chain compromise or corporate espionage. </p><p>"Additionally, the threat group has strategically selected follow-on payloads based on profiling victims’ system. Software developers, especially those in the finance and technology industries, are at elevated risk due to Nickel Alley’s targeting profile," Sophos warned.</p><p>"Organizations should monitor command execution and network traffic that spawns from Node.js processes, as it may indicate malware retrieval. As a general security practice, organizations should encourage employees to report suspicious unsolicited social media or email-based recruitment contact."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The build pipeline is becoming the new frontline’: Axios npm compromise highlights growing software supply chain risks, experts warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-build-pipeline-is-becoming-the-new-frontline-axios-npm-compromise-highlights-growing-software-supply-chain-risks-experts-warn</link>
                                                                            <description>
                            <![CDATA[ Cyber criminals exploited a hijacked maintainer account to compromise one of the world's most widely used JavaScript libraries ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FtT83GNxmPjbmsmBPsDEnS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Apr 2026 10:32:11 +0000</pubDate>                                                                                                                                <updated>Wed, 01 Apr 2026 14:13:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing digital data storage modules with padlock symbols in a storage environment.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4XZYfjMuoUwrLG8MTcaQBi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Attackers have compromised the npm account of Axios and published malicious versions to spread <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">remote access trojans (RATs)</a> to millions of developers.</p><p>Axios is a JavaScript HTTP client and is one of the most popular packages on npm, with more than 100 million weekly downloads. It manages requests between clients, such as browsers or Node.js apps, and servers.</p><p>On Monday, two malicious updates, <em>axios@1.14.1</em> and <em>axios@0.30.3</em>, were published, apparently through the compromise of the npm account of axios’ primary maintainer Jason Saayman. </p><p>The updates were identified almost immediately by several security firms and remained live for around two or three hours. The malicious versions introduce a dependency that executes during installation and deploys a cross‑platform remote access trojan (RAT) targeting macOS, Windows, and <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Linux</a>. </p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>communicates with a command and control (C2) server to retrieve platform‑specific second‑stage payloads, researchers noted. After execution, it deletes itself and replaces its own package.json with a clean version to evade forensic detection.</p><p>According to StepSecurity, the malicious dependency was staged 18 hours in advance, with separate payloads pre-built for all three operating systems. Both release branches were poisoned within 39 minutes of each other.</p><p>StepSecurity added that within two seconds of npm install, the malware was already calling home to the attacker's server before npm had even finished resolving dependencies -– making this one of the most operationally-sophisticated supply chain attacks ever documented against a top-10 npm package.</p><p>Because there were no git tags, any manual audit of the <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>repo would have failed to show anything was wrong.</p><h2 id="axios-npm-incident-highlights-supply-chain-dangers">Axios npm incident highlights supply chain dangers</h2><p>Ilkka Turunen, field CTO at Sonatype, said the latest npm-related incident highlights the growing dangers faced by developers globally, with threat actors ramping up attacks. </p><p>“Attackers have figured out they don’t need to compromise the code people trust if they can compromise the trust around it," Turunen said. </p><p>"In this case, the malicious capability was introduced through a staged dependency and designed to erase its own tracks, which made the attack harder to spot and slower to understand. That’s not just malware — it shows a more deliberate and mature playbook."</p><p>Anyone who installed either version before the takedown should assume their system is compromised and is advised to immediately quarantine hosts, implement their full incident response playbook, and rotate all exposed secrets. </p><p>It's not known who is responsible for the compromise, although many researchers are throwing suspicion on a North Korean actor known as UNC1069 that focuses on stealing cryptocurrency via centralized exchanges (CEX), software developers at financial institutions, tech firms, and venture capital funds. </p><p>The supply chain attack marks the latest in a string of attempts to exploit trust in <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> ecosystems, according to Upwind security researcher Avital Harel.</p><p>"The build pipeline is becoming the new frontline. Attackers know that if they can compromise the systems that build and distribute software, they can inherit trust at scale," Harel commented. </p><p>"Organizations should be looking much more closely at CI/CD systems, package dependencies, and developer environments, because that’s increasingly where attackers are placing their bets." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'It's destructive, not ransomware': Security experts weigh in on motivation behind Stryker cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ The attack on medical tech company Stryker has severely impacted operations globally ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uAEPy85heifUdKbTPUHP9Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/So4cFobEWd4kjqH4MbFRyA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Mar 2026 12:37:46 +0000</pubDate>                                                                                                                                <updated>Thu, 12 Mar 2026 12:38:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/So4cFobEWd4kjqH4MbFRyA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of medical technology company Stryker pictured on a building facade in Warsaw, Poland.]]></media:description>                                                            <media:text><![CDATA[Logo of medical technology company Stryker pictured on a building facade in Warsaw, Poland.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of medical technology company Stryker pictured on a building facade in Warsaw, Poland.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/So4cFobEWd4kjqH4MbFRyA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have warned that the cyber attack on Stryker signals a step change in politically-motivated attacks, with a particular focus on destruction rather than extortion. </p><p>Operations at the medical technology firm have been severely impacted in a cyber attack claimed by Iranian-linked threat group, Handala. The group claims to have wiped thousands of systems across the company’s global operations and stolen around 50 terabytes of data. </p><p>“In this operation, over 200,000 systems, servers, and mobile devices have been wiped and 50 terabytes of critical data have been extracted,” the group claimed in a statement online. </p><p>Stryker develops a range of products, including surgical equipment, neurotechnology, and orthopedic implants, with offices in 79 countries and over 50,000 employees worldwide. </p><p>The impact of the attack has been felt globally, with reports suggesting operations in Ireland have been severely disrupted. </p><p>Stryker employs around 4,000 employees in Cork, which the company <a href="https://www.stryker.com/ie/en/about/our-locations/cork.html" target="_blank"><u>describes </u></a>as its “biggest innovation and manufacturing hub outside the US”.</p><p>"Nobody can work,” a source told the <a href="https://www.irishmirror.ie/news/irish-news/stryker-cyber-attack-thousands-irish-36850017" target="_blank"><u><em>Irish Mirror</em></u></a>. “The entire company has been brought to a standstill”</p><h2 id="stryker-confirms-attack">Stryker confirms attack</h2><p>Stryker has <a href="https://www.linkedin.com/posts/stryker_a-message-to-our-customers-stryker-is-experiencing-activity-7437540918695706625-ZeNo/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAALaFlIB3G0zftVnXqlA-AAtC99kdJhiuxs" target="_blank"><u>confirmed </u></a>it is dealing with “global network disruption” across its Microsoft environment, which is believed to be the entry point for the group. </p><p>One employee told <a href="https://www.bleepingcomputer.com/news/security/medtech-giant-stryker-offline-after-iran-linked-wiper-malware-attack/" target="_blank"><u><em>BleepingComputer </em></u></a>that staff have been ordered to remove work-related applications from personal devices, in particular the company portal for mobile device management software Microsoft Intune and Microsoft Teams. </p><p>Targeting of Microsoft products is a common tactic for Handala, which has been active since at least December 2023. </p><p>A 2024 threat intelligence report from Cisco Talos and Splunk’s Threat Research Team specifically highlighted the group’s activities on this front, typically using “wiper” <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> to destroy company data. </p><p>“The Handala Hacking Team is notable for employing a wide range of sophisticated tactics and techniques, including data theft, phishing extortion, website defacement, and destructive attacks leveraging custom wiper malware that targets Windows and Linux environments,” the duo said in a <a href="https://www.splunk.com/en_us/blog/security/handalas-wiper-threat-analysis-and-detections.html" target="_blank"><u>blog post</u></a>. </p><h2 id="the-target-matters">“The target matters”</h2><p>Stryker noted in its statement that there’s “no indication of ransomware” involved in the attack. However, this aspect of the attack provides an insight into the underlying motivations, according to Huntress <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>Chris Henderson. </p><p>In this instance, the attack is “destructive, not <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>” and is a politically-motivated attack aimed solely at causing widespread disruption. </p><p>“The target matters. Stryker manufactures critical medical devices used in operating rooms and ICUs worldwide,” Henderson said. </p><p>“When a supplier of this scale goes offline, it doesn't just impact their employees; it creates ripple effects across hospitals, surgical centers, and healthcare providers who depend on their equipment and support infrastructure.”</p><p>Skip Sorrells, Field CTO-CISO at Claroty, echoed Henderson’s comments, noting that even prior to the Iran conflict hacktivist activities have been ramping up globally.</p><p>Security agencies including <a href="https://www.itpro.com/security/what-is-cisa">CISA </a>and the UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> have issued repeated warnings over the rise of hacktivist groups over the last two years. </p><p>In particular, pro-Russian hacktivist groups identified by the NCSC were found to be <a href="https://www.itpro.com/security/cyber-attacks/ncsc-names-and-shames-pro-russia-hacktivist-group-amid-escalating-ddos-attacks-on-uk-public-services">targeting local government agencies and critical infrastructure</a>. Critical sectors like healthcare are now firmly in the crosshairs, according to Sorrells. </p><p>“Attacks like this unfortunately aren’t surprising,” he said. “Even before the latest geopolitical tensions, hacktivist activity targeting healthcare and other critical infrastructure had been steadily increasing, and that trend makes organizations like medical device manufacturers and hospitals more likely to be caught in the crossfire.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of Asus routers are being used to fuel a massive cyber crime spree ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/thousands-of-asus-routers-are-being-used-to-fuel-a-massive-cyber-crime-spree</link>
                                                                            <description>
                            <![CDATA[ Black Lotus Labs has spotted a massive botnet of Asus routers built by malware that uses a common peer networking tool ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eKJRcjhiqzpr5rwsNrbEFS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FqwdpUKc89SZqpjHUQRg63-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Mar 2026 11:10:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FqwdpUKc89SZqpjHUQRg63-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Earth with a global botnet showing red and blue-colored lines spreading out across the planet.]]></media:description>                                                            <media:text><![CDATA[Earth with a global botnet showing red and blue-colored lines spreading out across the planet.]]></media:text>
                                <media:title type="plain"><![CDATA[Earth with a global botnet showing red and blue-colored lines spreading out across the planet.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FqwdpUKc89SZqpjHUQRg63-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/malware/28076/what-is-malware">Malware</a> targeting Asus routers has built a <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnet </a>of 14,000 devices to spread malicious traffic, according to researchers at Lumen's Black Lotus Labs. </p><p>Dubbed "KadNap", the malware was first spotted in August 2025, with 60% of the infected devices located in the US, with others spotted in the UK, across Europe, and Australia, among others. Alongside Asus routers, the malware is also targeting edge networking devices. </p><p>KadNap slips by existing network protections using the Kademlia distributed hash table (DHT) designed for peer-to-peer networks like BitTorrent to hide its own originating <a href="https://www.itpro.com/virtual-private-network-vpn/30351/how-do-you-hide-an-ip-address">IP address</a>. </p><p>"Infected devices use the DHT protocol to locate and connect with a command-and-control (C2) server, while defenders cannot easily find and add those C2s to threat lists," the researchers at Black Lotus Labs said in a <a href="https://blog.lumen.com/silence-of-the-hops-the-kadnap-botnet/" target="_blank"><u>blog post</u></a>. </p><p>“In short, the innovative use of the DHT protocol allows the malware to establish robust communication channels that are difficult to disrupt by hiding in the noise of legitimate peer-to-peer traffic."</p><p>Access to that network is then sold via a proxy service called "Doppelganger" to be used for criminal activity, researchers added. </p><p>"KadNap’s bots are sold through Doppelganger, a service whose users leverage these hijacked devices for a range of malicious purposes, including brute-force attacks and highly targeted exploitation campaigns," researchers said. </p><p>"As a result, every IP address associated with this botnet represents a significant, persistent risk to organizations and individuals alike."</p><p><em>ITPro </em>contacted Asus for comment, but did not receive a response by time of publication.</p><h2 id="spotting-kadnap">Spotting KadNap</h2><p>This particular botnet-building malware was spotted last summer by a Lumen algorithm that searches out dodgy networks as they pop up, with the company noticing 10,000 Asus devices all communicating with one set of servers. </p><p>Once the malicious file was on the router or other IoT or edge hardware, it would download a shell script and start the process of adding the kit to the botnet. </p><p>To hide, KadNap makes use of a legitimate distributed hash table known as Kademlia, which was designed to make it easier to find information across peers.</p><p>"To better understand this system, think of Kademlia like using a chain of friends to find someone’s phone number: each friend does not know the whole number but knows someone who can get you closer to the answer," the researchers explained. </p><p>"Passing your request along this chain, you quickly put together the whole phone number. Likewise, Kademlia nodes forward queries to others that are 'closer' to the target, enabling fast and efficient searches without knowing the whole network."</p><p>KadNap uses a custom version of the DHT to hide the IP address of the criminal's command and control server. That allows a newly infected router to find and connect to previously infected nodes to share additional payloads and build a bot network. </p><p>"The KadNap botnet stands out among others that support anonymous proxies in its use of a peer-to-peer network for decentralized control," the researchers said. "Their intention is clear: avoid detection and make it difficult for defenders to protect against."</p><h2 id="what-can-enterprises-do">What can enterprises do?</h2><p>Lumen said its own customers have been protected from these attacks since last August, and that it would share indicators of compromise (IoC) publicly so others could be protected as well. </p><p>Beyond that, the lab advised security professionals working on network defense to keep watch for attacks on weak credentials or suspicious logins, even if they seem to come from safe IP addresses. </p><p>Additional advice includes protecting cloud assets from communicating with bots and make use of Web Application Firewalls. </p><p>Regarding KadNap specifically, it's worth checking if devices aren't connecting to public BitTorrent trackers. </p><p>For users of small office or home office (SOHO) routers, Lumen advice includes:</p><ul><li>Ensuring routers are patched, updated, and rebooted regularly</li><li>Bolstering password security</li><li>Replacing outdated or unsupported devices</li></ul><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in life ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/the-rise-of-teen-hackers-makes-for-a-good-headline-but-cyber-crime-activities-peak-later-in-life</link>
                                                                            <description>
                            <![CDATA[ With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AixB4pKPDWgHro8HrA47Jg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Mar 2026 10:56:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While much emphasis has been placed on the <a href="https://www.itpro.com/security/channel-their-curiosity-into-something-meaningful-cyber-expert-warns-an-uptick-of-youth-hackers-should-be-a-wake-up-call-after-teens-charged-over-tfl-attack">rise of youth cyber crime</a> over the last two years, new research shows hacker activity peaks much later. </p><p>Orange Cyberdefense looked at the numbers and found that it's actually thirty- and forty-somethings that are the greatest threat.  </p><p>The company’s intelligence team <a href="https://www.orangecyberdefense.com/uk/security-navigator"><u>analyzed</u></a> 418 publicly announced law enforcement activities between 2021 and mid-2025 and found that offenders’ activities peaked between the ages of 35 and 44. This age group, they said, accounted for 37% of cyber crime cases.</p><p>Put together, the combined age groups of 25-to-44 make up well over half (58%) of analyzed cyber crime cases. </p><p>Only one-in-five (21%) incidents were the work of 18-to-24-year-olds. Despite the bad press they get in movies and the news, 12-to-17s were behind fewer than 5% of cases.</p><p>“The surge in cyber offences committed by teenagers in recent years may be creating a false impression of the age of today's cyber criminals," said Charl van der Walt, head of security research at Orange Cyberdefense. </p><p>"The sensationalist interpretation of cyber crime's youthfulness makes for a good headline, but these findings appear to tell a different story."</p><h2 id="differing-motives">Differing motives</h2><p>One big difference between the kids and their elders is the underlying motivation behind attacks, researchers noted. As you might expect, younger hackers are frequently experimenting while the older cohort is in it primarily for financial gain. </p><p>Among 18-24-year-olds, cyber criminal activity is highly diverse, though there's a focus on hacking (30%) in particular, followed by selling stolen data and <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS attacks</a> (10% each).</p><p>Things start to change among offenders aged between 25 and 34, who tend to focus on more profitable activities such as selling stolen data (21%), cyber extortion (14%) and <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>deployment (12%). </p><p>This trend continues among 35-to-44 year olds, where <a href="https://www.itpro.com/security/ransomware/369222/what-is-triple-extortion-ransomware">cyber extortion</a> (22%) is the crime of choice, followed by malware (19%) and <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber espionage</a> (13%), hacking (10%), and money laundering (7%). </p><p>"While younger, less experienced hackers engage in highly diverse – and often noticed and reported – actions, they may be less likely to engage in calculated, profit seeking activity," said van der Walt. </p><p>"Instead, cyber crime careers appear to peak much later into adulthood, accompanied by vastly more sophisticated and intentional techniques.”</p><p>Some of those teen-related activities are very high profile indeed. Late last year, for example, a 15-year-old was <a href="https://www.itpro.com/security/cyber-crime/15-year-old-revealed-as-key-player-in-scattered-lapsus-usd-hunters">outed by security researcher Brian Krebs</a> as a member of Scattered LAPSUS$ Hunters – the group responsible for the Jaguar Land Rover (JLR) and M&S cyber attacks.</p><p>Two teenagers, meanwhile, are set to face charges for the 2024 <a href="https://www.itpro.com/security/cyber-attacks/everything-we-know-about-the-tfl-cyber-attack-so-far"><u>hack of Transport for London</u></a> (TfL), while another pair have been <a href="https://www.itpro.com/security/teens-arrested-over-nursery-chain-kido-hack"><u>arrested</u></a> for the data breach of the Kido chain of children's nurseries.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DIY hackers are turning to ‘flat-pack’ malware components to speed up attacks and cut costs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/diy-hackers-are-turning-to-flat-pack-malware-components-to-speed-up-attacks-and-cut-costs</link>
                                                                            <description>
                            <![CDATA[ While these malware campaigns are very basic, researchers noted “they still work” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9micgTJB6ymCrHncsBFWMm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oo8cMGiY5DwjHYxKQ8VLsB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Mar 2026 09:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 03 Mar 2026 11:24:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oo8cMGiY5DwjHYxKQ8VLsB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware vector image showing alert symbol with exclamation mark and &#039;malware&#039; written underneath imposed over a digital interface.]]></media:description>                                                            <media:text><![CDATA[Malware vector image showing alert symbol with exclamation mark and &#039;malware&#039; written underneath imposed over a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Malware vector image showing alert symbol with exclamation mark and &#039;malware&#039; written underneath imposed over a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oo8cMGiY5DwjHYxKQ8VLsB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are using “modular <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>components” to create custom campaigns and speed up attacks, according to new research from HP. </p><p>Findings from HP Wolf Security's latest Threat Insights Report<em> </em>show hackers are combining off-the-shelf malware components, usually purchased via cyber crime forums, to wage attacks against enterprises globally. </p><p>Researchers at the firm noted that while early-stage lures and final payloads typically change, attackers are “reusing the same intermediate scripts and installers”. </p><p>This means that threat actors are able to build, customize, and scale campaigns with little effort and at a rapid pace – and it’s a trend that’s gaining traction. HP said it has observed multiple unrelated groups using the same basic building blocks in several campaigns. </p><p>The emergence of this ‘flat-pack’ malware trend aligns closely with the increased use of AI among threat actors, according to HP. Findings from the Threat Insights Report show attackers are also using AI to automate malware delivery as part of a focus on ‘<a href="https://www.itpro.com/security/cyber-crime/anthropic-admits-hackers-have-weaponized-its-tools-and-cyber-experts-warn-its-a-terrifying-glimpse-into-how-quickly-ai-is-changing-the-threat-landscape">vibe-hacking</a>’ techniques. </p><p>In one example cited by the company, threat actors used AI to create a fake invoice PDF which triggered a silent download from a compromised site. Thereafter, this redirected unsuspecting users to trusted platforms such as <a href="http://booking.com"><u>Booking.com</u></a> to curb their suspicions.</p><p>Alex Holland, principal threat researcher at HP Security Lab, said the increased use of AI in malware operations, combined with the focus on ‘flat-pack’ components, shows threat actors are prioritizing faster attacks and cheaper costs. </p><p>“It’s the classic project management triangle - speed, quality, and cost,” he said. “You often sacrifice one of them. What we’re seeing is many attackers are optimizing for speed and cost, not quality.”</p><p>“They are not using AI to raise the bar; they’re using it to move faster and reduce effort.”</p><p>Holland further warned that although these campaigns are often basic in nature, the “uncomfortable reality is they still work”. </p><h2 id="ai-malware-is-taking-off">AI malware is taking off</h2><p>The HP research comes in the wake of repeated warnings over the use of AI to build and fine-tune malware. As <em>ITPro </em>reported last month, research from Zscaler shows hackers are <a href="https://www.itpro.com/security/they-are-able-to-move-fast-now-ai-is-expanding-attack-surfaces-and-hackers-are-looking-to-reap-the-same-rewards-as-enterprises-with-the-technology"><u>leveraging the technology to create more potent malware strains</u></a>. </p><p>Google also warned that threat actors were found <a href="https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models">abusing its Gemini AI models to build malware</a> in early February. </p><p>The use of AI in this instance also goes beyond building malware, however, with the technology also used during the early research and development stages. </p><p>Analysis from Trend Micro in September 2025 warned that <a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware"><u>hackers were ‘vibe coding’ malware</u></a> by using AI to dissect publicly available threat intelligence reports. </p><p>This, Trend Micro noted, allowed threat actors to essentially reverse engineer malware strains based on technical blogs from industry stakeholders, create “partial malicious” code, and even mimic other group’s TTPs. </p><p>Ian Pratt, global head of security for personal systems at HP, said the firm’s research highlights the significant risks now posed by threat actors using AI. </p><p>“When attackers can generate and repackage malware in minutes, detection-based defences can’t keep up,” he said. “Instead of trying to spot every variant, organizations need to reduce exposure.”</p><p>Reducing exposure in this sense can be as simple as “containing high-risk activities” such as warning staff not to open untrusted attachments or clicking unknown links - typical advice given by most enterprises yet often still the source of breaches. </p><p>Separate analysis from the firm showed 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanners, underlining the increasing success rates of threat actors. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘They are able to move fast now’: AI is expanding attack surfaces – and hackers are looking to reap the same rewards as enterprises with the technology ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/they-are-able-to-move-fast-now-ai-is-expanding-attack-surfaces-and-hackers-are-looking-to-reap-the-same-rewards-as-enterprises-with-the-technology</link>
                                                                            <description>
                            <![CDATA[ Potent new malware strains, faster attack times, and the rise of shadow AI are causing havoc ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3pVpmH9oN7uEFGuHcNqtg4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hv5eL6mTr2kv7Y4y2nEKmT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Feb 2026 12:12:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hv5eL6mTr2kv7Y4y2nEKmT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI vector illustration showing digitized human brain surrounded by digital storage systems. ]]></media:description>                                                            <media:text><![CDATA[AI vector illustration showing digitized human brain surrounded by digital storage systems. ]]></media:text>
                                <media:title type="plain"><![CDATA[AI vector illustration showing digitized human brain surrounded by digital storage systems. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hv5eL6mTr2kv7Y4y2nEKmT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Attack surfaces are expanding at a rapid pace thanks to enterprise AI adoption, according to research from Zscaler, and it’s placing huge strain on cybersecurity teams. </p><p>Findings from Zscaler ThreatLabz’ 2026 <a href="https://www.zscaler.com/campaign/threatlabz-ai-security-report" target="_blank"><u><em>AI Security Report</em></u></a> show enterprises now face a confluence of threats. The rise of ‘shadow AI’ combined with machine-speed intrusions and the <a href="https://www.itpro.com/security/ncsc-ai-will-increase-speed-and-scale-of-critical-infrastructure-attacks">use of AI among threat actors</a> means time-to-compromise is plunging. </p><p>Deepen Desai, former CSO at Zscaler and head of security research at the ThreatLabz division, told <em>ITPro </em>the first of these issues is a natural byproduct of the industry’s rapid pivot to AI over the last three and a half years. </p><p>Employees have been experimenting with exciting new tools for some time now, often without considering the potential security risks associated with unauthorized AI solutions. </p><p>This creates a huge blind spot for enterprise security teams and creates the risk of disastrous data leakage. Research from Gartner in November 2025 projected up to <a href="https://www.itpro.com/technology/artificial-intelligence/gartner-says-40-percent-of-enterprises-will-experience-shadow-ai-breaches-by-2030-educating-staff-is-the-key-to-avoiding-disaster"><u>40% of enterprises globally will experience a shadow AI-related breach by 2030</u></a>, underlining the growing risks associated with this trend. </p><p>This is an issue that can be remedied by robust internal guardrails, however. It's the use of AI <em>by </em>threat actors that has alarm bells ringing for Desai and counterparts across the industry. </p><p>Hackers have already been observed using the technology to fine-tune <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and <a href="https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns">vishing </a>attacks, for example, but in recent months they’ve begun flocking to these tools to build and refine <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>. </p><p>“It all started with phishing and vishing and their standard initial access attacks, where their goal is just to compromise a credential or an identity,” he told <em>ITPro</em>. </p><p>“But soon we also started noticing malware created using AI, and we are able to tell that because when we reverse those payloads, we're able to see the comments that a lot of these <a href="https://www.itpro.com/technology/artificial-intelligence/how-ai-coding-is-transforming-the-it-industry-in-2025">AI coding tools</a> will add, which is very, very typical.”</p><p>Desai highlighted one recent incident observed by Zscaler in which AI-powered malware was connected to a Google Sheets document to support the attacker when executing commands. </p><p>“The malware that was deployed in this victim's environment would connect to a Google Sheet, which had two columns in it,” he explained. </p><p>“One column where the attacker is entering commands that this malware needs to execute on the victim environment, and the second column where the malware will update the results of what came out when it ran these commands.”</p><p>“Whether it was for data exfiltration, whether it is for downloading a new payload or giving that context for the attacker to perform future commands, it was literally being updated every few minutes,” Desai added. </p><p>Concerns about AI-powered malware have been gaining momentum over the last 18 months, with security experts warning hackers are increasingly relying on the technology to build potent new strains. </p><p>Research from TrendMicro in September 2025 found <a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware"><u>threat actors are “vibe coding” malware</u></a> based on dissected threat intelligence reports, allowing them to reverse engineer particular strains and speed up attacks. </p><p>Similarly, just last week Google warned hackers have been <a href="https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models"><u>abusing its Gemini AI models to build malware</u></a>. </p><h2 id="speedier-attacks-are-raising-concerns">Speedier attacks are raising concerns</h2><p>The use of AI in these instances is helping to speed up attacks, Desai told <em>ITPro</em>, posing huge challenges for security teams. Combine this with the fact that many of the AI systems used by enterprises are highly susceptible to compromise, and teams now face overlapping security considerations. </p><p>Analysis from the company found many enterprise AI systems “break almost immediately” when tested under adversarial conditions. The median time to first critical failure, for example, was just 16 minutes, and 90% of systems were compromised in under 90 minutes. </p><p>“They are able to move fast now because of the same efficiencies that we’re seeing on the production side,” Desai told <em>ITPro</em>, adding that security teams will likely find themselves fighting off AI-powered attacks with their own internal tools in the near future. </p><p>“You have to use AI to fight AI driven attacks,” he said. “You need to apply AI at all stages of the attack to detect phishing, to detect malware, to detect exfiltration, to detect command and control activity.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google says hacker groups are using Gemini to augment attacks – and companies are even ‘stealing’ its models ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence/google-says-hacker-groups-are-using-gemini-to-augment-attacks-and-companies-are-even-stealing-its-models</link>
                                                                            <description>
                            <![CDATA[ Google Threat Intelligence Group has shut down repeated attempts to misuse the Gemini model family ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qzWopoZe4zTA5NEjJaY4zK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/u2PgWCzhcwJ3sd5MyNLvqf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Feb 2026 11:40:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/u2PgWCzhcwJ3sd5MyNLvqf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Gemini AI logo and branding picture on a smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Google Gemini AI logo and branding picture on a smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Google Gemini AI logo and branding picture on a smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/u2PgWCzhcwJ3sd5MyNLvqf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>State-backed threat actors from <a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>CRINK nations</u></a> have come to rely on large language models (LLMs) as “essential tools” for researching and targeting victims, according to a new report.</p><p>The latest <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use" target="_blank"><u><em>AI Threat Tracker</em></u></a> report from Google Threat Intelligence Group (GTIG), produced in collaboration with Google DeepMind, details the numerous ways threat groups are already using AI to plan and carry out attacks.</p><p><a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>Advanced persistent threat (APT)</u></a> groups were tracked using Google’s own Gemini family of models to conduct targeted research on potential victims, probe vulnerabilities, and create tailored code and scripts.</p><p>For example, the China-based APT Temp.HEX was found using Gemini to file information on individual targets in Pakistan.</p><p>The as-yet-unattributed APT UNC6148 also used Gemini to seek out sensitive information tied to victims, such as email addresses and account details, as the first step in a targeted <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing campaign</a> on Ukraine and the wider defense sector. </p><p>In response, Google disabled the assets associated with both groups. Other incidents saw attackers use public AI models to more directly fuel attack campaigns.</p><p>Iranian-backed groups such as APT42 were observed using Gemini and other AI models to research potential victims, then craft convincing phishing emails based on target biographies. </p><p>That same group was observed using Gemini to translate local languages as well as regional references and phrases.</p><p>North Korea-backed groups seized headlines throughout 2024 and 2025, as <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat"><u>hackers infiltrated IT departments</u></a> of major organizations <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think"><u>including KnowBe4</u></a> with fake addresses and identities. </p><p>In the report, the North Korean-backed group UNC2970 was found using Gemini to plan attacks on <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>defense companies and map job specifications.</p><h2 id="ai-enhanced-malware-is-gathering-steam">AI-enhanced malware is gathering steam</h2><p>The report also noted the growing risk presented by malware that uses AI to achieve novel capabilities such as preventing network detection.</p><p>HONESTCUE <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, for example, has been found to use API calls to Gemini to generate ‘stage two’ code. This is used to download and execute additional malware directly in the memory of target systems using CSharpCodeProvider, a legitimate .NET class for executing C# code.</p><p>Because the Gemini-produced code executes the secondary malware directly in memory, HONESTCUE infects target systems without leaving telltale artifacts on the victim’s disk. </p><p>Though the malware hasn’t been linked to specific attack campaigns to date, GTIG researchers said they believe its developer is a single threat actor or small group testing the waters for future attacks. This is backed up by evidence HONESTCUE has been tested on Discord.</p><p>Another example can be found in COINBAIT, a <a href="https://www.itpro.com/security/phishing/phishing-as-a-service-kits-growth-2025-barracuda">phishing kit</a> created by the APT UNC5356 that shows signs of having been created using the <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate"><u>vibe coding platform</u></a> Lovable.</p><p>GTIG has previously warned that <a href="https://www.itpro.com/business/google-says-leading-ai-malware-strains-are-nowhere-near-good-enough-yet-but-that-wont-last-long-as-hackers-refine-techniques"><u>while AI malware is still nascent, it’s developing quickly</u></a>. In the latest report, authors noted that while no “paradigm shift” has yet been unlocked by APTs, their exploration of malicious AI is ongoing and the technology will play a growing role in every stage of the attack lifecycle.</p><p>On the other hand, researchers discovered that threat actors are passing off jailbroken public AI models as handmade offensive tools.</p><p>For example ‘Xantharox’, a dark web toolkit advertised as tailor-made offensive AI toolset, is actually powered by open source AI tools such as Crush and Hexstrike AI via model context protocol (MCP), as well as public AI models like Gemini.</p><p>Threat actors are stealing API keys to enable this hidden activity, with GTIG warning organizations with cloud and AI resources are at risk. Users on platforms such as One API and New API, often those in countries with regional AI censorship, are also targeted for API key harvesting.</p><h2 id="model-extraction-puts-ai-developers-at-risk">Model extraction puts AI developers at risk</h2><p>Researchers also observed instances of APTs performing ‘model extraction’, in which attackers use legitimate access to frontier models such as Gemini to help train new AI and machine learning (ML) models.</p><p>Generally, attackers use an approach known as knowledge distillation (KD) in which a ‘student’ AI model is trained on the answers to specific questions based on the exemplar answers of the pre-existing AI model.</p><p>This can result in models with advanced capabilities such as frontier reasoning but none of the guardrails present in public AI models like Gemini. In the future, threat actors could then use </p><p>GTIG tracked over 100,000 prompts intended to expose and replicate Gemini’s reasoning capabilities in non-English languages, which were automatically counteracted by Google’s systems.</p><p>“Google’s latest AI Threat Tracker marks a specific turning point: we are no longer just worried about bad prompts, but the industrial-scale extraction of the models themselves,” <a href="https://www.linkedin.com/feed/update/urn:li:activity:7427616775657426944/?originTrackingId=mUmbBH5%2FM1mlBWHYZ4FCAg%3D%3D" target="_blank"><u>wrote</u></a> Jamie Collier, lead advisor in Europe at Google Threat Intelligence Group, in a LinkedIn post marking the launch of the report.</p><p>Google DeepMind and GTIG blocked attempts at model extraction throughout 2025, noting that the attacks were launched by private companies and researchers around the world rather than APTs.</p><p>Distilling secondary models from Gemini is a violation of Google’s terms of service and is considered theft of intellectual property (IP). The hyperscaler recommended organizations that provide AI models as a service should closely observe API access for signs of model extraction. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chinese hackers are using ‘stealthy and resilient’ Brickstorm malware to target VMware servers and hide in networks for months at a time ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/chinese-hackers-are-using-stealthy-and-resilient-brickstorm-malware-to-target-vmware-servers-and-hide-in-networks-for-months-at-a-time</link>
                                                                            <description>
                            <![CDATA[ Organizations, particularly in the critical infrastructure, government services, and facilities and IT sectors, need to be wary of Brickstorm ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NiTJpD7arCJes2BVMNENyS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pfHyFGEfihSGxXFaZ3iWkc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Dec 2025 13:49:27 +0000</pubDate>                                                                                                                                <updated>Mon, 08 Dec 2025 13:50:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pfHyFGEfihSGxXFaZ3iWkc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Brickstorm malware concept image showing a brick flying through shattered glass against a black backdrop.]]></media:description>                                                            <media:text><![CDATA[Brickstorm malware concept image showing a brick flying through shattered glass against a black backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[Brickstorm malware concept image showing a brick flying through shattered glass against a black backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pfHyFGEfihSGxXFaZ3iWkc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> is warning that China-sponsored threat actors are using Brickstorm malware to achieve long-term persistence in critical infrastructure networks.</p><p>Brickstorm is a custom Executable and Linkable Format (ELF) Go-based backdoor that allows attackers to maintain stealthy access and provide capabilities for initiation, persistence, and secure command and control (C2). </p><p>It initiates by running checks, and maintains persistence by using a self-watching function, automatically reinstalling or restarting if disrupted.</p><p>For C2, Brickstorm uses multiple layers of encryption - HTTPS, WebSockets and nested Transport Layer Security (TLS) - to hide its communications with the cyber actors’ C2 server. </p><p>CISA warned it also uses DNS-over-HTTPS (DoH) and mimics web server functionality to blend its communications with legitimate traffic. </p><p>For remote system control, it gives cyber actors interactive shell access on the system and allows them to browse, upload, download, create, delete, and manipulate files. </p><p>Meanwhile, some samples act as a SOCKS proxy, facilitating lateral movement and allowing cyber actors to compromise additional systems.</p><p>Jon Baker, VP of threat-informed defense at AttackIQ, warned Brickstorm "excels at remaining undetected within networks"..</p><p>"The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>runs continuous health checks on itself, allowing it to reinstall and restart if tampered with, ensuring its continued operation," Baker explained. "All of this comes together to create a stealthy and resilient malware that can spread across networks and remotely take over entire systems."</p><h2 id="brickstorm-malware-used-to-target-government-it-sectors">Brickstorm malware used to target government, IT sectors</h2><p>CISA warned China-linked threat actors are using the malware strain to target VMware vSphere platforms, mainly in the government and IT sectors. Once compromised, they can use their access to the vCenter management console to steal cloned <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">virtual machine (VM)</a> snapshots for credential extraction and create hidden, rogue VMs.</p><p>CISA said it had analyzed eight Brickstorm samples obtained from victim organizations, including one where it conducted an <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response</a> engagement.</p><p>In this case, the agency said PRC state-sponsored cyber actors gained long-term persistent access to the organization’s internal network in April 2024 and uploaded Brickstorm malware to an internal VMware vCenter server. </p><p>They also gained access to two domain controllers and an Active Directory Federation Services (ADFS) server, successfully compromised the ADFS server and exported cryptographic keys. They used Brickstorm for persistent access to at least 3 September this year.</p><p>Gabrielle Hempel, security operations strategist at Exabeam, said a key concern with Brickstorm malware is that it’s “targeting control planes and not just endpoints”, making it a potent weapon in the hands of hackers. </p><p>"You’re seeing vSphere, vCenter, and authentication infrastructure being targeted, and this is strategic: once an adversary owns your hypervisor layer, your traditional EDR, NDR, and many SIEM tools become blind to this because the attacker is no longer living in normal host or network telemetry,” Hempel commented.</p><p>The US National Security Agency (NSA) is urging organizations — particularly those within critical infrastructure, government services and facilities, and IT — to use the indicators of compromise (IOCs) and detection signatures outlined in the report to detect Brickstorm backdoor activity and promptly report any compromise.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/shai-hulud-malware-is-back-with-a-vengeance-and-hit-more-than-19-000-github-repositories-so-far-heres-what-developers-need-to-know">Shai-Hulud malware is back with a vengeance and has hit more than 19,000 GitHub repositories</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">Malware as a Service explained</a></li><li><a href="https://www.itpro.com/security/malware/the-most-prominent-infostealers-and-how-businesses-can-protect-against-them">The most prominent infostealers and how businesses can protect against them</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The most prominent infostealers and how businesses can protect against them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/the-most-prominent-infostealers-and-how-businesses-can-protect-against-them</link>
                                                                            <description>
                            <![CDATA[ What are the most prominent infostealers of 2025 , how is the malware evolving, and how can you protect your business? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UKtGb8vbbdm4bAo6Gn4XyA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7jpErjJDERMSTESBCWn9u8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 05 Dec 2025 08:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7jpErjJDERMSTESBCWn9u8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized illustration showing icons representing malware, hackers, and stolen credentials made of felt such as a credit card, magnifying glass, fingerprint, and insect with a chip on its back.]]></media:description>                                                            <media:text><![CDATA[A stylized illustration showing icons representing malware, hackers, and stolen credentials made of felt such as a credit card, magnifying glass, fingerprint, and insect with a chip on its back.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized illustration showing icons representing malware, hackers, and stolen credentials made of felt such as a credit card, magnifying glass, fingerprint, and insect with a chip on its back.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7jpErjJDERMSTESBCWn9u8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> continues to evolve, infostealers are <a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials"><u>increasingly providing adversaries</u></a> with the credentials they need to perform devastating cyber-attacks. </p><p>You don’t have to look far to find examples, with intrusions at <a href="https://www.itpro.com/security/cyber-attacks/schneider-electric-confirms-breach-after-hacker-claims-to-have-40gb-of-stolen-data"><u>Schneider Electric</u></a> and <a href="https://www.infosecurity-magazine.com/news/telefonica-breach-20000-employees/" target="_blank"><u>Telefonica</u></a> were also perpetrated using credentials stolen via infostealers.</p><p>Attacks using infostealers often precede other breaches such as ransomware. 54% of ransomware victims’ credentials first appeared in infostealer dumps, according to Verizon’s <em>2025 Data Breach Investigations</em> <a href="https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf" target="_blank"><u>report</u></a>.</p><p>In September, cybersecurity researchers at Proofpoint <a href="https://www.itpro.com/security/malware/cybersecurity-experts-issue-urgent-warning-amid-surge-in-stealerium-malware-attacks"><u>issued a warning</u></a> over a significant rise in the use of Stealerium malware used to harvest sensitive data from victims worldwide. The infostealer can exfiltrate a wide range of data, from browser credentials and crypto wallets to Wi-Fi profiles and VPN configurations.</p><p>Apart from Stealerium, what are the most prominent infostealers of 2025 – and how can leaders protect their businesses as new strains continue to evolve?</p><h2 id="lumma-stealer">Lumma Stealer</h2><p>Perhaps the most famous infostealer and certainly the most active is Lumma Stealer. Attacks involving Lumma Stealer still account for four times more than prominent stealer Rhadamanthys and eight times more than Vidar, says Spence Hutchinson, staff threat intelligence researcher at eSentire TRU.</p><p>Lumma, which is attributed to a malware author called Shamel, is found for sale on Russian-speaking crime forums and has been distributed since at least July 2024 via GitHub networks such as the <a href="https://www.itpro.com/security/cyber-crime/researchers-discover-highly-sophisticated-operation-using-a-3000-strong-network-of-ghost-accounts-to-spread-malware-on-github"><u>Stargazers Ghost Network</u></a>.</p><p>Microsoft Threat Intelligence has noted that Lumma Stealer uses multi-vector delivery methods for attacks.</p><p>“Its operators demonstrate resourcefulness and proficiency in impersonation tactics,” the researchers <a href="https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/" target="_blank"><u>wrote</u></a> in May. </p><p>“The Lumma Stealer distribution infrastructure is flexible and adaptable. Operators continually refine their techniques, rotating malicious domains, exploiting ad networks, and leveraging legitimate cloud services to evade detection and maintain operational continuity.</p><p>In May, <a href="https://www.itpro.com/business/394-000-windows-devices-have-been-infected-with-lumma-stealer-malware-now-microsoft-is-hitting-back"><u>Lumma Stealer was disrupted</u></a> by a joint US-EU-Japanese <a href="https://www.europol.europa.eu/media-press/newsroom/news/europol-and-microsoft-disrupt-world%E2%80%99s-largest-infostealer-lumma" target="_blank"><u>law enforcement action</u></a> that took down infrastructure used to host deployments. After that, the software re-emerged with added <a href="https://www.itpro.com/security/stealthy-malware-the-threats-hiding-in-plain-sight"><u>stealthy malware</u></a> processes to avoid detection.</p><p>The malware now includes capabilities such as AMSI bypass, process hollowing, code flow obfuscation, encrypted command and control communications, persistence via registry modifications, and DLL sideloading, Daniel dos Santos, senior director, head of research at Forescout tells <em>IT Pro</em>.</p><h2 id="rhadamanthys">Rhadamanthys</h2><p>First seen in 2022, Rhadamanthys is a complex, multi-modular malware sold on the underground market. The malware is thought to have been created by experienced developers, and has been used in <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers"><u>ClickFix campaigns</u></a> in 2025.</p><p>Its latest release, v0.9.2, comes with “significant updates that may impact detection”, according to an October report by <a href="https://research.checkpoint.com/2025/rhadamanthys-0-9-x-walk-through-the-updates/"><u>Check Point Research</u></a>. </p><p>In November, Europol severely disrupted Rhadamanthys operations – alongside those of the VenomRAT remote access <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus"><u>Trojan</u></a> and Elysium <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet"><u>botnet</u></a> – in a new stage of <a href="https://www.itpro.com/security/ransomware/its-been-a-bad-week-for-ransomware-operators"><u>Operation Endgame</u></a>.</p><h2 id="risepro">RisePro</h2><p>Also available as a <a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note"><u>malware as as a service (MaaS)</u></a> offering, RisePro targets Windows operating systems. “It deploys a number of defence evasion techniques to remain undetected, including obfuscating command and control activity to exfiltrate data,” warns Calum Baird, digital forensics and incident response consultant at Systal Technology Solutions. </p><p>Kaspersky tracked it as a highly significant driver of infostealer attacks, with its share of total infections rising from 1.4% in 2023 to 23% in 2024.</p><h2 id="vidar">Vidar</h2><p>The Vidar infostealer targets personal information and cryptocurrency wallet details stored on devices. In 2022, Check Point Research tracked it as a strain <a href="https://www.itpro.com/security/malware/369299/zoom-themed-cyber-attacks-fuel-rapid-malware-growth"><u>used to target Zoom users</u></a> and in 2023, attackers were using the malware in a <a href="https://www.itpro.com/security/malware/369892/google-ads-malvertising-campaign-prompts-questions-around-search-security"><u>Google Ads malvertising campaign</u></a>.</p><p>It utilizes an “interesting method” for command and control, using social media platforms such as Telegram and Mastodon as infrastructure, according to Baird. </p><p>“Vidar samples have also been found to contain null bytes, inflating size in an attempt to evade antivirus detection,” he adds.</p><h2 id="stealc">StealC</h2><p>StealC infostealer has been sold since 2023, with version 2 released in March 2025. Additions to the new version include a command and control protocol encrypted with RC4 and updated payload delivery options via MSI packages and <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell">PowerShell</a>, says dos Santos.</p><p>This update has made StealC “more evasive and adaptable” than previous versions, increasing the threat it poses, Baird adds.</p><h2 id="gremlin-stealer"> Gremlin Stealer</h2><p>One of the biggest threats to watch is Gremlin Stealer, a known variant of Sharp Stealer, according to Anna Chung, principal researcher EMEA, Unit 42 at Palo Alto Networks. “It exfiltrates data from its victims and uploads this information to its dedicated web server for publication, which is part of the purchasable malware infrastructure.”</p><p>The malware can bypass modern browser defenses such as Chrome's cookie protection to steal browser data including cookies, passwords, credit cards and autofill forms from Chromium and Gecko-based clients. </p><p>But it doesn’t just stop at browsers: Gremlin targets FTP and VPN credentials, Discord tokens, Telegram session data, and popular cryptocurrency wallets, alongside general system information, screenshots and clipboard data.</p><h2 id="darkcloud-stealer">DarkCloud Stealer</h2><p>DarkCloud Stealer is primarily distributed through email <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing campaigns</u></a>, often using obfuscated archive files to evade initial detection, says Chung. Once executed, it can steal a wide range of sensitive data, including host and user details, screenshots, contacts, stored credentials such as usernames and passwords, credit card details, email client credentials and FTP client access data. </p><p>“In recent months, we’ve seen the DarkCloud infostealer specifically targeting government organizations, which is concerning given the range of data they possess,” says Chung.</p><h2 id="infostealers-in-the-future">Infostealers in the future</h2><p>Infostealers are stepping up their game with obfuscation, making them harder to detect and analyze. David Sancho, senior threat researcher at Trend Micro, predicts that infostealers will evolve to use more intelligent methods for collecting data, enabling them to identify which information on a victim’s computer is “most monetizable”. </p><p>On the attacker backends, AI-enhanced programs are likely to play “a growing role in analysing the vast amounts of data collected”, Sancho adds. “These systems could sift through stolen information to identify high-value assets, such as domain credentials from large enterprises, rather than less valuable data from personal devices.”</p><h2 id="responding-to-the-threat">Responding to the threat</h2><p>Infostealers are a growing threat to all firms but once you are aware of how they operate, steps can be taken to help mitigate them.</p><p>It’s important to note that infostealers are “simply a type of malware payload”, and the methods they use to infiltrate corporate networks are “varied and don’t follow a consistent pattern”, says Sancho.</p><p>Entry points include phishing emails or compromised websites offering “seemingly harmless” software downloads, he says. While keeping antivirus software up to date can help defend against these threats, the most effective protection is implementing multi-factor authentication (MFA), Sancho advises. “MFA ensures that even if attackers obtain valid credentials, they still require a second form of verification, typically a mobile device, to access corporate systems.”</p><p>Sancho also recommends using an external encrypted credentials repository, “so that the infostealer will not find any memorized passwords on the browser”.</p><p>Entry points include phishing emails or compromised websites offering “seemingly harmless” software downloads, he says. While keeping antivirus software up to date can help defend against these threats, the most effective protection is implementing <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication (MFA)</u></a>, Sancho advises. “MFA ensures that even if attackers obtain valid credentials, they still require a second form of verification, typically a mobile device, to access corporate systems.”</p><p>Sancho also recommends using an external encrypted credentials repository, “so that the infostealer will not find any memorized passwords on the browser”.</p><p>At the same time, experts recommend conducting regular phishing and security awareness training exercises. “Especially those that train against browser-based attacks, including current social engineering tactics,” says Hutchinson.</p><p>One helpful action is to disable some of the common commands used to carry out <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix</a>-style attacks – which often lead to Lumma Stealer or other infostealers being downloaded, says Hutchinson. </p><p>As part of this, he advises removing the “Run” prompt from the Start Menu using Windows Group Policy Objects and <a href="https://learn.microsoft.com/en-us/answers/questions/4227075/disabling-wscript" target="_blank"><u>disabling Wscript</u></a>, using AppLocker or Windows Defender GPO. “Disabling Run for all users is probably the main way to prevent ClickFix – since it tricks the user in to opening up run and pasting in a command copied to their clipboard.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Scattered Lapsus$ Hunters group is targeting Zendesk customers – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-scattered-lapsus-usd-hunters-group-is-targeting-zendesk-customers-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ The group appears to be infecting support and help-desk personnel with remote access trojans and other forms of malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yA82eDy5m43beT5ptyrzhG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KfsCD25eUDMdmZevdnb6rU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Nov 2025 11:45:15 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Nov 2025 11:46:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KfsCD25eUDMdmZevdnb6rU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zendesk logo and branding pictured on a smartphone screen. ]]></media:description>                                                            <media:text><![CDATA[Zendesk logo and branding pictured on a smartphone screen. ]]></media:text>
                                <media:title type="plain"><![CDATA[Zendesk logo and branding pictured on a smartphone screen. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KfsCD25eUDMdmZevdnb6rU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Scattered Lapsus$ Hunters threat group appears to be targeting <a href="https://www.itpro.com/business/marketing-and-comms/how-lush-aligned-its-disjointed-customer-support-operations">Zendesk </a>users in a new <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign, according to analysis from ReliaQuest.</p><p>The security firm <a href="https://reliaquest.com/blog/zendesk-scattered-lapsus-hunters-latest-target/" target="_blank"><u>said</u></a> it has spotted Zendesk-related infrastructure, including more than 40 typosquatted domains and URLs impersonating the company, created over the last six months. </p><p>These domains aim to mimic organizations’ Zendesk environments and host phishing pages, researchers warned. </p><p>"These domains, such as znedesk[.]com or vpn-zendesk[.]com, are clearly designed to mimic legitimate Zendesk environments. Some host phishing pages, like fake <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> portals that appear before Zendesk authentication," said ReliaQuest. </p><p>"It’s a classic tactic probably aimed at stealing credentials from unsuspecting users. We also identified Zendesk-related impersonating domains that contained multiple different organizations’ names or brands within the URL, making it even more likely that unsuspecting users would trust and click on these links."</p><p>The domains shared several registry details: registration through NiceNic, US and UK registrant contact information, and Cloudflare-masked nameservers. </p><p>"These elements are reminiscent of the recent Scattered Lapsus$ Hunters campaign that targeted customer relationship management platform Salesforce in August 2025," ReliaQuest said. </p><p>"The domains we uncovered while investigating the August campaign shared similarities with the Zendesk domains: formatting, registry characteristics, and the use of deceptive SSO portals." </p><h2 id="be-wary-of-fraudulent-zendesk-tickets">Be wary of fraudulent Zendesk tickets</h2><p>Meanwhile, ReliaQuest said it has observed fraudulent tickets being submitted to legitimate Zendesk portals operated by organizations using the software for customer service. </p><p>Pretexts include urgent system administration requests or fake password reset inquiries, and the aim is to infect support and help-desk personnel with <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">remote access trojans (RATs)</a> and other forms of <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>.</p><p>In September, Scattered Lapsus$ Hunters targeted the communication platform Discord, accessing its Zendesk-based support system and exfiltrating a large number of names, email addresses, billing information, IP addresses, and government-issued IDs.</p><p>A message posted on a Telegram channel associated with the group in November claimed: "Wait for 2026, we are running 3-4 campaigns atm." </p><p>Another read: "all the IR (incident response) people should be at work watching their logs during the upcoming holidays till January 2026 bcuz #ShinyHuntazz is coming to collect your customer databases."</p><p>ReliaQuest said organizations should handle customer support platforms with the same level of security as their own core infrastructure.  </p><p>"ReliaQuest anticipates that SLSH, or copycat threat actors, will likely continue abusing Zendesk and similar customer support platforms — typically monitored less rigorously than inbound email traffic — to access downstream customers' sensitive data and credentials," said the firm. </p><p>"These platforms now warrant equivalent security controls to core infrastructure, particularly since SLSH operates multiple, concurrent attack paths, i.e. external phishing domains coupled with internal ticket injection."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/crowdstrike-insider-attack-wake-up-call">If you're not taking insider threats seriously, then the CrowdStrike incident should be a big wake up call</a></li><li><a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer">Scattered Spider: Who are the alleged hackers behind the M&S cyber attack?</a></li><li><a href="https://www.itpro.com/security/hackers-behind-jaguar-land-rover-announce-their-retirement-should-we-believe-them">Hackers behind Jaguar Land Rover announce their 'retirement' – should we believe them?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shai-Hulud malware is back with a vengeance and has hit more than 19,000 GitHub repositories so far — here's what developers need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/shai-hulud-malware-is-back-with-a-vengeance-and-hit-more-than-19-000-github-repositories-so-far-heres-what-developers-need-to-know</link>
                                                                            <description>
                            <![CDATA[ The malware has compromised more than 700 widely-used npm packages, and is spreading fast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">REg52qhZmQHgZURnJGdGi8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S2kXYxtTBgGXo79HoNmvZZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Nov 2025 10:38:18 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Nov 2025 12:55:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S2kXYxtTBgGXo79HoNmvZZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dune Shai-Hulud concept image showing man standing on rock with giant sandworm breaching out of the sand. ]]></media:description>                                                            <media:text><![CDATA[Dune Shai-Hulud concept image showing man standing on rock with giant sandworm breaching out of the sand. ]]></media:text>
                                <media:title type="plain"><![CDATA[Dune Shai-Hulud concept image showing man standing on rock with giant sandworm breaching out of the sand. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S2kXYxtTBgGXo79HoNmvZZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Shai-Hulud worm is back and once again infecting npm packages – and the scale of the attack is even greater than a September 2025 campaign which affected 180 repositories before containment. </p><p>Attackers involved in the campaign have been exploiting compromised package maintainer accounts to publish trojanized versions of <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-these-malicious-npm-packages-to-target-developers-windows-macos-and-linux-systems-heres-how-to-stay-safe">legitimate npm packages</a> that appear to originate from the official source.</p><p>Once downloaded, the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>scans for credentials and <a href="https://www.itpro.com/development/32887/what-is-continuous-integration">CI/CD</a> secrets, which are then published to the user's own repositories. It also inserts the malicious payload into all of the users’ available npm packages, spreading the infection. </p><p>This time round, the malware has affected more than 19,000 GitHub repositories and compromised around 700 npm packages, including core libraries from Zapier and the Ethereum Name Service (ENS) ecosystem, along with PostHog and Postman.  </p><p><a href="https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack" target="_blank"><u>According to Wiz Threat Research</u></a>, the attack is accelerating at around 1,000 new repos every 30 minutes.</p><p>"This campaign continues the trend of npm supply-chain compromises referencing Shai-Hulud naming and tradecraft, though it may involve different actors," said Wiz. </p><h2 id="new-shai-hulud-campaign-shakes-up-tactics">New Shai-Hulud campaign shakes up tactics</h2><p>This campaign adds a couple of new features, according to researchers, including execution using install lifecycle scripts and new payload files <em>setup_bun.js</em> and <em>bun_environment.js</em>.</p><p>Meanwhile, if the malware fails to authenticate or establish persistence, it attempts to destroy the victim’s entire home directory, deleting every writable file owned by the current user under their home folder. </p><p>Wiz said it's observed multiple environments where the affected packages were downloaded before their removal from npm, suggesting active exposure.</p><p>While <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>is currently removing attacker-created repositories associated with this campaign, the threat actors continue to create new repositories as part of their ongoing activities.</p><p>Garrett Calpouzos, principal security researcher at Sonatype, said a peculiar aspect of the campaign is that it appears to be confusing AI analysis tools, largely due to the size and structure of the file.  </p><p>“It’s so large that it exceeds a normal context window and the models can’t keep track of everything they're reading," he noted. </p><p>"I’ve asked both <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a> and <a href="https://www.itpro.com/technology/artificial-intelligence/google-launches-flagship-gemini-3-model-and-google-antigravity-a-new-agentic-ai-development-platform">Gemini</a> to analyze it and I get different answers each time. Looking at their reasoning, they’re searching for obvious malware patterns – like calls to suspicious domains – and not finding any, so they incorrectly conclude it’s just a legitimate session or token management library."</p><h2 id="what-developers-need-to-know">What developers need to know</h2><p>Developers should cross-reference all installed packages against the compromised list, <a href="https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains" target="_blank"><u>said Aikido</u></a>, and uninstall any compromised package versions immediately.</p><p>Enterprises are also advised to check GitHub accounts for unauthorized repos with "Shai Hulud: The Second Coming" in the description.</p><p>Credential rotation is another key tactic here for defenders, according to Wiz, with devs advised to check GitHub, npm, cloud, and CI/CD secrets used on any machine that installed these packages. </p><p>Elsewhere, enterprises should disable npm postinstall scripts in CI environments, enforce <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">MFA </a>on all GitHub and npm accounts, and stop auto-updates until verified clean.</p><p>"The timing is notable, given npm’s recent announcement that it will revoke classic tokens on December 9 after the wave of supply chain attacks," commented Charlie Eriksen, a malware researcher at Aikido. </p><p>"With many users still not migrated to trusted publishing, the attacker seized the moment for one more hit before npm’s deadline."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/malware-free-attacks-threat-to-businesses">Malware-free attacks: The threat to businesses</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">Malware as a Service explained: What it is and why businesses should take note</a></li><li><a href="https://www.itpro.com/security/malware/what-is-polymorphic-malware">What is polymorphic malware?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The US, UK, and Australia just imposed sanctions on a Russian cyber crime group – 'we are exposing their dark networks and going after those responsible' ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/the-us-uk-and-australia-just-imposed-sanctions-on-a-russian-cyber-crime-group-we-are-exposing-their-dark-networks-and-going-after-those-responsible</link>
                                                                            <description>
                            <![CDATA[ Media Land offers 'bulletproof' hosting services used for ransomware and DDoS attacks around the world ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jbcE8oNisiHJvQRxooNzLU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Aqeo3GHF5pnDS754K9ahY5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Nov 2025 10:55:00 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Nov 2025 08:31:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Aqeo3GHF5pnDS754K9ahY5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Russian cyber crime concept image showing Russian national flag with padlock symbol in background with smashed glass in foreground.]]></media:description>                                                            <media:text><![CDATA[Russian cyber crime concept image showing Russian national flag with padlock symbol in background with smashed glass in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Russian cyber crime concept image showing Russian national flag with padlock symbol in background with smashed glass in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Aqeo3GHF5pnDS754K9ahY5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK, US, and Australia have imposed sanctions on a Russian cyber crime group offering so-called 'bulletproof' <a href="https://www.itpro.com/network-internet/web-hosting/368170/best-web-hosting-services-in-2022">hosting services</a> for hackers worldwide. </p><p>Media Land provides online infrastructure to support <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>operations, and is believed to have played a key role in a spate of devastating cyber attacks in recent years. </p><p>Ransomware victims of the outfit include UK <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">critical national infrastructure</a> organizations and it's also been used for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and phishing campaigns targeting UK taxpayers.</p><div class="product"><a data-dimension112="d3621f22-76d8-423e-9d21-6425e3c7656d" data-action="Deal Block" data-label="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop today to get 30% OFF for Enterprise and Business plans" href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="8aurHnFJraWhwkrtyVHwtD" name="NP-affiliate-black-friday-campaign-1200x1200" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/8aurHnFJraWhwkrtyVHwtD.jpg" mos="" align="middle" fullscreen="" width="1200" height="1200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Boost password security and keep your business safe with NordPass B2B.</p><p><a href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="sponsored" data-dimension112="d3621f22-76d8-423e-9d21-6425e3c7656d" data-action="Deal Block" data-label="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension25="">Catch the price drop today to get 30% OFF for Enterprise and Business plans</a><a class="view-deal button" href="https://go.nordpass.io/aff_c?offer_id=754&aff_id=3013&url_id=31981" target="_blank" rel="nofollow" data-dimension112="d3621f22-76d8-423e-9d21-6425e3c7656d" data-action="Deal Block" data-label="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension48="Catch the price drop today to get 30% OFF for Enterprise and Business plans" data-dimension25="">View Deal</a></p></div><p>In the US, Media Land infrastructure has been used in <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS)</a> attacks against companies and critical infrastructure. Meanwhile, in Australia, the group has helped criminals to carry out attacks against financial institutions, businesses, their customers, and critical infrastructure. </p><p>"Cyber criminals think that they can act in the shadows, targeting hard working British people and ruining livelihoods with impunity," said UK foreign secretary Yvette Cooper.</p><p>"But they are mistaken – together with our allies, we are exposing their dark networks and going after those responsible."</p><p>The measures target Media Land’s ringleader, Alexander Volosovik, also known as Yalishanda, who has been active since at least 2010 and is known to have worked with some of the most notorious cyber criminal groups, including Evil Corp, <a href="https://www.itpro.com/security/ransomware/lockbit-remains-most-dangerous-ransomware-despite-fall-in-attacks">LockBit</a>, and <a href="https://www.itpro.com/security/ransomware/royal-hive-black-basta-ransomware-gangs-collaborating-on-cyber-attacks">Black Basta</a>. </p><p>Also sanctioned is Kirill Zatolokin, a Media Land employee responsible for collecting payment from customers and coordinating with other cyber actors, as well as Yulia Pankova, who has helped Volosovik with legal issues and handled his finances.</p><h2 id="sanctions-target-media-land-sister-outfits">Sanctions target Media Land sister outfits</h2><p>The sanctions also target ML Cloud, a Media Land sister company whose technical infrastructure is often used in conjunction with Media Land, including in ransomware and <a href="https://www.itpro.com/security/cyber-attacks/cyber-experts-have-been-warning-about-ai-powered-ddos-attacks-now-theyre-becoming-a-reality">DDoS attacks</a>.</p><p>Hypercore, a UK company registered and utilized by Aeza Group, has also been targeted in the international campaign. </p><p>The sanctions block access to any assets held in the sanctioning countries, and bar businesses and individuals there from engaging with the listed entities or people. Financial institutions that violate these restrictions can face penalties themselves.</p><p>"These sanctions don’t just impose costs on criminals, they dismantle the infrastructure that enables cyber crime," said Australian deputy prime minister Richard Marles. </p><p>"By disrupting these networks, we make it harder for others to launch attacks and it strengthens Australia’s resilience against future threats."</p><h2 id="will-the-sanctions-work">Will the sanctions work?</h2><p>The move marks the latest in a string of actions by governments to crack down on cyber crime-related hosting services. </p><p>In July this year, the US Treasury <a href="https://www.itpro.com/security/ransomware/aeza-group-ransomware-hosting-us-sanctions">announced plans to impose sanctions on Azea Group</a>, another bulletproof hosting service for its activities. US officials revealed the group has been selling access to specialized services and infrastructure used in a series of ransomware and infostealer malware campaigns. </p><p>While this fresh crackdown has been welcomed by security industry stakeholders, John Binns, partner and head of the sanctions practice at BCL Solicitors, said these typically have a limited effect. </p><p>"The evidential threshold for designation under the regulations is significantly lower than any in the criminal process, and the real-world impact on sophisticated actors operating primarily in hostile jurisdictions can be modest," he said.</p><p>"While sanctions are undoubtedly a valuable addition to the law-enforcement toolkit against transnational cyber crime, they deliver a form of administrative rather than criminal justice and are best viewed as potentially complementing - rather than supplanting - efforts to secure arrests, prosecutions, and asset forfeiture through the courts."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do">Russia is targeting unpatched vulnerabilities – what can tech leaders do to shore up defenses?</a></li><li><a href="https://www.itpro.com/security/is-sector-cyber-awareness-crisis-workforce">Are we in a cyber awareness crisis?</a></li><li><a href="https://www.itpro.com/security/enterprises-need-to-acknowledge-the-importance-of-basic-cyber-hygiene">Enterprises need to acknowledge the importance of basic cyber hygiene</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europol hails triple takedown with Rhadamanthys, VenomRAT, and Elysium sting operations ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/europol-hails-triple-takedown-with-rhadamanthys-venomrat-and-elysium-sting-operations</link>
                                                                            <description>
                            <![CDATA[ The Rhadamanthys infostealer operation is one of the latest victims of Europol's Operation Endgame, with more than a thousand servers taken down ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">84rf84B6USKP3XsAAbyTHC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Nov 2025 12:08:54 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Nov 2025 12:09:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:description>                                                            <media:text><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a Europol sign affixed to its Amsterdam headquarters]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hNt2JaLuS3Ribvoh5XfgT8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the latest stage of its Operation Endgame campaign, Europol has seriously disrupted the Rhadamanthys infostealer, VenomRAT, and Elysium <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnet </a>malware operations.</p><p>More than 1,000 servers used by the groups to infect hundreds of thousands of victims worldwide with <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>were last week taken down.</p><p>Law enforcement searched one location in Germany, one in Greece, and nine in the Netherlands, seizing 20 domains. One arrest, related to the VenomRAT tool, has been made in Greece.</p><p>"The dismantled malware infrastructure consisted of hundreds of thousands of infected computers containing several million stolen credentials. Many of the victims were not aware of the infection of their systems," Europol said. </p><p>"The main suspect behind the infostealer had access to over 100,000 crypto wallets belonging to these victims, potentially worth millions of euros."</p><p>These hadn't yet been used to steal assets, Europol said. However, it's recommended checking <a href="http://politie.nl/checkyourhack" target="_blank"><u><em>politie.nl/checkyourhack</em></u></a> and <a href="http://haveibeenpwned.com" target="_blank"><u><em>haveibeenpwned.com</em></u></a> to find out whether computers have been hacked and learn what to do.</p><p>The Rhadamanthys infostealer harvests browser-resident data, including credentials, browser data, autofill information, and cryptocurrency wallet artifacts from browsers, password managers, and crypto wallets. </p><p><a href="https://www.proofpoint.com/us/blog/threat-insight/operation-endgame-quakes-rhadamanthys" target="_blank"><u>According to Proofpoint</u></a>, it costs between $300 and $500 a month, with options for a higher price point for customized uses. The firm said it appears that the threat actor behind Rhadamanthys was not only facilitating information stealer operations but also stealing sensitive data from Rhadamanthys affiliates. </p><p>"In addition to the infrastructure disruption, it’s likely that this operation will also negatively affect the criminals’ reputation, leading affiliates to mistrust them," the firm pointed out.</p><p><a href="https://www.shadowserver.org/news/rhadamanthys-historical-bot-infections-special-report/" target="_blank"><u>According to the Shadowserver Foundation</u></a>, which assisted in the operation, Rhadamanthys has grown to become one of the leading infostealers since Operation Endgame 2.0 disrupted the infostealer landscape earlier this year.   </p><p>"It is important to note that Rhadamanthys may have been used to drop additional malware on infected systems, so other malware infections may also be active on these systems and require further local remediation efforts," the Shadowserver Foundation warned. </p><p>"These victim systems may also have been used in historic or recent intrusions and ransomware incidents." </p><p>VenomRAT, which first appeared in 2020, generally arrives through malicious email attachments or links, also using fake <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus">antivirus </a>pages. </p><p>It gives its operators remote desktop-style control, allowing the theft of files, browser data, cryptocurrency wallets, credit card details, account passwords, and authentication cookies.</p><p>While it's mainly been used to target Latin American organizations, it has also claimed victims in North America and Western Europe. </p><p>The Elysium botnet meanwhile, carries out data theft, payload delivery and other tasks.</p><p>Operation Endgame, launched in 2024, has now led to total  seizures of more than €21 million. This latest action follows an Operation Endgame raid in May that saw 300 servers taken down and 650 domains seized, along with €3.5 million. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/botnets-are-being-sold-on-the-dark-web-for-as-little-as-dollar99">Botnets are being sold on the dark web for as little as $99</a></li><li><a href="https://www.itpro.com/security/malware/what-is-polymorphic-malware">What is polymorphic malware?</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">Everything you need to know about Malware as a Service</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using these malicious npm packages to target developers on Windows, macOS, and Linux systems – here’s how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-using-these-malicious-npm-packages-to-target-developers-windows-macos-and-linux-systems-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Security experts have issued a warning to developers after ten malicious npm packages were found to deliver infostealer malware across Windows, Linux, and macOS systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QPudZTpdftQoXU8Cq9PzxC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RZkY82LLq5627rxcbWkaVb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Oct 2025 12:20:13 +0000</pubDate>                                                                                                                                <updated>Thu, 30 Oct 2025 12:55:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RZkY82LLq5627rxcbWkaVb-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware concept image showing malicious npm packages contained in a red highlighted file surrounded by legitimate folders.]]></media:description>                                                            <media:text><![CDATA[Malware concept image showing malicious npm packages contained in a red highlighted file surrounded by legitimate folders.]]></media:text>
                                <media:title type="plain"><![CDATA[Malware concept image showing malicious npm packages contained in a red highlighted file surrounded by legitimate folders.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RZkY82LLq5627rxcbWkaVb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have issued a warning to developers after ten malicious npm packages have been found to deliver <a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses">infostealer malware</a> across Windows, Linux, and macOS systems.</p><p>Analysis by researchers at <a href="https://socket.dev/blog/10-npm-typosquatted-packages-deploy-credential-harvester" target="_blank"><u>Socket's Threat Research Team</u></a> shows the malware distributed as part of the campaign uses four layers of obfuscation to hide payloads, displays a fake CAPTCHA to appear legitimate, and fingerprints victims by IP address.</p><p>It downloads a 24MB PyInstaller-packaged information stealer that harvests credentials from system keyrings, browsers, and authentication services across <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">Windows, Linux</a>, and macOS.</p><p>"This <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>demonstrates multiple advanced techniques rarely seen together in npm supply chain attacks," said the researchers. </p><p>The ten packages were published on July 4, researchers noted, and have remained live for over four months, clocking up more than 9,900 downloads between them. </p><p>Researchers have asked the npm registry to remove them to prevent future victims from falling prey. </p><h2 id="how-the-malicious-npm-packages-work">How the malicious npm packages work</h2><p>The packages were registered under typosquatted names to mimic legitimate libraries. These include: </p><ul><li>typescriptjs, mimicking TypeScript</li><li>deezcord.js, and dezcord.js, mimicking discord.js</li><li>etherdjs, ethesjs, ethetsjs, mimicking ethers.js</li><li>nodemonjs, mimicking nodemon</li><li>react-router-dom.js, mimicking react-router-dom</li><li>zustand.js, mimicking zustand</li></ul><p>Once installed, the malware serves a <a href="https://www.itpro.com/security/cyber-crime/fake-captcha-attacks-surged-in-late-2024-heres-what-to-look-out-for">fake CAPTCHA</a> prompt. It detects the victim's operating system and launches the obfuscated payload in a new terminal window, meaning the malware runs independently of the npm install process. </p><p>"Developers who glance at their terminal during installation see a new window briefly appear, which the malware immediately clears to avoid suspicion," the researchers said.</p><p>It uses four distinct layers of obfuscation. A “Self-Decoding Eval Wrapper” wraps the entire payload in an immediately-invoked function expression that reconstructs and evaluates itself, preventing cursory inspection of the code.</p><p>The second layer uses XOR cipher with a dynamically generated key based on hashing the decoder function itself, making automated decryption difficult without executing the code.</p><p>In the third layer, the payload string is URL-encoded, requiring URI decoding before XOR decryption: a barrier to static analysis tools that do not implement full JavaScript evaluation.</p><p>Finally, in the fourth layer, the decoded code uses switch-case state machines with hexadecimal and octal arithmetic to obscure program flow.</p><p>Thereafter, it sends the victim's geolocation and system fingerprint information to the attacker's command and control (C2) server, allowing downloads and automatically launching a platform-specific data extractor binary. </p><p>"This cross-platform approach ensures developers on any operating system receive a fully functional information stealer tailored to their platform's credential storage mechanisms," researchers said.</p><p>"Windows developers have their Credential Manager harvested, macOS developers have their Keychain extracted, and Linux developers have their SecretService keyrings compromised."</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>According to Socket, researchers should immediately audit their dependencies for the ten malicious packages and assume that any system where they've been installed is fully compromised.</p><p>Similarly, they should reset all credentials stored in system keyrings and password managers, revoke authentication tokens for all services including OAuth, JWT, and API keys, enable multi-factor authentication on all accounts if not already enabled, and rotate SSH keys while reviewing authorized keys on all systems.</p><p>Access logs should be audited for unusual activity on connected services, and teams should check for lateral movement from compromised systems to production infrastructure. </p><p>Browser history should be reviewed for potential credential theft from saved passwords, and monitoring should be established for unauthorized access to repositories, <a href="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022">cloud services</a>, and internal systems.</p><p>Finally, <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN </a>and firewall logs should be reviewed for connections to 195[.]133[.]79[.]43, and any additional persistence mechanisms that may have been installed should be identified and removed.</p><h2 id="malicious-npm-packages-keep-causing-chaos">Malicious npm packages keep causing chaos</h2><p>The use of <a href="https://www.itpro.com/security/npm-package-malware-aikido-security"><u>malicious npm packages</u></a> has quickly become a key tactic for threat actors targeting developers across a range of industries, with a <a href="https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent"><u>host of major campaigns</u></a> uncovered this year alone. </p><p>Javvad Malik, lead <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>Advisor at KnowBe4, said the frequency of these campaigns underlines the need for developers to remain vigilant when downloading packages from popular ecosystems such as npm and PyPi. </p><p>"Malicious npm packages exploit the pressures developers operate under to bring functionality features to production as quickly as possible. Much like apps on mobile phones, people will often skip over or ignore the permissions that are being asked for in exchange for quick access to the app," he said.</p><p>"Teams should lock down by default, not just npm packages, but all third party extensions and agents. Builds should be run in isolated environments and developer credentials should be treated with the same level as production admin credentials."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/malicious-urls-overtake-email-attachments-as-the-biggest-malware-threat">Malicious URLs overtake email attachments as the biggest malware threat</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">Malware as a Service explained</a></li><li><a href="https://www.itpro.com/security/a-malicious-mcp-server-is-silently-stealing-user-emails">A malicious MCP server is silently stealing user emails</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warnings ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cisco-asa-customers-urged-to-take-immediate-action-as-ncsc-cisa-issue-critical-vulnerability-warnings</link>
                                                                            <description>
                            <![CDATA[ Cisco customers are urged to upgrade and secure systems immediately ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X3RPSiT74dQsebZ52iKP2E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Sep 2025 10:29:11 +0000</pubDate>                                                                                                                                <updated>Fri, 26 Sep 2025 10:29:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:description>                                                            <media:text><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security agencies are warning that hackers are exploiting vulnerabilities in <a href="https://www.itpro.com/infrastructure/networking/everything-you-need-to-know-about-cisco">Cisco </a>Adaptive Security Appliance (ASA) 5500-X Series devices to install <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, execute commands, and steal data.</p><p>The first vulnerability, tracked as CVE-2025-20333, allows authenticated attackers to execute arbitrary code on devices using ASA and Firewall Threat Defense (FTD) software. </p><p>Meanwhile, a second vulnerability (CVE-2025-20362) allows them to access restricted URL endpoints without authentication.</p><div class="product"><a data-dimension112="e6ff6323-2156-449f-8eb6-ce8595c4e50b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="e6ff6323-2156-449f-8eb6-ce8595c4e50b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="e6ff6323-2156-449f-8eb6-ce8595c4e50b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>"In May 2025, Cisco was engaged by multiple government agencies that provide incident response services to government organizations to support the investigation of attacks that were targeting certain Cisco Adaptive Security Appliance (ASA) 5500-X Series devices that were running Cisco Secure Firewall ASA Software with <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN </a>web services enabled," the networking giant said in a <a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks" target="_blank">customer advisory.</a></p><p>"Attackers were observed to have exploited multiple zero-day vulnerabilities and employed advanced evasion techniques such as disabling logging, intercepting CLI commands, and intentionally crashing devices to prevent diagnostic analysis."</p><h2 id="cisa-ncsc-respond-to-cisco-asa-flaws">CISA, NCSC respond to Cisco ASA flaws</h2><p>According to the US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a>, the campaign is 'widespread' and connected with “ArcaneDoor” activity identified early last year</p><p>This threat campaign targeted perimeter network devices from several vendors, including Cisco, to deliver malware strains such as Line Runner and Line Dancer. </p><p>"CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service," the agency said. </p><p>The UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has also issued guidance in the wake of the exploitation. The <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>agency noted that some Cisco ASA 5500-X series models will be out of support from September 2025 and August 2026. </p><p>With this in mind, enterprises using these models should take immediate action to mitigate potential risks. </p><p>“It is critical for organizations to take note of the recommended actions highlighted by Cisco today, particularly on detection and remediation,” said NCSC <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">chief technology officer</a> Ollie Whitehouse.</p><p>“We strongly encourage network defenders to follow vendor best practices and engage with the NCSC’s malware analysis report to assist with their investigations.</p><p>“End-of-life technology presents a significant risk for organisations. Systems and devices should be promptly migrated to modern versions to address vulnerabilities and strengthen resilience.”</p><h2 id="new-malware-strains-are-a-potent-threat">New malware strains are a potent threat</h2><p>New RayInitiator and Line Viper malware strains believed to be used in attacks represent a “significant evolution” on Line Dancer and Line Runner, the NCSC warned, particularly in terms of sophistication and their ability to evade detection. </p><p>CISA has now issued a directive ordering federal agencies - which have already been targeted - to identify, analyze, and mitigate potential compromises immediately.</p><p>"CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service," it said. </p><p>"These actions are directed to address the immediate risk, assess compromise, and inform analysis of the ongoing threat actor campaign.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/infrastructure/networking/cisco-polishes-its-platform-but-the-network-is-still-king">Cisco polishes its platform but the network is still king</a></li><li><a href="https://www.itpro.com/security/cisco-cybersecurity-readiness-index-2025-ai">96% of businesses have low cyber-readiness, claims Cisco</a></li><li><a href="https://www.itpro.com/business/business-strategy/cisco-promises-ai-training-for-a-million-americans">Cisco promises AI training for a million Americans</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are disguising malware as ChatGPT, Microsoft Office, and Google Drive to dupe workers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/hackers-are-disguising-malware-as-chatgpt-microsoft-office-and-google-drive-to-dupe-workers</link>
                                                                            <description>
                            <![CDATA[ Beware of downloading applications like ChatGPT, Microsoft Office applications, and Google Drive through search engines ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SnZmFBfqnNGgurYmgttKGn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kj6pPXLf6a7yeTiX6Vk8zE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Sep 2025 10:24:39 +0000</pubDate>                                                                                                                                <updated>Tue, 23 Sep 2025 10:25:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kj6pPXLf6a7yeTiX6Vk8zE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware concept image showing flashing alert symbol with flashing red background and network symbols. ]]></media:description>                                                            <media:text><![CDATA[Malware concept image showing flashing alert symbol with flashing red background and network symbols. ]]></media:text>
                                <media:title type="plain"><![CDATA[Malware concept image showing flashing alert symbol with flashing red background and network symbols. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kj6pPXLf6a7yeTiX6Vk8zE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Small and medium-sized businesses (SMBs) across Europe and North, West, and Central Africa are being targeted by <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>masquerading as <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">legitimate tools</a>.</p><p>According to Kaspersky, cyber criminals are disguising malware and potentially unwanted applications (PUAs) as trusted tools such as <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a>, <a href="https://www.itpro.com/software/microsoft/microsoft-office">Microsoft Office</a> applications ,and <a href="https://www.itpro.com/collaboration/33418/how-to-get-more-out-of-google-drive">Google Drive</a>. </p><p>Between January and April this year, Austria, Italy, and Germany were among the hardest hit countries in Europe, with the campaign accelerating at pace. </p><div class="product"><a data-dimension112="e8daafb6-682a-4043-a708-c545af5e1a9e" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="e8daafb6-682a-4043-a708-c545af5e1a9e" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="e8daafb6-682a-4043-a708-c545af5e1a9e" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Austria accounted for 40% of all detected cases in which PUAs and malware mimicked legitimate brands, followed by Italy at 25%, Germany at 11%, and Spain (10%). Meanwhile, in Africa, Morocco topped the list, with 41% of all detected PUAs. </p><p>The most common threats affecting SMBs in Europe included backdoors (24%), Trojans (17%), and not-<em>a-virus:Downloaders</em> (16%). All of these are designed to infiltrate networks without raising suspicion, Kaspersky noted. </p><p>In Africa, not-a-virus: Downloaders dominated (55%), followed by <em>DangerousObjects </em>(14%) and <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">Trojans </a>(13%).</p><p>“Small businesses face enterprise-level threats, often with startup-level budgets," said Marc Rivero, lead security researcher at the Global Research and Analysis Team (GreAT) at Kaspersky. “The key is knowing where to focus their limited resources for maximum protection." </p><p>Kaspersky said these growing threats highlight the need for more robust <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training">employee awareness training</a>. Enabling staff to spot the telltale signs of cyber criminal activity is crucial to preventing disaster. </p><p>The company also advised enforcing strong authentication and authorization with strict password policies and <a href="https://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide">multi-factor authentication</a> (MFA), regularly updating software and patching vulnerabilities.</p><p>Meanwhile, organizations should carry out regular training sessions, focusing on safe email practices, secure password management, recognizing phishing attempts, and the proper handling of sensitive data.</p><p>All software should come from official sources – not via search engines – and be installed centrally by the IT team to prevent hidden threats. Similarly, clear access rules should be set for emails, shared folders, and online services, with user activity monitored and access revoked promptly when employees leave the company.</p><p>"The best defense against sophisticated malware isn't the most expensive tool - it's understanding how attackers think and closing the doors they're looking for,” said Rivero.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/warning-issued-as-new-pakistan-based-malware-group-hits-millions-globally">Warning issued as Pakistan-based malware group hits millions globally</a></li><li><a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">The best malware removal tools 2025</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">What is Malware as a Service and why should businesses take note?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity experts issue urgent warning amid surge in Stealerium malware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/cybersecurity-experts-issue-urgent-warning-amid-surge-in-stealerium-malware-attacks</link>
                                                                            <description>
                            <![CDATA[ Proofpoint said Stealerium has flown under the radar for some time now, but researchers have observed a huge spike in activity between May and August this year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fEHYZkKsjgE2FJgMh8FRnS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kwyhJmg3ouGdLEZpYEUPxb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Sep 2025 10:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Sep 2025 11:55:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kwyhJmg3ouGdLEZpYEUPxb-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware concept image showing a laptop with skull and crossbones on screen, symbolizing a cyber attack.]]></media:description>                                                            <media:text><![CDATA[Malware concept image showing a laptop with skull and crossbones on screen, symbolizing a cyber attack.]]></media:text>
                                <media:title type="plain"><![CDATA[Malware concept image showing a laptop with skull and crossbones on screen, symbolizing a cyber attack.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kwyhJmg3ouGdLEZpYEUPxb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity</a> researchers have issued a warning over a significant rise in the use of Stealerium <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>. </p><p>Analysis from <a href="https://www.itpro.com/security/cyber-security/361477/proofpoint-impersonator-grabs-microsoft-365-and-google-logins-in">Proofpoint</a> shows the malware strain is being used to harvest sensitive data from victims worldwide. </p><p>Pitched as being available 'for educational purposes', the <a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">infostealer</a> can exfiltrate a wide range of data, from browser credentials and crypto wallets to <a href="https://www.itpro.com/infrastructure/network-internet/369209/no-wi-fi-is-better-than-slow-wi-fi">Wi-Fi</a> profiles and VPN configurations. </p><div class="product"><a data-dimension112="61b30eae-b803-492e-b903-05346aeb42e4" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="61b30eae-b803-492e-b903-05346aeb42e4" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="61b30eae-b803-492e-b903-05346aeb42e4" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>This is achieved through multiple channels such as SMTP, Discord, Telegram, GoFile, and Zulip, researchers noted. </p><p>In some cases, it's being used for sextortion, capturing screenshots and webcam images when pornography-related content is detected in open browser tabs.</p><p>Proofpoint said Stealerium has flown under the radar for some time now, but researchers have observed a huge spike in activity between May and August this year, including campaigns linked to threat actors TA2536 and TA2715.</p><p>"Both of these actors recently favored Snake Keylogger (also known as VIP Recovery), so the use of Stealerium was notable," researchers said in a <a href="https://www.proofpoint.com/us/blog/threat-insight/not-safe-work-tracking-and-investigating-stealerium-and-phantom-infostealers" target="_blank"><u>blog post</u></a> detailing the campaigns. </p><p>"Proofpoint researchers identified additional campaigns through August 2025 that employed a variety of persuasive lures and delivery mechanisms. While most campaigns are not attributed to tracked threat actors, the initial TA2715 activity marked the first observed use of Stealerium in Proofpoint threat data in over a year."</p><h2 id="how-hackers-are-using-stealerium-malware">How hackers are using Stealerium malware</h2><p>Recent campaigns have used a wide range of <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques, researchers noted, including payment notices, legal threats, travel bookings, and adult-themed content. </p><p>These are often with compressed executables such as JavaScript, VBScript, ISO, or IMG attachments.</p><p>The team also spotted multiple campaigns leveraging travel, hospitality, and even wedding-themed lures. The subject lines generally convey urgency or financial importance, including 'Payment Due', 'Court Summons' and Donation Invoice. </p><p>In one instance, Proofpoint identified a TA2715 campaign impersonating a Canadian charitable organization with a 'request for quote' lure. The messages contained a compressed executable attachment that, when executed, downloaded and installed Stealerium. </p><p>Upon execution, Stealerium issues a series of '<em>netsh wlan</em>' commands to enumerate saved Wi-Fi profiles and nearby <a href="https://www.itpro.com/infrastructure/networking/wireless-network-cyber-attacks">wireless networks</a>. </p><p>Several campaigns also leveraged <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell">PowerShell</a> to add <a href="https://www.itpro.com/cloud/cloud-security/microsoft-defender-for-business-review-feature-filled-enterprise-security-for-small-businesses">Windows Defender</a> exclusions and used scheduled tasks for persistence and evasion. </p><p>Meanwhile, the malware has a particular feature that focuses on pornography-related data. Researchers said it is able to detect adult content-related browser tabs and takes a desktop screenshot as well as a webcam image capture. </p><p>This, researchers said, is likely to be used later for sextortion. </p><p>"While this feature is not novel among cyber crime malware, it is not often observed," the researchers said. </p><p>The company advised organizations to monitor for activity involving 'netsh wlan', suspicious use of PowerShell defender exclusions, and headless <a href="https://www.itpro.com/security/vulnerability/362243/google-chrome-zero-day-under-active-exploitation">Chrome executions</a> which are consistent with post-infection behaviors. </p><p>Similarly, they should keep an eye out for large amounts of data leaving networks, particularly to services and URLs that aren't permitted for use in the organization, or prevent outbound traffic to these services altogether. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware">Hackers are using AI to dissect threat intel reports and ‘vibe code’ malware</a></li><li><a href="https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note">Everything you need to know about Malware as a Service</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/malicious-urls-overtake-email-attachments-as-the-biggest-malware-threat">Malicious URLs overtake email attachments as the biggest malware threat</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using AI to dissect threat intelligence reports and ‘vibe code’ malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware</link>
                                                                            <description>
                            <![CDATA[ TrendMicro has called for caution on how much detail is  disclosed in security advisories ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pvKTtDch3DykNsjC8jrx2S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mXAs4UMae4KH6AzSXeDwbe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Sep 2025 07:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mXAs4UMae4KH6AzSXeDwbe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Young female hacker wearing a hooded sweatshirt working on a desktop computer in a dimly lit room with glowing lights reflecting on back of computer monitor.]]></media:description>                                                            <media:text><![CDATA[Young female hacker wearing a hooded sweatshirt working on a desktop computer in a dimly lit room with glowing lights reflecting on back of computer monitor.]]></media:text>
                                <media:title type="plain"><![CDATA[Young female hacker wearing a hooded sweatshirt working on a desktop computer in a dimly lit room with glowing lights reflecting on back of computer monitor.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mXAs4UMae4KH6AzSXeDwbe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Threat intelligence reports play a crucial role in helping enterprises keep tabs on emerging threats. These blog posts detail the tactics, techniques, and procedures (TTPs) of a threat group or dissect the makeup of a particular <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>strain. </p><p>New <a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/do-security-blogs-enable-vibe-coded-cybercrime" target="_blank"><u>research</u></a>, however, shows they could also be doing more harm than good.  According to research from Trend Micro, hackers are now using AI to analyze these reports and use them to refine their tactics. </p><p>The study showed <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">large language models (LLMs)</a> can translate technical blogs into “partial malicious code” in a dark twist on the “vibe coding” trend.</p><div class="product"><a data-dimension112="5a3f80d2-1966-4006-b3d5-de728f0982b1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="5a3f80d2-1966-4006-b3d5-de728f0982b1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="5a3f80d2-1966-4006-b3d5-de728f0982b1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>This not only allows threat actors to speed up attacks or reverse engineer malware strains, it also helps them mimic other group’s <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt">TTPs</a>, creating challenges with the attribution of attacks. </p><p>Speaking to <em>ITPro</em>, Robert McArdle, Director of Forward Threat Research at Trend Micro, said the company’s findings highlight the latest example of cyber criminals jumping on the <a href="https://www.itpro.com/software/development/vibe-coding-best-ai-models-secure-code-generation">vibe coding</a> bandwagon to wreak havoc. </p><p>“We already know that <a href="https://www.itpro.com/security/cyber-crime/anthropic-admits-hackers-have-weaponized-its-tools-and-cyber-experts-warn-its-a-terrifying-glimpse-into-how-quickly-ai-is-changing-the-threat-landscape">cyber criminals are using vibe coding</a>,” McArdle said. “We’ve seen that in their discussions on criminal forums. We’ve seen existing malware that very much looks like it was vibe coded.”</p><p>“It got us thinking, what if you can actually clone an analysis by a researcher to try to re-implement the malware from what they've described?”</p><p>McArdle told <em>ITPro </em>the company decided to test this by using <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> to dissect its own blog posts, which showed some initial promise. </p><p>“What came back was quite good,” he said. “It wasn’t the final product. It did need a little bit of tweaking to get it to work, but it certainly took a lot of work out of the way.”</p><p>This ‘lightening of the load’ is a key concern, McArdle noted. While AI tools are unlocking productivity gains for workers on the right side of the law, they’re proving equally powerful for criminals. </p><p>Worse still, these tools are helping lower the barrier to entry for up-and-coming cyber criminals and accelerating processes for those with a higher level of technical know-how. </p><p>“<a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>lets you jump from your current level of proficiency up to the next level faster,” he told <em>ITPro</em>. “So if you’re a complete novice and you know very little about code, you can vibe code a reasonably okay malware.”</p><p>“If you're already skilled and you go to an in-depth analysis of something even more advanced, then it certainly helps you get up to speed on that faster and go from those examples and have some sort of working code," McArdle continued. “So in each case it levels up the skill set of the attacker.”</p><h2 id="time-to-tone-down-the-technical-details">Time to tone down the technical details?</h2><p>Faced with this, McArdle said Trend Micro’s view on threat intelligence reports is that industry providers should consider toning down the technical details. </p><p>The company itself has taken this on board and McArdle said a key factor in releasing this research was to raise awareness and let industry counterparts know what’s going on. </p><p>“We often release these [threat intelligence reports] to raise awareness, to let people know that you know something is going on,” he said. </p><p>“Within those, it's the level of detail that you put in the post that’s the difference. We need to let people know this new attack is happening. Here's the main details you need to know to defend yourself. Here's the bigger world context, and so on,” McArdle added.</p><p>“But we probably don't always need to go down to the low-level code of ‘this is <em>exactly </em>how this was implemented, from start to finish’.”</p><p>“The more and more you go to that level, the more an AI is capable of reconstructing an approximation of the malware from it,” he said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/security-researchers-have-just-identified-what-could-be-the-first-ai-powered-ransomware-strain-and-it-uses-openais-gpt-oss-20b-model">Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain</a></li><li><a href="https://www.itpro.com/security/cyber-crime/the-rise-of-ghostgpt-why-cybercriminals-are-turning-to-generative-ai">The rise of GhostGPT – Why cybercriminals are turning to generative AI</a></li><li><a href="https://www.itpro.com/security/malware/microsoft-quietly-launched-an-ai-agent-that-can-reverse-engineer-and-detect-malware">Microsoft quietly launched an AI agent that can detect and reverse engineer malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft quietly launched an AI agent that can detect and reverse engineer malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/microsoft-quietly-launched-an-ai-agent-that-can-reverse-engineer-and-detect-malware</link>
                                                                            <description>
                            <![CDATA[ Researchers say the tool is already achieving the “gold standard” in malware classification ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VtR898d4aarv57XPHrzE4B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Aug 2025 11:52:08 +0000</pubDate>                                                                                                                                <updated>Fri, 22 Aug 2025 11:54:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LFPWMoCGDVHowHbMpHJZkU.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google. &lt;/p&gt;&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:description>                                                            <media:text><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:text>
                                <media:title type="plain"><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has launched an autonomous agent for detecting malware – and it’s already completed a first-of-a-kind detection of an active hacking group.</p><p>Project Ire is an AI agent capable of reverse engineering software files to investigate whether they’re malicious and analyze their origins, even if they don’t match any previously-cataloged threats.</p><p>Powered by a combination of <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models"><u>large language models (LLMs)</u></a> and specialized cybersecurity analysis tools, the agent is intended to automate <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> classification to ease <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>analyst <a href="https://www.itpro.com/security/uk-cybersecurity-workers-are-overworked-overwhelmed-and-burning-out-faster-than-global-counterparts-heres-why"><u>burnout</u></a>.</p><p>In recent tests, Project Ire was exposed to known samples from a database hackers have used for <a href="https://www.itpro.com/security/cyber-attacks/malware-free-attacks-threat-to-businesses"><u>living off the land attacks</u></a>, alongside harmless Windows drivers.</p><p>The agent correctly flagged 90% of all files, with only a two percent false positive rate, confirming the malicious nature of files such as a kernel-level <a href="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit"><u>rootkit</u></a> by identifying suspicious features like process termination and a web-connected <a href="https://www.itpro.com/security/hacking/368756/what-is-dark-utilities-c2-as-a-service-c2aas"><u>command and control</u></a> structure.</p><p>Microsoft researchers described its ability to blindly reverse engineer files as “the gold standard in malware classification”.</p><p>They added that Project Ire is the first reverse engineer at Microsoft to build a strong enough case against a specific <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>advanced persistent threat (APT)</u></a> malware strain to justify its automatic blocking in Windows Defender.</p><p>In a broader test, researchers exposed Project Ire to 4,000 files that were unclassified by Microsoft’s automated systems and would normally have to be reviewed by highly-skilled reverse engineers.</p><p>Project Ire achieved a precision score of 0.89, meaning 90% of the files it marked as malicious were indeed threats, alongside an overall recall score of 0.26 meaning it discovered around 25% of all the malware in the sample.</p><p>Microsoft noted the tool achieved these results autonomously, with none of the files it was exposed to having been present in its training data, adding that other autonomous tools made by Microsoft were unable to classify the files at all.</p><p>Project Ire was created as a joint project between Microsoft Research, Microsoft Defender Research, and Microsoft Discovery & Quantum.</p><h2 id="project-ire-could-shake-up-ai-malware-classification">Project Ire could shake up AI malware classification</h2><p>Malware classification is a painstaking process, in which experts pore over hundreds or thousands of files to determine whether a given piece of software has a malicious purpose.</p><p>In the past it’s been nearly impossible to automate, as AI tools can’t easily reverse engineer files without their context. They also lack the ability to definitively validate whether a file is malicious, as specific features within software could have both malicious and benign purposes. </p><p>Microsoft has attempted to overcome these limitations through Project Ire by equipping it with multi-level reasoning capabilities and the ability to call open source tools, documentation, and decompilers via <a href="https://www.itpro.com/security/the-top-api-risks-and-how-to-mitigate-them"><u>API</u></a> calls.</p><p>Every time Project Ire analyzes a file, the agent first runs triage to classify it, note its structure, and capture any other details that could point to its purpose or origin.</p><p>It then reverse engineers the file’s control flow graph, a graphic representation of a program’s execution paths, using the open source frameworks angr and Ghidra. </p><p>Project Ire can then call specific tools via an API to investigate specific functions within the file, adding each finding to an auditable chain of evidence that human analysts can check afterward to validate the LLM’s findings. </p><p>It is capable of periodically cross-checking its own claims using a built-in ‘validator’ tool, which uses expert statements from human malware reverse engineers who helped build Project Ire as context for making a final call for whether the file is malicious or benign.</p><p>This is then summarized in a final report for analyst oversight.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent">Developers face a torrent of malware threats as malicious open source packages surge 188%</a></li><li>The <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">best malware removal tools</a> for your business in 2025</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicious URLs overtake email attachments as the biggest malware threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/malicious-urls-overtake-email-attachments-as-the-biggest-malware-threat</link>
                                                                            <description>
                            <![CDATA[ With malware threats surging, research from Proofpoint highlights the increasing use of off-the-shelf 'phish kits' like CoGUI and Darcula ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MnqNyLFMRRCSCpH4xotVDV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Aug 2025 10:11:40 +0000</pubDate>                                                                                                                                <updated>Mon, 18 Aug 2025 10:12:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There's been a sharp rise in the number of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and URL-based attacks over the last year, with <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">malicious URLs</a> now being used four-times as often as attachments in email threats.</p><p>Malicious links are embedded in messages, buttons, and even within attachments like PDFs or Word documents to entice clicks that initiate credential phishing or malware downloads.</p><p>According to a <a href="https://www.proofpoint.com/us/resources/threat-reports/human-factor-url-phishing" target="_blank"><u>new report from Proofpoint</u></a>, researchers observed around 3.7 billion URL-based threats over a six month period, highlighting the growing scale of the problem. </p><p>Only 8.3 million of these threats were intended to deliver malware, however, with the most frequently-observed payloads in URL-based campaigns being <a href="https://www.itpro.com/technology/choosing-the-best-rmm-solution-for-your-msp-business">remote monitoring and management (RMM) tools</a> and remote access software (RAS). </p><p>These attacks are getting increasingly difficult for users to identify, Proofpoint noted, with cyber criminals now using advanced <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370293/ai-detection-tools-vs-generative-ai-arms-race">AI-generated content</a> to create their malicious URLs. </p><p>Not only are they <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-pdfs-to-impersonate-big-brands-like-microsoft-and-docusign-in-a-new-threat-campaign">impersonating trusted brands</a>, but also abusing legitimate services, tricking users with fake error prompts and bypassing traditional security by <a href="https://www.itpro.com/security/hackers-are-stepping-up-qishing-attacks-by-hiding-malicious-qr-codes-in-pdf-email-attachments">embedding threats in QR codes</a> and SMS messages.</p><p>"URL-based phishing threats are no longer confined to the inbox, they can be carried out anywhere and are often extremely difficult for people to identify,” said Selena Larson, senior threat intelligence analyst at Proofpoint.</p><h2 id="new-techniques-are-paying-off-for-hackers">New techniques are paying off for hackers</h2><p>Some of the URL-based credential phishing campaigns with the highest volumes in the past 12 months have been facilitated by off-the-shelf 'phish kits' like CoGUI and Darcula. </p><p>CoGUI is primarily used by Chinese-speaking threat actors, according to Proofpoint. These high-volume campaigns typically include message counts ranging from the hundreds of thousands to tens of millions at a time, and are mainly used to steal personal details such as credit card numbers.</p><p>Meanwhile, <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix malware campaigns</a> - a phishing technique that lures users into running malicious code by displaying fake error messages or CAPTCHA screens - are up by nearly 400% year-over-year. </p><p>Malware operators are exploiting the urge to resolve a perceived technical issue, helping them spread remote access trojans (RATs), infostealers and loaders.</p><h2 id="qr-code-and-smishing-threats-are-rising">QR code and smishing threats are rising</h2><p>Proofpoint also identified more than 4.2 million QR code phishing threats in the first half of 2025 alone. In these cases, the main aim of attackers is credential phishing, with 3.7 billion URL-based attacks aimed at stealing logins. </p><p>With phishing lures that impersonate trusted brands and use off-the-shelf tools such as CoGUI and Darcula phish kits, Proofpoint said even low-skilled actors can deploy highly convincing campaigns that bypass multi<a href="https://www.itpro.com/security/forget-mfa-fatigue-attackers-are-exploiting-click-tolerance-to-trick-users-into-infecting-themselves-with-malware">-factor authentication (MFA)</a> and lead to full account takeover.</p><p>The number of smishing campaigns rocketed by 2,534%, as attackers shift their focus to mobile devices - at least 55% of suspected SMS-based phishing messages analyzed by the firm contained malicious URLs, often mimicking government communications or delivery services.</p><p>“From QR codes in emails and fake CAPTCHA pages to mobile-first smishing scams, attackers are weaponizing trusted platforms and familiar experiences to exploit human psychology," said Larson. </p><p>"Defending against these threats requires multi-layered, AI-powered detection and a human-centric security strategy.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent">Developers face a torrent of malware threats as malicious open source packages surge 188%</a></li><li><a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">The best malware removal kits for small businesses</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Warning issued as new Pakistan-based malware group hits millions globally ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/warning-issued-as-new-pakistan-based-malware-group-hits-millions-globally</link>
                                                                            <description>
                            <![CDATA[ Tempting people in with offers of pirated software, the network installs commodity infostealers, according to CloudSEK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">R8wUYjv2NQWMDuhdKvRn5n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wtsGxk4n6oHAkbWZ7YpcKF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 15 Aug 2025 11:59:20 +0000</pubDate>                                                                                                                                <updated>Fri, 15 Aug 2025 11:59:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wtsGxk4n6oHAkbWZ7YpcKF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware concept image showing a shield with a red-colored, locked padlock place on top.]]></media:description>                                                            <media:text><![CDATA[Malware concept image showing a shield with a red-colored, locked padlock place on top.]]></media:text>
                                <media:title type="plain"><![CDATA[Malware concept image showing a shield with a red-colored, locked padlock place on top.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wtsGxk4n6oHAkbWZ7YpcKF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers at cybersecurity firm CloudSEK have issued a warning about a Pakistan-based <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>syndicate carrying out <a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">infostealer attacks</a> on millions of victims worldwide. </p><p>The group commands a sprawling network of operators, affiliates, and infrastructure, according to CloudSEK, adding up to a multi-million-dollar cyber crime business.</p><p>With many operators sharing the same family surname, researchers even suggested the group could be a multi-generational, family-run cyber crime outfit. </p><p>Their roles appear to be divided between primary operators - network management and finances - affiliates, generating traffic via warez sites, and financial facilitators handling payouts and settlements.</p><p>The group lures its victims in through Search Engine Optimization (SEO) poisoning and spam posted on legitimate online forums. Alongside this, the operators also ran paid ads through legitimate traffic services to drive even more users to malicious domains. </p><p>Blending malicious activity with normal web marketing traffic also made detection and takedown more difficult.</p><p>Links to cracked versions of high-demand software — such as Adobe After Effects and Internet Download Manager (IDM) — also led users to malicious WordPress sites. </p><p>“This investigation shows that cyber crime today is no longer a dark-web-only phenomenon," said Nivya Ravi, director of products at CloudSEK. </p><p>"It’s hiding in plain sight, using <a href="https://www.itpro.com/network-internet/web-hosting/368182/what-is-seo">SEO</a>, legitimate payment processors and publicly accessible forums, to operate with alarming efficiency." </p><p>The WordPress sites distributed commodity infostealers, including Lumma Stealer, Meta Stealer, and, more recently, AMOS, all of which were concealed inside password-protected archives to evade detection.</p><p>Once installed, the malware exfiltrated credentials, browser data, <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> wallets, and other sensitive information — data that was later monetized through resale and secondary fraud.</p><h2 id="a-sprawling-malware-network">A sprawling malware network </h2><p>The CloudSEK research revealed that the network involved 5,239 registered affiliates operating 3,883 malware distribution sites. Its lifetime revenue is estimated to be at least $4.67 million - although it may well be more, thanks to undocumented 'off-ledger' settlements. </p><p>Between May and October 2020 alone, the network paid out $130,560 to affiliates at an average Effective Cost Per Install (eCPI) of $0.0693. Payments were made via Payoneer in two-thirds of cases, with Bitcoin accounting for almost all the rest.</p><p>CloudSEK believes that the network may have hit 10 million victims worldwide.</p><p>"This is not a small-time hacking group — it’s an industrial-scale cybercrime enterprise that has been operating for years, infecting millions of devices across the globe," said Ravi. </p><p>"By hijacking the demand for pirated software, they have turned unsuspecting users into a steady revenue stream."</p><p>The group launched a big campaign ahead of India’s Independence Day this month, with coordinated attacks targeting the government, finance and defense sectors and including <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, <a href="https://www.itpro.com/security/22658/25-fake-government-websites-closed-down">fake websites</a>, data breaches, and scams. </p><p>CloudSEK recommends a multi-pronged disruption strategy combining domain takedowns targeting the 383 long-haul sites, as well as a financial ban in collaboration with Payoneer and other payment processors.</p><p>Similarly, the company urged for search engine de-indexing of warez sites hosting malware and user education campaigns warning about cracked software risks.</p><p>"The scale and sophistication of this network underscore the urgent need for coordinated, cross-border action to dismantle such operations before they cause irreversible damage to individuals, businesses, and critical infrastructure,” said Ravi.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent">Devs face a torrent of malware threats as malicious open source packages surge 188%</a></li><li><a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">The best malware removal tools for businesses in 2025</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malware as a service explained: What it is and why businesses should take note ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/malware-as-a-service-explained-what-it-is-and-why-businesses-should-take-note</link>
                                                                            <description>
                            <![CDATA[ What is malware as a service (MaaS), why is it so popular with adversaries, and what can businesses do to protect themselves from this growing threat? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mUwH4wnNwCz9yVPEoR73Kn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9JMkhTZBajGwt8HZPT7F7j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Jul 2025 11:41:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9JMkhTZBajGwt8HZPT7F7j-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized CGI image showing a bacteria-shaped malware with three red lights resembling traffic lights, against a dark backrgound with green, yellow, and red lights.]]></media:description>                                                            <media:text><![CDATA[A stylized CGI image showing a bacteria-shaped malware with three red lights resembling traffic lights, against a dark backrgound with green, yellow, and red lights.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized CGI image showing a bacteria-shaped malware with three red lights resembling traffic lights, against a dark backrgound with green, yellow, and red lights.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9JMkhTZBajGwt8HZPT7F7j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Advanced attack capabilities are becoming accessible to almost anyone as adversaries offer platforms that can be used by cybercriminals with little expertise. A prime example of this is malware as a service (MaaS), an out-of-the-box solution similar to software as a service (SaaS) that allows even low skilled criminals to access tools to carry out sophisticated cyberattacks.</p><p>Over the last year, MaaS has been growing in popularity. Research shows there was a <a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem"><u>distinct surge in separate malware campaigns</u></a> delivering the same payload in 2024, suggesting hackers are increasingly procuring tools from MaaS platforms.</p><p>Recent <a href="https://darktrace.com/resources/annual-threat-report-2024" target="_blank"><u>Darktrace</u></a> research found the MaaS model was responsible for 57% of all cyber threats detected in the second half of 2024, up 17% from the first half of the year. Meanwhile, a <a href="https://www.watchguard.com/wgrd-news/press-releases/internet-security-report-q3-2024" target="_blank"><u>report</u></a> from WatchGuard reported an “astronomical surge” in malware threats in the third quarter of 2024, surpassing 420,000 –  a 300% increase on the previous quarter’s figures and the largest quarterly rise it has ever observed.</p><p>So, what exactly is MaaS, why is it so popular with adversaries and what can businesses do to protect themselves against this growing threat?</p><h2 id="maas-a-subscription-based-model">MaaS – a subscription-based model</h2><p>Much like SaaS, MaaS offers a subscription-based model. This sees technically skilled developers rent out malware to other cyber criminals, who use it for malicious purposes. </p><p>MaaS offers advanced capabilities to those lacking the technical expertise to develop the tools themselves, says Boris Cipot, senior security engineer at Black Duck. “This accessibility has driven rapid growth in the MaaS market, and it continues to expand at a significant pace.”</p><p>Because attackers no longer need to develop their own malware, the barriers to entry are much lower, says Nathaniel Jones, VP, security and AI strategy at Darktrace. “Criminals can operate attacks almost like a legitimate business, processing payments and creating subscription-based or one-off payment models.”</p><p>Like legitimate services, tools on offer also receive regular updates, incorporating plugins that exploit newly-discovered vulnerabilities. </p><p>MaaS offerings are extensive and can be “highly sophisticated and structured”, says Ian Porteous, regional director of security engineering and UK&I at Check Point Software. “Many include marketplace portals on the dark web, user-friendly interfaces for managing malware campaigns – and even technical support services.”</p><p>Another benefit of MaaS to cybercriminals is the anonymity it provides, with attackers able to use the malicious tools within the platform without revealing their identity or even operating under a specific name or group.</p><p>“Payments are often made via cryptocurrency, and with profit sharing, bonuses, promotions and other partner or associate benefits further confusing the financial transaction flows,” explains Rob Vann, CSO at Cyberfort.</p><p>It is also available relatively cheaply, depending on the package. Basic malware kits can typically be rented for around £80 ($108) to £400 ($543) per month, with more complex packages costing thousands. “Despite crackdowns, MaaS persists due to anonymized transactions on dark web marketplaces and evolving tactics that exploit weaker defences in vulnerable industries,” says Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster university. </p><h2 id="ai-enhanced-maas">AI-enhanced MaaS</h2><p>The growth of MaaS is a concern on its own. But experts warn malware kits are getting better at what they do due to technology such as <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a>. This is enabling attackers to create “adaptive malware that can evade traditional security measures”, says Matt Riley, data protection and information security officer at Sharp UK and Europe. </p><p>For example, AI tools could generate payloads designed to fool antivirus and machine learning-based detection models, disguising true intent by masquerading as legitimate code, says Vann.</p><p>Porteous points to <a href="https://protect.checkpoint.com/v2/r02/___https:/cdn.openai.com/threat-intelligence-reports/disrupting-malicious-uses-of-our-models-february-2025-update.pdf___.YzJlOmNwYWxsOmM6bzo3OGRiYjNjYmJhNGNkZTdjN2JkMGVmZDMzNmIyY2I0Yzo3OmQ5NGI6NjJiZWVlZGRhZWUxZWUzZTBjYWRmNzlmODI3MWE0NWIyZWY3NzgyMTMxZDY0OGIzMDFhYjc1YjdmM2M2M2VlNjpoOlQ6Tg" target="_blank"><u>OpenAI’s February 2025 report</u></a>. “This highlights how North Korean-affiliated actors have used ChatGPT to research cyber intrusion techniques, develop <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell"><u>PowerShell</u></a> scripts for automation, and debug code for <a href="https://www.itpro.com/security/why-remote-desktop-tools-are-facing-an-onslaught-of-cyber-threats"><u>remote desktop protocol attacks</u></a>. Given these findings, it is highly likely that MaaS operators are leveraging AI in similar ways.”</p><p>One of the most immediate impacts of AI on cyber crime is its ability to generate more convincing <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year"><u>phishing attacks</u></a>, says Porteous. “Generative AI can create highly personalized phishing emails that lack the grammatical errors and other red flags that security professionals have traditionally relied on to detect scams. MaaS platforms can integrate AI-powered tools to automate and scale these phishing campaigns with unprecedented efficiency.”</p><p>In the future, AI could be used for marketing and sales, too. Although there is no real evidence of this yet, there are indications that marketplaces are starting to utilize AI to drive interactions between the most lucrative vendors and partners, says Vann. “We expect to see the use of AI to build and leverage strong MaaS platforms, establish reputations for payments, and select partner relationships, special offers and other promotions to continue to drive financial performance in this area of cybercrime.”</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/2fa90d58-bc3c-4ca0-8bcb-e4bb4fcc1297/"></iframe><h2 id="what-should-businesses-do-about-maas">What should businesses do about MaaS?</h2><p>MaaS is being used more widely than ever before and it’s easy to see why. With this in mind, businesses should ensure they are in a solid position to defend against attacks utilising the criminal model. </p><p>It starts with good <a href="https://www.itpro.com/security/cyber-requirements-stress-perspective">cyber hygiene</a>. Make sure you do the basics well, says Vann. “Ensure that you aren’t the softest target, enforce multi factor authentication (MFA) and make sure security tooling is up to date and functioning correctly.”</p><p>Meanwhile, train employees with real world examples of <a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected"><u>deepfakes</u></a>, AI-crafted phishing emails and other advanced techniques, he advises.</p><p>Layered cybersecurity strategies are “crucial”, adds Curran. “Advanced endpoint protection with AI is key to stopping smart malware. If a system does become compromised, network segmentation can limit the spread.”</p><p>Email filtering solutions should be in place and a <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna"><u>zero trust</u></a> security model will ensure no user or device is automatically trusted, say Curran. Investing in cyber threat intelligence and “a solid incident response plan” will help organizations to detect and mitigate threats faster, Curran adds.</p><p>At the same time, Curran emphasizes the importance of regularly backing up critical data offline. “This will ensure a swift and seamless recovery when – not if – an organization is attacked. This can even avoid the need to pay a ransom when critical systems are required back online quickly.”</p><p>Regularly updating and patching software to close vulnerabilities is “another vital step”, says Riley. “Cybercriminals often exploit outdated systems, and without these updates, even the most sophisticated defences can be bypassed.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Developers face a torrent of malware threats as malicious open source packages surge 188% ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/developers-face-a-torrent-of-malware-threats-as-malicious-open-source-packages-surge-188-percent</link>
                                                                            <description>
                            <![CDATA[ Researchers have identified more than 16,000 malicious open source packages across popular ecosystems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jAgGygn4ZH59PBSiZHmgQ9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Jul 2025 11:17:33 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Jul 2025 11:17:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:description>                                                            <media:text><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of <a href="https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024">open source malware</a> packages is rising fast, and security researchers are warning <a href="https://www.itpro.com/business-strategy/careers-training/356509/how-to-become-a-software-developer">software developers</a> to remain vigilant.</p><p>Software supply chain security firm Sonatype reports that it uncovered 16,279 malicious open source packages across major ecosystems, including npm and PyPI, over the last quarter.</p><p>Overall, the total volume of malware logged by the firm has surged by 188% compared with the same quarter last year.</p><div class="product"><a data-dimension112="6ad7363c-82bd-4992-b607-fe686f2aabbe" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="6ad7363c-82bd-4992-b607-fe686f2aabbe" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="6ad7363c-82bd-4992-b607-fe686f2aabbe" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>"Attackers are no longer simply experimenting with open source. The numbers are telling us that threat actors have identified data as the most profitable target, and developers as the easiest way in," said Brian Fox, CTO and co-founder of Sonatype. </p><p>“Developers and security teams must be vigilant, as threats increasingly hide in plain sight within everyday tools and dependencies.”</p><p>The main threat vector was data exfiltration, accounting for 55% of all malicious packages discovered. In the second quarter alone, Sonatype found more than 4,400 packages were specifically designed to steal sensitive data, including secrets, personally identifiable information (PII), passwords, access tokens, and API keys. </p><p>There was also a big rise in <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>focused on data corruption, which now accounts for 3% of all malicious packages, twice as many as last year. </p><p>Meanwhile, cryptomining malware accounted for 5% of all packages in the second quarter, slightly down from the previous quarter. Sonatype attributed this to a shift among attackers from resource exploitation to credential theft and long-term infiltration.</p><p>Many of the packages used advanced techniques for exfiltrating sensitive data, including exfiltrating .git-credentials, AWS secrets, and environment variables; targeting developer systems to harvest credentials used in <a href="https://www.itpro.com/development/32887/what-is-continuous-integration">CI/CD</a> pipelines; and using time-delayed payloads and encrypted transmissions to avoid detection.</p><p>"We continue to see a large volume of malware targeting environment variables, config files, and other common places used by CI/CD tools and cloud services to store sensitive information," said Sonatype principal security researcher Garrett Calpouzos. </p><p>"Once attackers collect these credentials, they can attempt unauthorized access to cloud accounts, APIs, databases, and internal systems, opening the door to broader compromise and exploitation."</p><h2 id="open-source-ecosystem-threats-are-growing">Open source ecosystem threats are growing</h2><p>The notorious <a href="https://www.itpro.com/security/malware/369189/lazarus-group-targets-macos-users-with-counterfeit-crypto-job-offers">Lazarus Group</a>, an Advanced Persistent Threat (APT) associated with the North Korean regime, was behind 107 packages, accounting for more than 30,050 known downloads. </p><p>Earlier this year, SecurityScorecard revealed that the group's latest campaign, dubbed Operation Marstech Mayhem, was based on an advanced implant named Marstech1 and designed to compromise software developers and cryptocurrency wallets through manipulated open source repositories. </p><p>By embedding its malware inside NPM packages, researchers said it made it almost impossible for developers to detect without thorough vetting. </p><p>Similarly, Fortinet warned last year it had identified thousands of malicious packages distributed across <a href="https://www.itpro.com/development/open-source/369920/350000-open-source-projects-vulnerable-15-year-old-python-bug">open source repositories</a>. </p><p>The packages included lightweight code designed to evade detection, scripts that execute malware upon installation and packages lacking repository URLs, making them harder to trace.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">Malware-free attacks surged in 2024 as attackers drop malicious software for legitimate tools</a></li><li><a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">A ‘significant increase’ in infostealer malware attacks left 3.9 billion credentials exposed to cyber criminals last year</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI is clamping down on ChatGPT accounts used to spread malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/openai-is-clamping-down-on-chatgpt-accounts-used-to-spread-malware</link>
                                                                            <description>
                            <![CDATA[ Tools like ChatGPT are being used by threat actors to automate and amplify campaigns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dvQ5V6ky8EKaaP74Xf5Upn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AM7ReJDhZZWMAqjKqACmJL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Jun 2025 10:39:03 +0000</pubDate>                                                                                                                                <updated>Mon, 09 Jun 2025 10:39:15 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AM7ReJDhZZWMAqjKqACmJL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT logo and branding pictured in white coloring against a black backdrop.]]></media:description>                                                            <media:text><![CDATA[ChatGPT logo and branding pictured in white coloring against a black backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT logo and branding pictured in white coloring against a black backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AM7ReJDhZZWMAqjKqACmJL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has taken down a host of ChatGPT accounts linked to state-sponsored threat actors as it continues to tackle malicious use of its AI tools. </p><p>The ten banned accounts, which have links to groups in China, Russia, and Iran, were used to support cyber crime campaigns, the company revealed late last week. </p><p>"By using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>as a force multiplier for our expert investigative teams, in the three months since our last report we’ve been able to detect, disrupt, and expose abusive activity including social engineering, cyber espionage, deceptive employment schemes, covert influence operations and scams," OpenAI said in a <a href="https://cdn.openai.com/threat-intelligence-reports/5f73af09-a3a3-4a55-992e-069237681620/disrupting-malicious-uses-of-ai-june-2025.pdf" target="_blank"><u>blog post</u></a> detailing the takedown. </p><p>Four of the campaigns appear to have originated in China, generating posts in English, Chinese, and Urdu that were then posted on social media sites including TikTok, X, Reddit, and Facebook.</p><p>Topics included Taiwan, specifically targeting Reversed Front, a video and board game that depicts resistance against the Chinese Communist Party, along with posts on Pakistani activist Mahrang Baloch, who has publicly criticized China’s investments in Balochistan and the closure of the US Agency for International Development (USAID).</p><p>Meanwhile, a group of ChatGPT accounts apparently operated by a Russian-speaking threat actor were banned. OpenAI said these were being used to develop and refine malware strains aimed at targeting Windows devices. </p><p>Threat actors also used the chatbot to debug code in multiple languages and to set up their command-and-control infrastructure.</p><p>Other China-linked accounts - dubbed Uncle Spam - were used to create social media posts on US politics, particularly tariffs. </p><p>"We banned ChatGPT accounts that were generating short recruitment-style messages in English, Spanish, Swahili, Kinyarwanda, German, and Haitian Creole.” the company said. “These messages offered recipients high salaries for trivial tasks — such as liking social media posts —and encouraged them to recruit others." </p><p>Sam Rubin, SVP of Unit 42 at Palo Alto Networks, said the report aligned with what its own cybersecurity specialists have been seeing in recent months. </p><p>Threat actors are increasingly flocking to AI tools to support and ramp up operations and activities, he noted. </p><p>"Attacker use of LLMs is accelerating, and as these models become more advanced, we can expect attacks to increase in speed, scale, and sophistication. It’s no surprise that threat actors — from profit-driven cybercriminals to state-sponsored groups like those aligned with China — are embracing LLMs,” Rubin commented. </p><p>“They lower the barrier to entry and dramatically improve the believability of malicious content. In one model we tested, 51 out of 123 malicious prompts slipped past safety filters — a 41% failure rate that makes it clear today’s guardrails aren’t holding the line."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/ai-enabled-cyber-attacks-exacerbated-by-digital-divide-in-uk">AI-enabled cyber attacks exacerbated by digital divide in UK</a></li><li><a href="https://www.itpro.com/security/cyber-crime/agentic-ai-cybersecurity-risks">Agentic AI could be a blessing and a curse for cybersecurity</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/executives-ai-cybersecurity-teams-vs-analysts">Executives think AI can supercharge cybersecurity teams – analysts aren’t convinced</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ It's been a bad week for ransomware operators ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/its-been-a-bad-week-for-ransomware-operators</link>
                                                                            <description>
                            <![CDATA[ A host of ransomware strains have been neutralized, servers seized, and key players indicted ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MdJgGcGovV2xMcJEhrSkNc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bBfHCREVCzyehuRCbKWheD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 May 2025 10:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bBfHCREVCzyehuRCbKWheD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing digitized padlock pictured on a laptop screen on red background]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing digitized padlock pictured on a laptop screen on red background]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing digitized padlock pictured on a laptop screen on red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bBfHCREVCzyehuRCbKWheD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hundreds of servers have been taken down as part of an international law enforcement operation against <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>groups.</p><p>Coordinated by Europol and Eurojust, the action saw key infrastructure dismantled over the last week, with 300 servers taken down, 650 domains neutralized, and nearly two dozen international arrest warrants issued.</p><p>In a statement confirming the campaign, Europol revealed more than €3.5 million in cryptocurrency was seized.</p><p>This brings the total amount netted during Operation Endgame - an ongoing, international operation against <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">ransomware services</a> and infrastructure - up to more than €21.2 million.</p><p>The operation focused on initial access <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, and neutralized the Bumblebee, Lactrodectus, <a href="https://www.itpro.com/security/ransomware/qakbot-threat-still-lingering-despite-fbi-takedown">Qakbot</a>, Hijackloader, DanaBot, Trickbot, and Warmcookie malware strains.</p><p>Arrest warrants were issued against 20 individuals believed to be providing or operating initial access services to ransomware operators.</p><p>This latest phase of <a href="https://www.itpro.com/security/europol-operation-endgame-botnet-follow-up-arrests">Operation Endgame</a> follows on from the largest-ever international action against botnets in May 2024. That targeted the new malware variants and successor groups that had re-emerged after previous takedowns.</p><p>"This new phase demonstrates law enforcement’s ability to adapt and strike again, even as cyber criminals retool and reorganize," said Europol executive director Catherine De Bolle. </p><p>"By disrupting the services criminals rely on to deploy ransomware, we are breaking the kill chain at its source."</p><p>Europol has now put out a public appeal to track down suspects who are believed to have provided or operated the ransomware tools.</p><h2 id="danabot-ransomware-criminals-snared">DanaBot ransomware criminals snared</h2><p>Meanwhile, also as part of Operation Endgame, the US Department of Justice has indicted a series of people associated with two of the ransomware groups. </p><p>Russian national Rustam Rafailevich Gallyamov, 48, is charged with leading the cyber crime group that developed and deployed the Qakbot malware. </p><p>From 2019 onward, it's alleged, Gallyamov used the Qakbot malware to infect thousands of computers around the world as part of a botnet.</p><p>Once in, he's said to have provided access to co-conspirators who infected the computers with ransomware, including Prolock, Dopplepaymer, Egregor, REvil, Conti, Name Locker, Black Basta, and Cactus. </p><p>In exchange, he allegedly received part of the ransoms received from victims.</p><p>Similarly, another 16 people have been indicted for developing and deploying the DanaBot malware, which infected more than 300,000 computers around the world for fraud and ransomware, and which caused at least $50 million in damage.</p><p>"The enforcement actions announced today, made possible by enduring law enforcement and industry partnerships across the globe, disrupted a significant cyber threat group, who were profiting from the theft of victim data and the targeting of sensitive networks," said special agent in charge Kenneth DeChellis of the Department of Defense Cyber Field Office. </p><p>"The DanaBot malware was a clear threat to the Department of Defense and our partners. DCIS will vigorously defend our infrastructure, personnel, and intellectual property."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/what-is-polymorphic-malware">What is polymorphic malware?</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/malware-free-attacks-threat-to-businesses">Malware-free attacks: The threat to businesses</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is polymorphic malware? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/what-is-polymorphic-malware</link>
                                                                            <description>
                            <![CDATA[ Polymorphic malware constantly changes its code to avoid detection, making it a top cybersecurity threat that demands advanced, behavior-based defenses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EsNfyxw6wvaK6zMfnTeDHD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L9ELEs4vTK7uviL6eLinFC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Apr 2025 19:16:01 +0000</pubDate>                                                                                                                                <updated>Wed, 30 Apr 2025 11:38:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ David Howell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RyCMPNysW5pydbG6t9n8Kh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L9ELEs4vTK7uviL6eLinFC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image showing overlapping bue, purple, red, orange, and yellow fibres representing polymorphic malware.]]></media:description>                                                            <media:text><![CDATA[An abstract image showing overlapping bue, purple, red, orange, and yellow fibres representing polymorphic malware.]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image showing overlapping bue, purple, red, orange, and yellow fibres representing polymorphic malware.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L9ELEs4vTK7uviL6eLinFC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Polymorphic malware is one of the most sophisticated threats in cybersecurity today, with the ability to constantly change its appearance unlike traditional <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> that remains static in its code structure. </p><p>Polymorphic malware is defined by its ability to alter its code or structure every time it executes while still performing the same malicious action. It typically uses tactics like <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>dynamic encryption</u></a>, code obfuscation, and randomized decryption stubs to ensure that each version of itself looks unique.</p><p>This ability to ‘mutate’, altering its own code without losing its malicious core function, allows polymorphic malware to <a href="https://www.itpro.com/security/stealthy-malware-the-threats-hiding-in-plain-sight"><u>slip past signature-based detection tools undetected</u></a>, making it a nightmare for legacy <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools"><u>antivirus systems</u></a> and a challenge even for seasoned <a href="https://www.itpro.com/business/leadership/how-leaders-can-look-after-information-security-professionals"><u>security teams</u></a>.</p><p>“The clue is in the name,” explains Rob Pocock, technology director at Red Helix. “Traditional antivirus solutions rely heavily on signature-based detection – they look for known patterns. Polymorphic malware constantly changes its code to avoid detection, so signature-based tools simply can’t keep up.”</p><p>Most consumer-grade <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus"><u>antivirus software</u></a> uses signature-based detection, which identifies malware by comparing it against a database of known code patterns. But when the malware keeps changing its appearance, this approach breaks down.</p><p>Alex Hinchliffe, a principal threat researcher at Unit 42, tells <em>ITPro</em> that polymorphic malware can modify its code with every replication. “Each time a malicious program is compiled, it yields a new unique fingerprint or hash. Add free compression or packing tools, and you get even more variation.”</p><h2 id="polymorphic-malware-is-evolving-fast">Polymorphic malware is evolving fast</h2><p>Polymorphic malware has moved far beyond manual code tweaking. Today, <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>threat groups</u></a> use automated toolkits to churn out thousands of variants at scale. Some even use <a href="https://www.itpro.com/strategy/28181/what-is-ai"><u>AI</u></a> to determine the best mutating times and methods.</p><p>As Pocock explains: “We’re seeing a sharp rise in the accessibility and sophistication of polymorphic malware. Even low-skilled attackers can use <a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem"><u>malware kits</u></a> with built-in mutation engines. AI is also being used to morph the code intelligently — maximizing stealth.”</p><p>Axel Maisonneuve, technical education contributor at BSV Association, adds that these threats now commonly use memory injection, <a href="https://www.itpro.com/security/malware/357065/what-is-fileless-malware"><u>fileless execution</u></a>, and "living-off-the-land" binaries (LOLBins), such as PowerShell and WMI. These techniques allow <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools"><u>malware</u></a> to blend in with normal system operations, reducing the chance of detection.</p><p>Aditya Sood, VP of security engineering at Aryaka, notes a similar trend. “Polymorphic malware has evolved to avoid detection using AI-driven engines, fileless techniques, and LOLBins. It’s increasingly delivered through phishing and embedded in trusted cloud services.”</p><h2 id="no-sector-is-immune-but-some-are-more-attractive">No sector is immune – but some are more attractive</h2><p>While polymorphic malware threatens every organization, attackers often focus on sectors with greater rewards or weaker defences.</p><p>"Virtually any organization could be a target," Pocock says, "but those handling sensitive or valuable data – like finance, healthcare, and government – tend to be hit more frequently."</p><p>Maisonneuve agrees, saying, “Hospitals, government agencies, banks, and critical infrastructure providers are especially at risk. They have valuable data and often complex or outdated systems. Even educational institutions are frequent targets due to underfunded cybersecurity and broad access needs.”</p><p>The threat isn't limited to major players. Any business that stores data or relies on digital operations can be a victim. With polymorphic malware being used by advanced threat actors and amateurs, a wide net is cast. No business is immune from these types of attacks.</p><h2 id="real-world-examples-of-polymorphic-malware">Real-world examples of polymorphic malware</h2><p>Several high-profile malware campaigns have used polymorphism to devastating effect. One of the earliest examples was the <a href="https://www.itpro.com/153711/storm-worm-targets-barclays-halifax-customers"><u>Storm Worm</u></a>, which emerged in 2007. More recently, malware like <a href="https://www.itpro.com/security/hacking/361340/what-is-emotet"><u>Emotet</u></a>, <a href="https://www.itpro.com/security/ransomware/360101/diavol-ransomware-linked-to-trickbot-botnet"><u>TrickBot</u></a>, <a href="https://www.itpro.com/security/24870/click-fraud-becomes-entry-route-for-ransomware-attacks"><u>CryptoWall</u></a>, and <a href="https://www.itpro.com/security/cyber-crime/370041/ryuk-conti-ransomware-members-uk-sanctions-crackdown"><u>Ryuk ransomware</u></a> have demonstrated the power of polymorphic techniques.</p><p>“Storm Worm was among the first to use large-scale automated polymorphism,” notes  Sood. “CryptoWall changed payloads dynamically. And Emotet evolved into a polymorphic botnet, constantly morphing to avoid detection.”</p><p>Maisonneuve emphasizes that polymorphism was key to the success of these campaigns. “Emotet and TrickBot used polymorphic loaders and encryption stubs to slip past security tools. Ryuk was often dropped via these polymorphic channels, showing how effective these techniques are.”</p><p>One newer example is <a href="https://www.itpro.com/security/ais-use-as-a-hacking-tool-has-been-overhyped"><u>BlackMamba</u></a>, a polymorphic malware created using <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai"><u>generative AI</u></a>. This underscores how AI can now be used offensively to engineer malware that adapts faster than human defenders can keep up.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/085cb084-22ca-44af-8162-059d36a4d754"></iframe><h2 id="defending-against-polymorphic-malware">Defending against polymorphic malware</h2><p>A defense strategy based solely on signature detection is no longer enough. Experts unanimously agree that effective protection comes from layering multiple tools and practices together.</p><p>“Businesses need a multi-pronged, defence-in-depth approach,” said Oliver Fay, EMEA threat research lead at Accenture. “This includes technical hardening through strong <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management"><u>patch management</u></a> and layered controls, and <a href="https://www.itpro.com/security/human-error-is-cybersecuritys-number-one-concern-kaseya-report-finds"><u>human resilience</u></a> through user training.”</p><p>“Defenders must rely on dynamic analysis – like sandboxing or behavior monitoring – to catch it in the act,” says Maisonneuve. These methods observe what a program does rather than how it looks, which is key for spotting ever-changing threats.</p><p>Key recommendations from cybersecurity experts include:</p><ul><li>Use behavior-based detection. Rather than looking for a specific signature, these tools focus on what a program does — such as deleting <a href="https://www.itpro.com/storage/29803/best-backup-software"><u>backups</u></a> or injecting into system processes — which are strong indicators of malicious intent.</li><li><a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>Adopt a zero trust</u></a> model. Strict access controls and constant verification of users and devices reduce the chance of lateral movement after an initial breach.</li><li>Invest in email and network protection. Most attacks still begin with phishing. Techniques like <a href="https://www.itpro.com/security/phishing/359702/what-is-dmarc-and-how-can-it-improve-your-email-security"><u>DMARC enforcement</u></a>, sandboxing, and network segmentation can limit the scope of an attack.</li><li>Prioritize patching and updates. Unpatched systems are an open invitation to attackers. Automate updates whenever possible.</li><li><a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness"><u>Train your staff</u></a>. Simulate phishing, teach file hygiene, and ensure users recognize signs of compromise.</li></ul><p>Sood also emphasizes the role of <a href="https://www.itpro.com/security/building-an-incident-response-strategy"><u>incident response</u></a>. “Automation and well-rehearsed plans are critical. Security teams must be ready to detect, investigate, and contain threats quickly.”</p><p>AI and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning"><u>machine learning</u></a> are also proving especially effective in this fight. “These technologies can detect command-and-control activity, analyze process behavior, and scale response efforts dramatically,” said Hinchliffe. “They’re turning what used to be weeks of detection into real-time prevention.”</p><p>Polymorphic malware isn't science fiction, but a daily reality. Attackers constantly evolve their tools to bypass traditional defenses, and static signature-based systems aren't enough anymore. As Maisonneuve succinctly tells <em>ITPro</em>: “The mouse is constantly changing shape. If your defenses don’t adapt, you’re playing a losing game.”</p><p>Businesses must rethink their approach: shift from reactive to proactive, from static scans to dynamic monitoring, and from single-layer tools to integrated defense systems. And with attackers increasingly using automation and AI, defenders must follow suit.</p><p>Ultimately, protecting against polymorphic malware means moving beyond what malware looks like and focusing on what it does. That shift – supported by the right tools, processes, and people – is the only way to stay ahead of this fast-moving threat.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using Zoom’s remote control feature to infect devices with malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-using-zooms-remote-control-feature-to-infect-devices-with-malware</link>
                                                                            <description>
                            <![CDATA[ Security experts have issued an alert over a new social engineering campaign using Zoom’s remote control features to take over victim devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m5BG2PenTC4nHGhF3tsKeH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Apr 2025 09:07:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have issued an alert over a new social engineering campaign using Zoom’s remote control features to take over victim devices. </p><p>In a <a href="https://blog.trailofbits.com/2025/04/17/mitigating-elusive-comet-zoom-remote-control-attacks/" target="_blank"><u>report from Trail of Bits</u></a>, researchers attributed the campaign to a cyber criminal group known as ‘Elusive Comet’, which attempted to target the company’s CEO on social media. </p><p>The campaign in question centers around abusing the video conferencing software’s remote control feature, which allows participants to take control of another users’ computer. </p><p>In a blog post detailing the CEO’s exchange with the group, the firm said the attack started with an invitation to appear on ‘Bloomberg Crypto’ as part of an interview. </p><p>These invitations were sent via social media or email, using phony email addresses mimicking official Bloomberg accounts belonging to journalists. Notably, invitations were sent via Calendly links, the company said, which are intended to lure the victim under the guise of authenticity. </p><p>“Two separate Twitter accounts approached our CEO with invitations to participate in a “Bloomberg Crypto” series—a scenario that immediately raised red flags,” the firm said in a blog post. </p><p>“The attackers refused to communicate via email and directed scheduling through Calendly pages that clearly weren’t official Bloomberg properties. These operational anomalies, rather than technical indicators, revealed the attack for what it was.”</p><p>Trail of Bits identified a number of accounts linked to the campaign and warned organizations to update monitoring systems to include these new indicators.</p><p>These included:</p><ul><li>X: @KOanhHa</li><li>X: @EditorStacy</li><li>Email: bloombergconferences[@]gmail.com</li><li>Zoom URL: https://us06web[.]zoom[.]us/j/84525670750</li><li>Calendly URL: calendly[.]com/bloombergseries</li><li>Calendly URL: calendly[.]com/cryptobloomberg</li></ul><h2 id="zoom-attack-relies-on-user-trust">Zoom attack relies on user trust</h2><p>Trail of Bits warned that with the campaign relying on a feature in a legitimate service, it could pose a serious risk to unwitting users. </p><p>Upon entering a call with the threat actors, they change display names to ‘Zoom’ to make the request “appear as a system notification”. If granted access, the attacker can assume control of the victim’s device to install <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, exfiltrate data, or steal cryptocurrency. </p><p>“What makes this attack particularly dangerous is the permission dialog’s similarity to other harmless <a href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now">Zoom </a>notifications,” the firm said. “Users habituated to clicking “Approve” on Zoom prompts may grant complete control of their computer without realizing the implications.”</p><p>Max Gannon, Intelligence Manager at Cofense, echoed Trail of Bits’ comments on the campaign, noting that the use of legitimate software by cyber criminals has become a serious problem for enterprises. </p><p>“The malicious use of legitimate software is a growing trend we've continued to see in 2025,” he said.</p><p>“In this case, threat actors are leveraging legitimate Zoom and Calendly links to bypass security controls. As trusted domains, their use in this attack makes it more difficult to detect and block."</p><p>Analysis from Mimecast earlier this year highlighted the growing threat posed by cyber criminals using legitimate services in attack chains. In its most recent threat intelligence report, the firm flagged more than 5 billion threats in the second half of 2024 alone, with <a href="https://www.itpro.com/security/cyber-crime/threat-actors-are-leaning-on-trusted-services-more-than-ever"><u>‘living off trusted services’ (LOTS) attacks a key cause for concern</u></a>. </p><p>Also known as <a href="https://www.itpro.com/security/cyber-attacks/malware-free-attacks-threat-to-businesses"><u>malware-free attacks</u></a>, this approach is useful in helping cyber criminals circumvent authentication practices at target organizations, the study noted.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses">Infostealer malware: What’s the threat to businesses?</a></li><li><a href="https://www.itpro.com/security/forget-mfa-fatigue-attackers-are-exploiting-click-tolerance-to-trick-users-into-infecting-themselves-with-malware">Forget MFA fatigue, attackers are exploiting ‘click tolerance’ to trick users into infecting themselves with malware</a></li><li><a href="https://www.itpro.com/security/malware/369299/zoom-themed-cyber-attacks-fuel-rapid-malware-growth">Zoom-themed cyber attacks fuel rapid malware growth</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are duping developers with malware-laden coding challenges ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-duping-developers-with-malware-laden-coding-challenges</link>
                                                                            <description>
                            <![CDATA[ A North Korean state-sponsored group has been targeting crypto developers through fake coding challenges given as part of the recruitment process. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wpDxx4XidWpG6V8wQi3DyE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZCsZjR3vKiA3rUPRWJ84EC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Apr 2025 09:51:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZCsZjR3vKiA3rUPRWJ84EC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand on a keyboard in a dark room]]></media:description>                                                            <media:text><![CDATA[A hand on a keyboard in a dark room]]></media:text>
                                <media:title type="plain"><![CDATA[A hand on a keyboard in a dark room]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZCsZjR3vKiA3rUPRWJ84EC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A North Korean state-sponsored hacker group has been targeting crypto developers through coding challenges as part of a fake recruitment process.</p><p>Posing as recruiters on LinkedIn, the Slow Pisces group asks developers to participate in compromised Python and <a href="https://www.itpro.com/development/30202/what-is-javascript-and-why-should-i-learn-it">JavaScript </a>projects, infecting their systems using custom <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and leveraging <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>repositories.</p><p>Analysis from Unit 42, Palo Alto Networks’ threat intelligence wing, shows the group mainly used projects in <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer">Python </a>or JavaScript - probably depending on whether the target applied for a <a href="https://www.itpro.com/business-strategy/careers-training/358369/front-end-developer-career-guide-7-skills-a-front-end">front-end or back-end development role</a>. There were also a couple of Java-based repositories, researchers found. </p><p>The hackers are using two newly discovered malware strains, RN Loader and RN Stealer, along with new evasion techniques including YAML deserialization and EJS escapeFunction.</p><p>RN Loader sends basic information about the victim's device and operating system over <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">HTTPS </a>to the group's C2 server, while RN Stealer is an infostealer that exfiltrates data and compressed data.</p><p>Distribution of the malware is tightly controlled, going only to carefully validated targets based on factors such as their IP address, their location, time and HTTP headers.</p><p>"We have observed Slow Pisces impersonating several organizations with these lures, primarily in the <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency </a>sector," <a href="https://unit42.paloaltonetworks.com/slow-pisces-new-custom-malware/" target="_blank"><u>said</u></a> Unit 42. </p><p>"Slow Pisces presented targets with so-called coding challenges as projects from GitHub repositories. The repositories contained code adapted from <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> projects, including applications for viewing and analyzing stock market data, statistics from European soccer leagues, weather data, and cryptocurrency prices."</p><h2 id="everything-you-need-to-know-about-the-slow-pisces-group">Everything you need to know about the Slow Pisces group</h2><p>Slow Pisces - also known as Jade Sleet, TraderTraitor and Pukchong - has been linked to a number of high-profile cryptocurrency thefts, having reportedly stolen over $1 billion from the cryptocurrency sector in 2023. </p><p>Their methods included fake trading applications, malware distributed via the <a href="https://www.itpro.com/infrastructure/network-internet/354619/solarwinds-npm-20194-review-a-monitoring-masterclass">Node Package Manager (NPM)</a>, and supply chain compromises.</p><p>In December 2024, the FBI attributed the theft of $308 million from a Japan-based cryptocurrency company to the group, and it was also allegedly involved in the theft of $1.5 billion from a Dubai cryptocurrency exchange.</p><p>Unit 42 said it shared its findings with GitHub and LinkedIn, both of which have removed the malicious accounts and repositories.</p><p>"Based on public reports of cryptocurrency heists, this campaign appears highly successful and likely to persist in 2025," said Unit 42. </p><p>"The most effective mitigation remains strict segregation of corporate and personal devices. This helps prevent the compromise of corporate systems from targeted social engineering campaigns."</p><h2 id="north-korean-hackers-are-on-a-roll">North Korean hackers are on a roll</h2><p>This is just the latest in a series of North Korean campaigns based around fake recruitment. More usually, the technique is for the criminals to pose as job applicants.</p><p>Research shows they've been infiltrating organizations in both the US and Europe to raise money for the North Korean regime, steal proprietary data, install malware on corporate systems, and demand <a href="https://www.itpro.com/security/ransomware/the-end-of-ransomware-payments-how-businesses-fit-into-the-fight">ransom payments</a>.</p><p>The rise of <a href="https://www.itpro.com/security/fbi-issues-guidance-for-enterprises-as-fake-north-korean-it-workers-wreak-havoc">fake IT workers</a> has prompted security agencies to issue several warnings over the growing risks faced by enterprises. Some victims have been vocal about the issue, including <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>training firm KnowBe4, which <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think"><u>revealed last year it had been duped by a threat actor posing as an IT worker</u></a>. </p><p>Similarly, the techniques highlighted by Unit 42 are by no means novel. Threat groups such as Alluring Pisces and Contagious Interview have also exploited LinkedIn to target jobseekers. </p><p>Recent analysis from Bitdefender shows the social networking platform has <a href="https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks"><u>become a prime hunting ground for cyber criminals</u></a>, with a host of groups leveraging the platform to dupe unsuspecting users. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/google-warns-that-fake-north-korean-it-workers-have-expanded-to-europe">Google warns that fake North Korean IT workers have expanded to Europe</a></li><li><a href="https://www.itpro.com/security/disgruntled-dev-malicious-code-insider-threat">A developer crippled company networks with malicious code and a ‘kill switch’ after being sacked</a></li><li><a href="https://www.itpro.com/software/want-developers-to-build-secure-software-you-need-to-ditch-these-two-programming-languages">Want developers to build secure software? You need to ditch these two programming languages</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 – and experts warn it’s lowering the barrier of entry for amateur hackers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web</link>
                                                                            <description>
                            <![CDATA[ Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qsveyM9EvfU5jiXfZRPQk8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Apr 2025 11:58:06 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Apr 2025 12:03:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:description>                                                            <media:text><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:text>
                                <media:title type="plain"><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While inflation is rising around the world, some things are getting cheaper - and one is the cost of launching a phishing attack.</p><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing</a> kits are now widely available on the <a href="https://www.itpro.com/security/the-dark-web-is-absolutely-awash-with-stolen-data-on-british-mps">dark web</a> and via messaging apps like Telegram, and are often selling for less than $25. </p><p>This means that even criminals with minimal tech skills can easily steal personal information, carry out identity theft and access bank accounts. Meanwhile, <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>infections can lead to the complete loss of device control, enabling cyber criminals to steal files, encrypt sensitive data, or launch <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attacks.</p><p>"Phishing kits are a force multiplier for cyber crime. They put powerful attack tools into the hands of people who may not have the skills to build them on their own," said Adrianus Warmenhoven, a cybersecurity expert at <a href="https://www.itpro.com/vpns/27145/nordvpn-review">NordVPN</a>. </p><p>"With features like drag-and-drop website builders, email templates, and even contact lists, these kits enable even the least technical attackers to carry out professional-looking scams."</p><h2 id="phishing-as-a-service-is-booming">Phishing as a Service is booming</h2><p>Meanwhile, subscription-based Phishing as a Service (PhaaS) is also on the rise, with these services handling everything from hosting to victim targeting.</p><p>“Phishing kits and PhaaS platforms lower the barrier to entry, so we’re seeing a surge in the number and variety of attacks. That means consumers need to be more alert than ever," said Warmenhoven.</p><p>The research team <a href="https://nordvpn.com/research-lab/online-threats-statistic/"><u>found</u></a> that last year's most commonly impersonated brands in phishing attacks were Google, Facebook, and Microsoft - and that fake URLs imitating these popular platforms are a primary method for cyber criminals to harvest credentials. </p><p>Nearly 85,000 fake Google URLs were discovered last year.</p><p>Similarly, .exe, .zip, .php, .dll and .pdf were the riskiest extensions when downloading files. Video hosting, entertainment and sports, meanwhile, were the domain categories with the most malware.</p><p>According to <a href="https://blog.barracuda.com/2025/03/19/threat-spotlight-phishing-as-a-service-fast-evolving-threat" target="_blank"><u>research</u></a> from Barracuda Networks, the first quarter of this year showed a massive spike in phishing, with more than a million attacks detected by the firm's systems in January and February.</p><p>Tycoon 2FA was the most prominent - and sophisticated - platform, accounting for 89% of incidents in January 2025. Next came EvilProxy, with a share of 8%, followed by a new contender, Sneaky 2FA, with a 3% share of attacks.</p><p>To stay safe, Warmenhoven recommended constantly checking suspicious links for misspellings or inconsistencies before clicking, avoiding free video hosting sites, and enabling multi-factor authentication.</p><p>"Be cautious of unsolicited emails, especially those offering deals or urgent requests. Always verify the legitimacy of files before downloading and use anti-malware tools to scan them," he said.</p><p>"Protect your privacy using tracker blockers to block personal data collection, and ensure your devices are regularly updated to close security vulnerabilities."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-crime/afds-phishing-campaign-microsoft">A new phishing campaign is exploiting Microsoft’s legacy ADFS identity solution to steal credentials and bypass MFA</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/phishing/device-code-phishing-storm-2372-microsoft">Hackers are using this new phishing technique to bypass MFA</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Seized database helps Europol snare botnet customers in ‘Operation Endgame’ follow-up sting ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/europol-operation-endgame-botnet-follow-up-arrests</link>
                                                                            <description>
                            <![CDATA[ Europol has detained several people believed to be involved in a botnet operation as part of a follow-up to a major takedown last year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vsdWMViFBLwKPaWxpsCreJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Apr 2025 12:02:51 +0000</pubDate>                                                                                                                                <updated>Thu, 10 Apr 2025 18:37:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:description>                                                            <media:text><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:text>
                                <media:title type="plain"><![CDATA[Europol logo and badge pictured on the exterior of the Europol headquarters in The Hague, Netherlands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/X8SLtm2YmMKNBeG8ZeCDXf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Europol has detained several people believed to be involved in a <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnet </a>operation as part of a follow-up to a major takedown last year. </p><p>Following the <em>Operation Endgame</em> investigation, major malware droppers including IcedID, SystemBC, Pikabot, Smokeloader and Bumblebee, were shut down last year.</p><p>According to Europol, analysis of the contents of a seized database enabled it to identify customers of the SmokeLoader pay-per-install botnet, operated by an individual known as <em>‘Superstar’</em>.</p><p>The law enforcement agency has now made arrests, carried out house searches, and conducted arrest warrants or ‘knock and talks’. </p><p>"Superstar used his botnet to run a pay-per-install service, enabling customers to gain access to victims’ machines. Customers used the service to deploy malware for their own criminal activities," Europol said. </p><p>"Investigations revealed that botnet access was purchased for a range of purposes, including keylogging, webcam access, <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>deployment, cryptomining and more. Law enforcement tracked down the customers as they were registered in a database seized during Operation Endgame." </p><p>The <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>had infected millions of computers around the world, according to the FBI. SystemBC facilitated anonymous communication between an infected system and a command-and-control servers.</p><p>Meanwhile, Bumblebee was distributed mainly via phishing campaigns or compromised websites, and was designed to enable the delivery and execution of further payloads on compromised systems.</p><p>SmokeLoader was mainly used as a downloader to install additional malicious software onto the systems it infected. Similarly, IcedID - also known as BokBot - had been further developed to carry out a range of crimes as well as the theft of financial data. </p><h2 id="europol-hails-success-of-largest-botnet-takedown">Europol hails success of largest botnet takedown</h2><p>As part of last year's operation - the largest ever against a botnet - more than 100 servers were shut down or disrupted and over 2,000 internet domains tied to the hacking activities were seized. </p><p>But while last May's activities were focused on the high-level players who were using ransomware, for example, this latest set of raids is designed to mop up the customers of Cybercrime as a Service providers.  </p><p>Law enforcement agencies in several countries were able to link online personas and their usernames to actual individuals. </p><p>"When called in for questioning, several suspects chose to cooperate with the authorities by facilitating the examination of digital evidence stored on their personal devices," Europol said. </p><p>"Several suspects resold the services purchased from SmokeLoader at a markup, thus adding an additional layer of interest to the investigation."</p><p>Europol said it’s not quite finished yet, either. The law enforcement agency is still investigating possible leads, revealing it has more suspects in the crosshairs. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/botnets-are-being-sold-on-the-dark-web-for-as-little-as-dollar99">Botnets are being sold on the dark web for as little as $99</a></li><li><a href="https://www.itpro.com/security/cyber-crime/cobalt-strike-takedown-fortra-microsoft">Cobalt Strike abusers have been dealt a hammer blow</a></li><li><a href="https://www.itpro.com/security/cyber-crime/the-zservers-takedown-is-another-big-win-for-law-enforcement">The Zservers takedown is another big win for law enforcement</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This potent malware variant can hijack your Windows PC, steal passwords, and more: Neptune RAT is spreading on GitHub, Telegram, and even YouTube – and experts warn 'anyone could use it to launch attacks'  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/neptune-rat-malware-growth</link>
                                                                            <description>
                            <![CDATA[ Neptune RAT can hijack Windows PCs and steal passwords – and it's spreading fast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PizbTrVZ9Uhbkvh2u8RVqC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Apr 2025 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:description>                                                            <media:text><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:text>
                                <media:title type="plain"><![CDATA[Neptune RAT malware concept image showing a skull and crossbones in binary code against a red colored backdrop.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mP59D9NhKL5dmDvk5CMAzZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new version of the Neptune RAT malware has emerged, security researchers have warned, and is spreading on GitHub, Telegram, and even YouTube. </p><p>The remote access trojan is 'an extremely serious threat' being offered on the ransomware-as-a-service model, according to researchers at <a href="https://www.cyfirma.com/research/neptune-rat-an-advanced-windows-rat-with-system-destruction-capabilities-and-password-exfiltration-from-270-applications/"><u>Cyfirma</u></a>.</p><p>Affecting <a href="https://www.itpro.com/software/microsoft/windows">Windows </a>devices, it hijacks Chromium-based browsers including Chrome, Brave, and Opera using a Chromium.dll attack that decrypts stored login data and installs itself as a scheduled Windows task.</p><p>It includes a crypto clipper and a <a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses">password stealer</a> with the ability to exfiltrate the credentials of more than 270 different applications, along with ransomware capabilities and live desktop monitoring.</p><p>Advanced anti-analysis techniques and persistence methods, such as modifying the Windows Registry and adding tasks to the Task Scheduler, mean it can maintain its presence on the victim’s system for extended periods of time.</p><p>"The analysis of the latest version of Neptune RAT reveals a sophisticated and highly dangerous piece of <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>designed for persistent, covert operations on Windows systems," Cyfirma researchers said. </p><p>"Its ability to generate direct PowerShell commands (using irm and iex) enables seamless delivery and execution, effectively bypassing traditional security measures. It also has the capability to destroy Windows OS and features advanced password-grabbing functionalities."</p><h2 id="neptune-rat-lowers-the-bar-for-cyber-criminals">Neptune RAT lowers the bar for cyber criminals</h2><p>The new version has been made available without the source code, making analysis more challenging. Notably, it's being offered via an unusual model, with the developer claiming that while it's free to use, there's a more advanced version behind a paywall.</p><p>Chris Hauk, consumer privacy advocate at Pixel Privacy, said the emergence of the new Neptune RAT variant shows the “try it before you buy it era of malware has arrived”. </p><p>“Neptune RAT is available as a download from <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a>, making it available to a wider variety of internet users than usual," he said. </p><p>"As antivirus and anti-malware apps have not yet been able to detect and remove Neptune RAT, internet users will need to stay alert and practice safe computing by not clicking on links or opening attachments that are shared by unknown users."</p><p>Paul Bischoff, consumer privacy advocate at Comparitech, echoed Hauk’s comments, noting that the accessibility of the variant will have wide-reaching implications for consumers and enterprises alike and lower the barrier of entry for cyber criminals. </p><p>"The maker of Neptune RAT is giving their malware out for free, so it's not just one hacker group we need to worry about," he said.</p><p>"Anyone could use it to launch attacks through email, text, ads, or download links. Once the malware has infected a system, it is extremely destructive, dangerous, and hard to remove."</p><p>Given its anti-detection features, the new Neptune RAT version is hard to avoid, Cyfirma researchers said, adding that this poses a “significant risk to both individuals and organizations”.</p><p>"Continuous monitoring, robust endpoint protection, and proactive threat detection strategies are crucial to mitigating the impact of this malware."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/small-businesses-face-continued-security-threats-as-trojan-attacks-surge">Small businesses face continued security threats as trojan attacks surge</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li><li><a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">Malware-free attacks surged in 2024 as attackers drop malicious software for legitimate tools</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Warning issued over ‘fast flux’ techniques used to obscure malicious signals on compromised networks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/warning-issued-over-fast-flux-techniques-used-to-obscure-malicious-signals-on-compromised-networks</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity agencies have issued a stark message that too little is being done to sniff out malware hiding in corporate networks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u8XbEY7Mt6secUMHHeuVKT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LBK4xgJuLRTpzeH9RiQXvY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Apr 2025 10:57:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ rory.bathgate@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rory Bathgate is the Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He is a subject expert on artificial intelligence and business networks but in his time at ITPro has also covered a wide range of areas including cyber security and hardware. Throughout his time at ITPro, Rory has charted the rise in popularity of generative AI and specifically companies such as Microsoft, OpenAI, and Google.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Alongside this, he has delved into increasing calls for ethical and responsible AI as global legislators circle the technology, as well as the latest in mobile networking technology, from 5G mmWave to the 3G sunset and how it will affect businesses.&lt;/p&gt;
&lt;p&gt;He has provided coverage from high-profile tech conferences such as Dell Technologies World, SuiteWorld, and VMware Explore Europe. His on-the-ground coverage has included live blogs, extensive daily coverage of the most significant announcements, analysis pieces, and podcasts.&lt;/p&gt;
&lt;p&gt;Indeed, Rory is also a full-time co-host of the ITPro Podcast alongside Jane McCallion, where he swaps a keyboard for a microphone to discuss the latest learnings in tech. Each week, a guest comes onto the show to discuss topics such as cyber security, productivity, or digital transformation in detail.&lt;/p&gt;
&lt;p&gt;Rory has an MA in Eighteenth-Century Studies from King’s College London, as well as a BA in English and American Literature from the University of Kent. He joined ITPro in 2022 as a graduate, after four years in student journalism.&lt;/p&gt;
&lt;p&gt;In his free time, Rory enjoys photography and video editing, and can often be found at the cinema or reading a good science fiction paperback.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LBK4xgJuLRTpzeH9RiQXvY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Internet security, virus, big data hacking and malware concept with blurred blue binary code in form of skull symbol on dark background.]]></media:description>                                                            <media:text><![CDATA[Internet security, virus, big data hacking and malware concept with blurred blue binary code in form of skull symbol on dark background.]]></media:text>
                                <media:title type="plain"><![CDATA[Internet security, virus, big data hacking and malware concept with blurred blue binary code in form of skull symbol on dark background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LBK4xgJuLRTpzeH9RiQXvY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations are at risk of falling prey to a common network vulnerability that allows threat actors to evade detection and spread malware with impunity, law enforcement agencies have warned.</p><p>‘Fast flux’ is a domain-based technique used to hide communications sent by malware to its command and control (C2) infrastructure – the malicious servers that send out updates and new directions to malware on infected devices.</p><p>It works by repeatedly changing the <a href="https://www.itpro.com/domain-name-system-dns/30228/what-is-dns"><u>DNS records</u></a> for the C2 infrastructure so that no one domain is easily identifiable by the victim’s cybersecurity team.</p><p>Constantly shifting IP addresses also means that even if one is flagged as malicious and blocked, the malware can easily contact the C2 again through any number of other addresses.</p><p>To make matters harder for cybersecurity teams, the commands sent to the malware are often relayed via <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet"><u>botnets</u></a>, a swarm of infected devices. This further muddies the water when it comes to tracing signals, giving the hackers behind the C2 an extra layer of anonymity.</p><p>A more intensive method known as ‘double flux’ sees threat actors also swap out the DNS name servers used to store records for their malicious site, as an additional protection against being discovered by law enforcement.</p><p>Fast flux allows threat groups to cycle out IP addresses as many as several hundred times in a day, severely limiting the capability of security teams to pin down their malicious communications. </p><h2 id="fast-flux-techniques-are-being-used-to-devastating-effect">‘Fast flux’ techniques are being used to devastating effect</h2><p>The use of fast flux techniques have been observed in <a href="https://www.itpro.com/security/ransomware/us-government-offers-dollar10-million-reward-in-bid-to-track-down-hive-ransomware-leaders"><u>Hive ransomware activity</u></a>, by other <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware groups</u></a> as well as <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier"><u>state-sponsored</u></a> entities such as the Russian <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>advanced persistent threat (APT)</u></a> group, <a href="https://www.microsoft.com/en-us/security/security-insider/aqua-blizzard"><u>Aqua Blizzard</u></a>. </p><p>The methods were laid out in an advisory issued by the <a href="https://www.itpro.com/security/what-is-cisa"><u>Cybersecurity and Infrastructure Security Agency (CISA)</u></a> alongside the National Security Agency (NSA) and Federal Bureau of Investigation (FBI).</p><p>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), Canadian Centre for Cyber Security (CCCS), and New Zealand’s National Cyber Security Centre (NCSC-NZ) also issues the joint warning.</p><p>The combined law enforcement agencies noted that fast flux is also used to prevent authorities from disabling <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself"><u>social engineering</u></a> websites and to keep hacking forums online. </p><h2 id="fighting-fast-flux">Fighting fast flux</h2><p>To mitigate the threat posed by these techniques, security experts urged all organizations to adopt protective domain name system (PDNS) services, which come with features such as DNS sinkholing. </p><p>This allows security teams to intercept and block malicious DNS requests, thereby stemming the flow of attacks and flagging infected.</p><p>PDNS services also offer advanced monitoring, filtering, and analysis. It is available via a range of providers, as well as free of charge to select services in the UK via the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>.</p><p>“Fast flux is an ongoing, serious threat to national security, and this guidance shares important insight we’ve gathered about the threat,” said Dave Luber, NSA Cybersecurity Director. </p><p>“It is imperative <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>providers, especially Protective DNS providers, follow these guidelines to safeguard critical infrastructure and sensitive information.”</p><p>In addition to their advice for all organizations, the combined agencies provided cybersecurity service providers (CSPs) and internet service providers (ISPs) with a number of techniques known to produce good results against fast flux.</p><p>This included greater reliance on intelligence feeds to flag malicious domains, better use of anomaly detection to detect domains with unusually diverse IP addresses or geolocation data, and to create advanced <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm"><u>algorithms</u></a> that can match anomalous behavior with fast flux methodology.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cisa-breached-a-federal-agency-as-part-of-its-red-team-program-and-nobody-noticed-for-five-months">CISA breached a federal agency as part of its red team program — and nobody noticed for five months</a></li><li><a href="https://www.itpro.com/security/why-cisa-is-extending-cyber-support-to-resource-poor-organizations">Why CISA is extending cyber support to ‘resource poor’ organizations</a></li><li><a href="https://www.itpro.com/security/ransomware/medusa-ransomware-cisa-advisory">CISA issues warning over Medusa ransomware after 300 victims from critical sectors impacted</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Infostealer malware: What’s the threat to businesses? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses</link>
                                                                            <description>
                            <![CDATA[ To counter the rising threat of infostealer malware,  security teams must be vigilant and practice rigorous patching ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">W4VfSWQZrJEL7sCgCz5kJ8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gk766rgmc5xqmYdCEvHAJf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Mar 2025 10:55:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gk766rgmc5xqmYdCEvHAJf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A top-down illustration showing red, ghostly hands emanating from a monitor and typing on a computer keyboard to represent infostealer malware. Along the red hands and forearms of the implied hacker, binary is shown to represent stolen data.]]></media:description>                                                            <media:text><![CDATA[A top-down illustration showing red, ghostly hands emanating from a monitor and typing on a computer keyboard to represent infostealer malware. Along the red hands and forearms of the implied hacker, binary is shown to represent stolen data.]]></media:text>
                                <media:title type="plain"><![CDATA[A top-down illustration showing red, ghostly hands emanating from a monitor and typing on a computer keyboard to represent infostealer malware. Along the red hands and forearms of the implied hacker, binary is shown to represent stolen data.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gk766rgmc5xqmYdCEvHAJf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Infostealers have been around for some time but recently they’ve been making headlines. This targeted <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, created to compromise the systems of victims and exfiltrate sensitive information, is on the rise and poses an active threat to all businesses.</p><p>A recent report found that infostealers <a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials"><u>exposed billions of credentials in 2024</u></a>, with KELA Cyber Threat Intelligence measuring 4.3 million machines infected with the malware around the world.</p><p>Infostealers were used in headline-grabbing attacks in the past year such as <a href="https://www.itpro.com/security/cyber-attacks/snowflake-data-breach-claims-spark-war-of-words-over-culpability"><u>the Snowflake data breach</u></a> and sometimes come as a precursor to <a href="https://www.itpro.com/security/ransomware/ransomware-attacks-worst-month-ever"><u>ransomware attacks</u></a>.</p><p>So how big is the threat posed by infostealers and what needs to be done to protect against them?</p><h2 id="infostealers-at-work">Infostealers at work</h2><p>Infostealers are malicious programs designed to extract sensitive data, such as passwords, <a href="https://www.itpro.com/security/361576/what-are-cookies"><u>session cookies</u></a> and <a href="https://www.itpro.com/security/a-leaked-github-access-token-could-have-led-to-a-catastrophic-supply-chain-attack"><u>authentication tokens</u></a>. Their goal is clear: to gain access to accounts, platforms or corporate networks, says Axel Maisonneuve, technical education contributor at BSV Association. </p><p>He calls infostealers “highly effective” due to their “small size, speed and ability to operate stealthily” – which means they often go undetected.</p><p>Infostealers typically arrive via <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> emails, <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links"><u>compromised URLs</u></a>, infected downloads, or flaws in software operating systems, Kevin Curran, IEEE senior member and professor of cybersecurity at Ulster University explains. </p><p>“Once on the device, the malware looks for certain kinds of information, including browser passwords, <a href="https://www.itpro.com/security/cyber-attacks/370223/four-year-old-iframe-flaw-hackers-steal-bitwarden-passwords"><u>autofill data</u></a> such as credit card numbers and addresses, cryptocurrency wallet data, system data and session cookies for accounts currently logged in. After collecting the information, the malware sends the data to an attacker-controlled server, or makes it available for download.”</p><p>Once extracted, the stolen data is often packaged up and sold on an auto shop – a <a href="https://www.itpro.com/security/32117/what-is-the-dark-web"><u>dark web</u></a> marketplace that specializes in the sale of digital products – for a relatively small price. </p><p>However, particularly valuable stolen data can be sold for several hundred dollars, says Robert Fitzsimons, lead threat intelligence engineer at Searchlight Cyber. “Similarly, information can be disseminated on platforms including <a href="https://www.itpro.com/security/cyber-crime/telegrams-popularity-continues-to-soar-as-catalog-of-available-cyber-crime-services-matures"><u>Telegram</u></a> and dark web hacker forums to be used by other threat actors such as <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware groups</u></a> during the reconnaissance phase of further attacks.”</p><p>Infostealers are now widely accessible thanks to the rise of the <a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem"><u>malware as a service (MaaS)</u></a> model, says Maisonneuve. “Platforms such as Raccoon Stealer and <a href="https://www.itpro.com/security/malware/two-notorious-infostealer-malware-operations-were-just-knocked-offline"><u>Redline</u></a> are available via subscription in underground forums, while <a href="https://www.itpro.com/security/cyber-attacks/what-is-an-apt"><u>advanced persistent threat (APT)</u></a> groups use them for large-scale espionage.”</p><h2 id="infostealer-examples">Infostealer examples</h2><p>One of the most well-known examples of an infostealer is <a href="https://www.itpro.com/security/hacking/361340/what-is-emotet"><u>Emotet</u></a>, which initially started as a banking <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus"><u>Trojan</u></a> but evolved into a powerful infostealing tool. “Emotet’s capabilities have enabled large-scale ransomware operations, making it infamous in the cybersecurity landscape,” says Dray Agha, senior manager of security operations at Huntress.</p><p>Another emerging example is <a href="https://www.itpro.com/security/cyber-attacks/malicious-github-repositories-target-users-with-malware"><u>Lumma Stealer</u></a>, a more recent malware variant. “Lumma Stealer is notable for its ability to capture information related to <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication</u></a> (MFA), undermining critical layers of security and leaving victims exposed to further attacks,” Agha explains.</p><p>An increasing number of infostealer campaigns are leveraging <a href="https://www.itpro.com/security/cyber-crime/fake-captcha-attacks-surged-in-late-2024-heres-what-to-look-out-for"><u>fake CAPTCHA</u></a> pages to deliver Lumma Stealer malware, says Stefan Tenase, cyber intelligence expert at CSIS. “While thinking they are solving a CAPTCHA to prove they are human, victims are duped into pasting malicious <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell"><u>PowerShell</u></a> code into their systems, showcasing how simple yet effective social engineering tactics can be.”</p><p>John Flatley, consulting solutions architect at Barracuda describes how the firm <a href="https://blog.barracuda.com/2024/08/14/phishing-advanced-infostealer-data-exfiltration" target="_blank"><u>recently observed</u></a> a phishing campaign delivering a sophisticated infostealer capable of collecting extensive data, including browser session cookies, saved credit card details, cryptocurrency wallet extensions and PDF files. “The attack started with a phishing email and unfolded in stages to finally reveal the obfuscated infostealer malware. </p><p>“Once deployed, the infostealer exfiltrated the sensitive information to attacker-controlled email accounts for selling onwards, or for financial theft or lateral movement within an organization.”</p><p>Prashant Kumar, X-Labs security researcher at Forcepoint describes how the firm’s research teams have seen increased activity from a new infostealer targeting businesses called VIPKeyLogger, which circulates through phishing campaigns as an attachment. “Opening the attachment leads to a sequence of events that ultimately ends up with data exfiltration such as recording keystrokes and collecting information including clipboard data, screenshots and browser history.”</p><p>Another <a href="https://www.itpro.com/security/the-holiday-crunch-threats-security-teams-face-and-how-to-mitigate-them"><u>campaign circulated in the holiday season</u></a> was the <a href="https://www.itpro.com/security/cyber-crime/researchers-discover-highly-sophisticated-operation-using-a-3000-strong-network-of-ghost-accounts-to-spread-malware-on-github"><u>Rhadamanthys</u></a> stealer, which masquerades as travel industry emails, says Kumar. “Clicking the documents triggers a chain of downloads and obfuscated scripts to steal user credentials and cryptocurrency wallet data.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><h2 id="protecting-your-business-from-infostealers">Protecting your business from infostealers</h2><p>The threat from infostealers is growing, but thankfully, there are tools and techniques to avoid being hit.</p><p>Defending against infostealers requires a comprehensive approach to cybersecurity, emphasizing preventative measures and advanced tools, says Agha. One critical part of this is security awareness training, which helps employees recognize and avoid common attack methods such as phishing attempts and malicious links, he says.</p><p>It's also important to use <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus"><u>antivirus</u></a> and <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools"><u>anti-malware</u></a> solutions with real-time scanning capabilities, says Curran. “These act to detect and block malware, including <a href="https://www.itpro.com/spyware/30001/what-is-spyware"><u>spyware</u></a> and keyloggers.”</p><p>Trusted <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022">password managers</a> are “essential for generating and securely storing strong, unique passwords”, he says. However, he warns that storing passwords directly in browsers can make them vulnerable to infostealer attacks.</p><p>Once they're inside your organization, infostealers can be difficult to spot. With this in mind, Fitzsimons advises monitoring dark web forums for <a href="https://www.itpro.com/security/data-breaches/a-treasure-trove-for-adversaries-10-billion-stolen-passwords-have-been-shared-online-in-the-biggest-data-leak-of-all-time"><u>stolen data logs</u></a> related to your company. “This means you can more easily identify the compromised device, where the infostealer is installed and when it was infected. You can then take quick action to contain its spread within your network.”</p><p>Keeping software and systems up to date is also important to avoid being impacted by infostealers, says Agha. “<a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk"><u>Regular updates and patching</u></a> help close the vulnerabilities attackers often exploit to deploy malware. Additionally, implementing strong authentication practices, such as MFA, adds an extra layer of security. Even if login credentials are compromised, MFA can prevent unauthorized access to critical systems.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake file converter tools are on the rise – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/fake-file-converter-tools-are-on-the-rise-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ The FBI has issued an alert over the rise of fake file converter tools available online after observing a spate of scams and ransomware attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VVekdSkGWA2QGjxQxot4DP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Mar 2025 11:01:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:description>                                                            <media:text><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:text>
                                <media:title type="plain"><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has issued an alert over the rise of fake file converter tools online after observing a spate of scams and <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attacks. </p><p>According to the FBI Denver Field Office, cyber criminals are creating free online document converter tools to load malware onto victims’ computers, leading in some cases to identity theft or <a href="https://www.itpro.com/ransomware/34345/40-of-cybersecurity-professionals-think-paying-ransomware-demands-should-be-illegal">ransom demands</a>.</p><p>Threat actors are exploiting a range of file converter or downloader tools, officials warned, including one website claiming to convert one type of file to another, such as a .doc file to a .pdf file. </p><p>The tool may also claim to combine files, such as joining multiple .jpg files into one .pdf file, or to be an MP3 or MP4 downloading tool.</p><p>These converters and downloading tools will do the job they claim, but leave the resulting file holding hidden <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>that gives criminals access to the victim’s computer. </p><p>These tools can also scrape the submitted files for personal identifying information, such as social security numbers, dates of birth, phone numbers, banking information, <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency </a>information such as seed phrases or wallet addresses, email addresses, and passwords.</p><p>"The best way to thwart these fraudsters is to educate people so they don’t fall victim to these fraudsters in the first place," said FBI Denver special agent in charge Mark Michalek. </p><p>"If you or someone you know has been affected by this scheme, we encourage you to make a report and take actions to protect your assets. Every day, we are working to hold these scammers accountable and provide victims with the resources they need."</p><h2 id="how-to-spot-fake-file-converter-tools">How to spot fake file converter tools</h2><p>Malwarebytes has identified some of these suspect file converters, which include <em>Imageconvertors.com, convertitoremp3.it, convertisseurs-pdf.com and convertscloud.com</em>.</p><p>There are several techniques used by the cyber criminals, according to Malwarebytes.</p><p>"They encourage you to download a tool on your device to do the conversion. This is the actual malware. You might be recommended to install a browser extension that you can use going forward. These extensions are often browser hijackers and adware," it said.</p><p>"In the most sophisticated scenario, the so-called converted file contains malware code that downloads and install an information stealer and everyone who opens it will get their device infected."</p><p>A suspect file converter tool is believed to have been behind the hack of major US local newspaper publisher Lee Enterprises last month, claimed by the Qilin ransomware operation.</p><p>The attack affected a number of the company's business operations, including product distribution, billing, collections, and vendor payments. </p><p>Lee Enterprises said it wasn't clear whether any sensitive data or personally identifiable information was compromised during the breach.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/forget-mfa-fatigue-attackers-are-exploiting-click-tolerance-to-trick-users-into-infecting-themselves-with-malware">Forget MFA fatigue, attackers are exploiting ‘click tolerance’ to trick users into infecting themselves with malware</a></li><li><a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">Malware-free attacks surged in 2024</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why ‘malware as a service’ is becoming a serious problem</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Forget MFA fatigue, attackers are exploiting ‘click tolerance’ to trick users into infecting themselves with malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/forget-mfa-fatigue-attackers-are-exploiting-click-tolerance-to-trick-users-into-infecting-themselves-with-malware</link>
                                                                            <description>
                            <![CDATA[ Threat actors are exploiting users’ familiarity with verification tests to trick them into loading malware onto their systems, new research has warned. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yweBc4aY8D9tgu72WurDee</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Mar 2025 09:16:19 +0000</pubDate>                                                                                                                                <updated>Thu, 20 Mar 2025 12:04:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Threat actors are exploiting users’ familiarity with verification tests to trick them into loading <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>onto their systems, new research has warned.</p><p>A <a href="https://threatresearch.ext.hp.com/hp-wolf-security-threat-insights-report-march-2025/" target="_blank">report</a> from HP Wolf Security highlighted multiple threat campaigns where hackers took advantage of the fact users are forced to jump through a growing number of hoops to prove they are a legitimate user. </p><p>The report describes this trend as ‘click tolerance’, where the prevalence of authentication protocols has led to users being accustomed to follow steps given to them.</p><p>In the cases observed by HP, the attackers used <a href="https://www.itpro.com/security/cyber-crime/fake-captcha-attacks-surged-in-late-2024-heres-what-to-look-out-for">fake CAPTCHAs</a> to redirect users to attacker-controlled sites which prompted them into completing a number of fake authentication steps. </p><p>As users progress through these steps, the website copies malicious code to their clipboard and subsequently prompts the victim to press a number of shortcuts that open a ‘run’ dialog and execute the code directly on their system.</p><p>Speaking to <em>ITPro , </em>Ian Pratt, global head of security at HP, said attacks like this are not necessarily new but this campaign stood out as it actually gets the victim to infect themselves, which helps the attackers bypass traditional security products.</p><p>“It’s certainly not the first time it’s been done but it’s been done really well and it’s being done at a scale we haven’t seen before,” he noted.</p><p>“It’s a really good way of bypassing a lot of security products because effectively the user typed it into the run box. It’s not like they downloaded a script. There was no file that the <a href="https://www.itpro.com/security/29665/does-antivirus-software-do-more-harm-than-good">antivirus </a>could look at and make a decision about. They just hit CTRL + V and it ran.”</p><h2 id="what-happens-after-you-click">What happens after you click</h2><p>Much like previous social engineering tactics that relied on <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">MFA fatigue</a> to steal user’s one time passcodes (OTPS), this campaign illustrates how additional security protections also breeds new types of complacency attackers can exploit.</p><p>Pratt said this campaign relies on the idea that users are used to completing tedious authentication measures and often can’t distinguish between legitimate procedures and malicious ones.</p><p>“People are being trained that sometimes a screen is going to appear and then you’re going to have to click through it. Maybe you’ll be logging in, maybe it's just but people do it without thinking now and attackers are exploiting that with these fake CAPTCHAs.”</p><p>He argued that this has laid bare an obvious shortcoming in employee security training, noting that it’s important phishing training and other security awareness programs put more emphasis on what users do after they fall for the initial deception in the attack chain.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Z9ggB3xs29f2quPySea2Xc" name="Nine steps to proactively manage data privacy and protection_listing.jpg" caption="" alt="Whtiepaper cover with green title over image of female wearing glasses smiling at camera" src="https://cdn.mos.cms.futurecdn.net/Z9ggB3xs29f2quPySea2Xc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-protection/370011/nine-steps-to-proactive-manage-data-privacy-and"><em>Reduce risks, comply with regulations, and protect data</em></a></p></div></div><p>“I think that the most important part of phishing training is going forwards… what they should be adding to what they’re doing is that it’s actually what happens after you click that’s most important,” he explained.</p><p>“After you clicked on that thing, was it what you expected, was the content correct. Did anything seem off at that point? The most important thing you can do is report it because we’re seeing a lot of effort being put into the lures but not necessarily a lot of effort being put into the thing that you can get taken to, often it will be completely irrelevant content or a command shell flashes up on your screen.</p><p>“Anything suspicious like that, that’s the best opportunity of spotting that something’s gone wrong and then to disconnect your laptop from the network and go and call someone. That’s the big one.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">Malware-free attacks surged in 2024 as attackers drop malicious software for legitimate tools</a></li><li><a href="https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem">Why 'malware as a service' is becoming a serious problem for enterprises</a></li><li><a href="https://www.itpro.com/security/hunter-killer-malware-is-on-the-rise-and-security-experts-are-seriously-concerned">Hunter-killer malware is on the rise, and security experts are seriously concerned</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A ‘significant increase’ in infostealer malware attacks left 3.9 billion credentials exposed to cyber criminals last year – and experts worry this is a ticking time bomb for enterprises ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials</link>
                                                                            <description>
                            <![CDATA[ The threat of infostealer malware is on the rise, with 4.3 million machines infected last year alone ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6GPdt3tuUtsBDsnhJ6kGTM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gr35Nym2DPm2qLtu2CHabe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Mar 2025 08:31:42 +0000</pubDate>                                                                                                                                <updated>Tue, 11 Mar 2025 16:21:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gr35Nym2DPm2qLtu2CHabe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[angled view of a dialogue box with a purple Malware icon surrounded by other neon blue dialogue boxes with pink backlight]]></media:description>                                                            <media:text><![CDATA[angled view of a dialogue box with a purple Malware icon surrounded by other neon blue dialogue boxes with pink backlight]]></media:text>
                                <media:title type="plain"><![CDATA[angled view of a dialogue box with a purple Malware icon surrounded by other neon blue dialogue boxes with pink backlight]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gr35Nym2DPm2qLtu2CHabe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have warned that billions of credentials exposed to cyber criminals were sourced from infostealer logs last year – and it's created a ticking time bomb for enterprises as hackers begin cracking systems.</p><p>KELA Cyber Threat Intelligence’s <em>State of Cybercrime</em> <em>2024 </em><a href="https://www.kelacyber.com/resources/research/state-of-cybercrime-2024/" target="_blank">report</a> singled out infostealers as a persistent threat that usually serve as “precursors to advanced attacks, including <a href="https://www.itpro.com/security/ransomware">ransomware</a> and espionage”.</p><p>The firm said it observed more than 4.3 million machines around the world that had been infected with infostealer <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, such as <a href="https://www.itpro.com/security/cyber-crime/researchers-discover-highly-sophisticated-operation-using-a-3000-strong-network-of-ghost-accounts-to-spread-malware-on-github">Lumma stealer</a> or RedLine, in 2024.</p><p>It estimated that this would account for more than 330 million credentials compromised using infostealers, which it said was slightly higher than the figures from 2023.</p><p>KELA warned that these credentials could be leveraged in future attacks that could balloon into “massive extortion campaigns”, citing the string of attacks leveraging <a href="https://www.itpro.com/security/cyber-attacks/with-hundreds-of-snowflake-credentials-published-on-the-dark-web-its-time-for-enterprises-to-get-mfa-in-order">compromised Snowflake credentials</a> throughout 2024 that impacted at least 165 different companies.</p><p>In addition to the 330 million credentials KELA identified, the report said it also observed 3.9 billion credentials shared in the form of credential lists. These credential lists, commonly referred to as url:login:pass (ULP) files by threat actors, are compilations of data obtained during attacks.</p><p>These could be credentials harvested from a diverse range of sources, such as third-party breaches or <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, but the report claimed that most ULP files are sourced from infostealer logs.</p><p>Lumma remains the most popular <a href="https://www.itpro.com/security/368641/facebook-business-accounts-hijacked-by-infostealer-malware-campaign">infostealer malware</a> strain according to KELA, and was responsible for 40.48% of the infected machines in its data lake.</p><p>Other top offenders were StealC (20.29%, and Redline (16.43%), which KELA noted had been disrupted in October 2024 as part of <a href="https://www.itpro.com/security/malware/two-notorious-infostealer-malware-operations-were-just-knocked-offline">Operation Magnus</a>.</p><p>India, Brazil, and Indonesia were the top three most affected nations accounting for 20.12% of bots infected by infostealer malware in 2024.</p><p>KELA also highlighted the sensitive services most commonly targeted using these compromised credentials with the most frequently attacked being <a href="https://www.itpro.com/cloud/32167/our-5-minute-guide-to-enterprise-cloud-computing">business cloud solutions</a> (22.02%), <a href="https://www.itpro.com/security/33149/90-of-hacked-cms-sites-in-2018-were-powered-by-wordpress">CMS</a> (21.19%), <a href="https://www.itpro.com/business-communications/33417/i-miss-the-good-old-days-of-email-there-i-said-it">email</a> (13.85%), and user authentication systems (11.5%).</p><h2 id="how-to-protect-yourself-against-infostealer-threats">How to protect yourself against infostealer threats</h2><p>According to Huntress’ 2025 <a href="https://www.huntress.com/resources/2025-cyber-threat-report" target="_blank"><em>Cyber Threat Report</em></a><em>,</em> infostealers accounted for nearly a quarter (24%) of all cyber incidents in 2024, making it the most common threat category of the year.</p><p>Speaking to <em>ITPro, </em>Jaron Bradley, director of Jamf Threat Labs at <a href="https://www.itpro.com/business/leadership/jamf-appoints-new-ciso-and-global-channel-lead">Jamf</a>, said infostealers campaigns are on the rise with evidence suggesting they are a particularly effective tactic used by threat actors.</p><p>“There has been a significant increase in Infostealer campaigns, and they have proven highly effective, even on <a href="https://www.itpro.com/tag/macos">macOS</a>. These stealers are designed to target specific locations on the user's hard drive, seeking critical files such as usernames, passwords, browser session data, <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> wallets, documents, and more.”</p><p>Bradley added that the initial stages of  infostealer campaigns require actions from the victim, so by <a href="https://www.itpro.com/security/33476/kaspersky-lab-aims-to-improve-security-awareness-with-a-training-platform">improving overall security awareness</a> businesses can mitigate some of the threat they pose to their organization.</p><p>“Users should be cautious about opening software sent by strangers, particularly if it comes with unusual instructions, such as right-clicking or adjusting settings,” he explained.</p><p>“For these infostealers to fully succeed, they also require the victim's login password, which is typically obtained by simply prompting the user with a popup window. Users should always question why an application would need their login credentials before willingly providing them.”</p><p>As well as investing in <a href="https://www.itpro.com/security/33476/kaspersky-lab-aims-to-improve-security-awareness-with-a-training-platform">improving company-wide security awareness</a>, KELA suggested a number of additional counter measures businesses can take to protect themselves.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="R2JhsMftrZR9bfZBy5pb9L" name="The Big Book of Selling Data Protection" caption="" alt="The Big Book of Selling Data Protection" src="https://cdn.mos.cms.futurecdn.net/R2JhsMftrZR9bfZBy5pb9L.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: N-Able)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-big-book-of-selling-data-protection"><em>MSPs: Seal the deal and increase revenue</em></a></p></div></div><p>These include deploying enhanced <a href="https://www.itpro.com/security/cyber-security/368443/an-edr-buyers-guide">endpoint detection and response</a> (EDR) solutions that use behavior-based analysis rather than solely signature-based methods to detect and isolate infostealer activity in real time.</p><p>Improved <a href="https://www.itpro.com/business/acquisition/knowbe4-snaps-up-cloud-email-security-specialist-egress">email security</a> is also essential in preventing phishing attempts, which are the primary delivery method for infostealers, the report added.</p><p>Finally,  <a href="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model">network segmentation</a> is another important defense layer used to limit lateral movement once the attacker is inside your perimeter and stop them from accessing critical systems and sensitive data.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/github-malvertising-campaign-microsoft">Nearly a million devices were infected in a huge GitHub malvertising campaign</a></li><li><a href="https://www.itpro.com/security/cyber-crime/cobalt-strike-takedown-fortra-microsoft">Cobalt Strike abusers have been dealt a hammer blow</a></li><li><a href="Java developers are facing serious productivity issues">Java developers are facing serious productivity issues</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why ‘malware as a service’ is becoming a serious problem ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/why-malware-as-a-service-is-becoming-a-serious-problem</link>
                                                                            <description>
                            <![CDATA[ Researchers have issued a warning over the rise of 'malware as a service' platforms amid a surge in attacks over the last year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">88BZdeNJiYUjw3wdr39wYe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/C5CVHQe64yFiVrMZmpFsbQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Feb 2025 13:00:13 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Feb 2025 12:52:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/C5CVHQe64yFiVrMZmpFsbQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close up of yellow networking cables going to a circuitboard]]></media:description>                                                            <media:text><![CDATA[Close up of yellow networking cables going to a circuitboard]]></media:text>
                                <media:title type="plain"><![CDATA[Close up of yellow networking cables going to a circuitboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/C5CVHQe64yFiVrMZmpFsbQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There was a distinct surge in separate <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> campaigns delivering the same payload last year, research shows, suggesting hackers are increasingly procuring tools from ‘malware as a service’ platforms.</p><p>The malware as a service model is becoming the dominant mode of cyber attacks as the cyber crime space continues to mature into a <a href="https://www.itpro.com/security/ransomware/359919/ransomware-criminals-look-to-other-hackers-to-provide-them-with-network">lucrative ecosystem</a> for hackers for hire.</p><p>New <a href="https://darktrace.com/resources/annual-threat-report-2024" target="_blank">research</a> from <a href="https://www.itpro.com/business/business-strategy/darktrace-cleared-of-channel-stuffing-claims-by-ey-audit-announces-31-revenue-growth">Darktrace</a> found the malware as a service (MaaS) model was responsible for 57% of all cyber threats detected in the second half of 2024, up 17% from the first half of the year.</p><p>A <a href="https://www.watchguard.com/wgrd-news/press-releases/internet-security-report-q3-2024" target="_blank">report</a> from <a href="https://www.itpro.com/business/acquisition/watchguard-snaps-up-actzero-to-power-mdr-services">WatchGuard</a> also warned it observed an “astronomical surge” in total malware threats in the third quarter of 2024, surpassing 420,000.</p><p>Total <a href="https://www.itpro.com/internet-of-things-iot/33371/iot-malware-threats-ballooned-in-2018https://www.itpro.com/security/stealthy-malware-the-threats-hiding-in-plain-sight">malware threats</a> refers to the number of unique attempts detected on WatchGuard-protected endpoints with any duplicates - those with the same hash are not counted.</p><p>WatchGuard noted this represented a 300% increase on the previous quarter’s figures, which is the largest quarterly rise it has ever observed.</p><p>The report stated that one might conclude this surge was driven by an overall increase in new threats, but WatchGuard found that there was actually an “uncharacteristic decline in new threats”.</p><p>It noted that the results of its telemetry indicate there has been a “flood of homogenous <a href="https://www.itpro.com/security/34784/the-future-of-spam-is-scary">spam</a>-like malware arriving on endpoints, likely separate malware campaigns with the same payload”.</p><p>The report further stated that there are often numerous duplicate malware families from quarter to quarter, but this time there was only one: Glupteba.</p><p>WatchGuard described Glupteba as a multi-faceted malware with various capabilities, such as acting as a <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">botnet</a>, stealing information, <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">mining cryptocurrency</a>, and loading other malware onto the system.</p><h2 id="malware-as-a-service-rise-propped-up-by-phishing-attacks">Malware as a service rise propped up by phishing attacks</h2><p>Phishing remains the dominant initial access vector used in these attacks, with Darktrace recording over 30.4 million <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> emails targeting its customers between December 2023 and 2024.</p><p>Just under two-fifths (38%) of these emails were targeted <a href="https://www.itpro.com/software/google-docs/361922/researchers-spot-spear-phishing-exploit-in-google-docs">spear phishing</a> attacks tailored for ‘high value individuals’.</p><p>Darktrace noted 32% of the detected <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them">phishing emails contained AI generated text</a> that displayed some form of ‘linguistic complexity’ such as increased text volume, punctuation, and sentence length.</p><p>The sophistication of these techniques has blossomed, the report added, stating that 70% of the emails containing  <a href="https://www.itpro.com/technology/artificial-intelligence/ai-threats-the-importance-of-a-concrete-strategy-in-fighting-novel-attacks">AI-enhanced phishing</a> content passed the popular DMARC authentication system, which is used to verify the legitimacy of incoming emails.</p><p>Moreover, 55% of all the emails had successfully found their way through all of the target organization’s existing layers before being detected.</p><p>Attacks leveraging <a href="https://www.itpro.com/marketing-comms/qr-codes/360864/are-qr-codes-safe">QR codes</a>, or <a href="https://www.itpro.com/security/hackers-are-stepping-up-qishing-attacks-by-hiding-malicious-qr-codes-in-pdf-email-attachments">qishing</a>, have become a growing trend in today’s threat landscape, exploiting the often-weaker security of mobile devices, and Darktrace detected just under a million (940,000) malicious QR codes in the emails it analyzed.</p><h2 id="legitimate-service-attacks-are-another-key-focus">Legitimate service attacks are another key focus</h2><p>The report also noted threat actors were often seen abusing legitimate services to lend authenticity to their scams. The researchers observed hackers exploiting  a number of trusted services such as <a href="https://www.itpro.com/software/microsoft-office/355740/microsoft-announces-lists-a-new-app-for-teams-sharepoint-and">Microsoft Sharepoint</a>, <a href="https://www.itpro.com/software/zoom-wants-to-take-on-google-and-microsoft-with-its-own-docs">Zoom Docs</a>, <a href="https://www.itpro.com/software/367972/how-easy-is-it-to-sync-quickbooks-to-another-computer">QuickBooks</a>, HelloSign, and Adobe to disguise their sender address.</p><p>In addition, trusted service providers were also appropriated as parts of the threat actor’s attack infrastructure, Darktrace noted.</p><p>“Threat actors were frequently observed using redirects via legitimate services like <a href="https://www.itpro.com/software/google">Google</a> to deliver malicious payloads, effectively evading detection,” the report said.</p><p>“Additionally,Darktrace noted instances where attackers hijacked email accounts, including <a href="https://www.itpro.com/security/biometrics/356023/amazon-halts-police-use-of-its-facial-recognition-tech">Amazon</a> Simple Email Service (SES) accounts, belonging to legitimate third parties, such as business partners and trusted vendors.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sN9hzieUPYt9YngAjVNAJK" name="Whitepaper_ DevSecOps is dead...or is it__" caption="" alt="Whitepaper: DevSecOps is dead...or is it?:" src="https://cdn.mos.cms.futurecdn.net/sN9hzieUPYt9YngAjVNAJK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/devsecops-is-dead-or-is-it"><em>Integrate security into the development processes</em></a></p></div></div><p><em>ITPro </em>learned that <a href="https://www.itpro.com/security/cyber-crime/threat-actors-are-leaning-on-trusted-services-more-than-ever">living off trusted services</a> (LoTS) attacks are becoming an increasingly important part of the threat actors arsenal as general security awareness among their targets grows.</p><p>A recent report from security firm Mimecast explained that while these tactics often make their attacks more complex, it helps attackers get around increased authentication checks on corporate accounts.</p><p>It added that major cloud providers whose services are often abused in these attacks, namely Google and <a href="https://www.itpro.com/software/microsoft">Microsoft</a>, have begun taking steps to root out the malicious use of their platforms in such attacks.</p><p>As a result, threat actors have been observed migrating to slightly smaller trusted services providers that they can use to lend authenticity to their attacks.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-crime/what-is-hackbot-as-a-service-and-are-malicious-llms-a-risk">What is hackbot as a service and are malicious LLMs a risk?</a></li><li><a href="https://www.itpro.com/security/cyber-crime/blacklock-ransomware-group-reliaquest">The ‘BlackLock’ group has become one of the most prolific operators in the cyber crime industry</a></li><li><a href="https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024">Open source malware surged by 156% in 2024</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ There’s a new ransomware player on the scene: the ‘BlackLock’ group has become one of the most prolific operators in the cyber crime industry – and researchers warn it’s only going to get worse for potential victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/blacklock-ransomware-group-reliaquest</link>
                                                                            <description>
                            <![CDATA[ Security experts have warned the BlackLock group could become the most active ransomware operator in 2025 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DuUe3wJfL47GoEiaDQbEyA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dKikTPpzL92Y4jzf78G8aM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Feb 2025 13:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Feb 2025 14:14:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dKikTPpzL92Y4jzf78G8aM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Black padlock sitting on laptop keyboard with red background, representing the BlackLock ransomware group.]]></media:description>                                                            <media:text><![CDATA[Black padlock sitting on laptop keyboard with red background, representing the BlackLock ransomware group.]]></media:text>
                                <media:title type="plain"><![CDATA[Black padlock sitting on laptop keyboard with red background, representing the BlackLock ransomware group.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dKikTPpzL92Y4jzf78G8aM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The BlackLock ransomware group has become one of the most prolific operators in the <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">Ransomware as a Service</a> (RaaS) ecosystem, with experts warning it could accelerate its growth over the next year.</p><p>Also known as El Dorado, BlackLock was ranked as the seventh most active ransomware group based on the number of posts on its <a href="https://www.itpro.com/security/ransomware/alphv-leak-site-seized-by-law-enforcement-as-decryption-tool-released">data leak site</a> by the end of 2024, marking a 1,425% growth from Q3.</p><p>Security firm <a href="https://www.itpro.com/security/cyber-crime/hackers-have-been-posing-as-it-support-on-microsoft-teams">ReliaQuest</a> recently published <a href=" https://www.reliaquest.com/blog/threat-spotlight-inside-the-worlds-fastest-rising-ransomware-operator-blacklock/" target="_blank">research on the group</a> and its rise to prominence, detailing its TTPs and why the operation has seen so much success in recent years.</p><p>The group was among the top three most active collectives on the <a href="https://www.itpro.com/security/ransomware/360835/ransomware-hackers-break-off-from-babuk-to-join-a-new-group">RAMP forum</a>, whose community listed BlackLock among the top ransomware operators in terms of their reputation on the site.</p><p>Reliaquest noted that BlackLock’s rise has been both “swift and strategic” and predicted that if the group’s activity continues at this pace it will go on to become the <a href="https://www.itpro.com/security/ransomware/the-big-three-ransomware-groups-are-losing-their-grip-on-the-industry-as-gangs-begin-to-fracture-study-shows">most active ransomware group</a> in 2025.</p><p>The group is known to use <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">double extortion tactics</a> whereby they encrypt data while also stealing sensitive information, hoping to exert more pressure on victims with the potential threat of exposing the stolen information.</p><p>Its ransomware is custom-built to target <a href="https://www.itpro.com/software/microsoft/windows">Windows</a>, <a href="https://www.itpro.com/security/threat-actors-are-exploiting-a-vmware-esxi-bug-which-could-be-catastrophic-for-affected-firms">VMWare ESXi</a>, and <a href="https://www.itpro.com/uk/software/linux">Linux</a> environments, although Reliquest noted that the Linux variant is less mature than its Windows counterpart.</p><h2 id="why-blacklock-stands-out-from-the-crowd">Why BlackLock stands out from the crowd</h2><p>The report identifies a number of ways in which BlackLock has set itself apart in what is a <a href="https://www.itpro.com/security/inter-cartel-strife-and-affiliate-poaching-could-hamstring-alphv-in-2024">highly competitive digital extortion landscape</a>, firstly with what it describes as an unusual leak site that uses a combination of unique tricks aimed at preventing researchers from downloading stolen data.</p><p>The site is “packed” with a number of features that Reliaquest speculates are intended to prevent targeted organizations from assessing the scope of their breaches.</p><p>“This, in turn, ramps up <a href="https://www.itpro.com/security/ransomware/368167/double-extortion-ransomware-pushes-average-payments-close-to-1-million">pressure on the organizations to quickly pay ransoms</a>, often before they can fully evaluate the situation,” researchers said. </p><p>“These features also highlight BlackLock’s technical sophistication, reinforcing its reputation as a polished, professional operation.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jejbonnPY7UGDvayx8yMbh" name="Supercharge trust for operations_listing.jpg" caption="" alt="Whitepaper cover of female worker wearing a cap backwards, surrounded by pallets, pulling sticky labels" src="https://cdn.mos.cms.futurecdn.net/jejbonnPY7UGDvayx8yMbh.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/supercharge-trust-for-operations"><em>Drive operations performance across the enterprise</em></a></p></div></div><p>BlackLock’s use of custom-built <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> is another indicator of their sophistication, Reliaquest added, which it said is a hallmark of top-tier groups such as Qlin or <a href="https://www.itpro.com/security/369809/play-ransomware-gang-behind-recent-cyber-attack-on-rackspace">Play</a>.</p><p>Competing groups like Bl00dy, Dragonforce, and RA World rely on externally developed ransomware builders such as leaked versions of <a href="https://www.itpro.com/security/ransomware/360095/babuk-ransomware-returns-to-target-corporate-networks">Babuk</a> or <a href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter">LockBit</a>, the report notes, whereas BlackLock develops its own bespoke malware.</p><p>“While <a href="https://www.itpro.com/security/ransomware/369435/yanluowang-ransomware-leaks-suggest-pseudo-chinese-persona-revil-links">leaked ransomware builders</a> are easy to use, they come with a major drawback: Security researchers can access and dissect the code, find weaknesses, and develop defenses against them. In contrast, BlackLock’s custom malware keeps researchers in the dark — at least until its source code is leaked.”</p><p>Reliaquest also reported the group has been actively <a href="https://www.itpro.com/security/ransomware/367481/fbi-warns-rust-based-ransomware-has-breached-over-60-organisations">recruiting affiliates</a> known as ‘traffers’ to support the earlier stages of their attacks, whereas it has been far more discreet when looking to bring higher-level developers on board.</p><iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><h2 id="blacklock-targets-need-to-be-wary">BlackLock targets need to be wary</h2><p>The report identified potential indicators for BlackLock’s next major targets, citing forum activity that would suggest the group plans on exploiting <a href="https://www.itpro.com/cloud/cloud-security/hybrid-cloud-environments-are-under-serious-threat-from-hackers-heres-what-you-need-to-know">Microsoft Entra Connect</a> in an upcoming campaign.</p><p>A user known to represent BlackLock was found sharing security research on how attackers could abuse Entra Connect’s synchronization mechanism to manipulate user attributes and compromise <a href="https://www.itpro.com/cloud/cloud-computing/aws-says-enterprises-are-moving-back-on-prem-but-does-cloud-repatriation-really-threaten-hyperscalers">on-prem</a> environments.</p><p>“For organizations managing multiple domains under one tenant, this tactic creates a significant risk of privilege escalation and the potential for a major breach. While the blog describes the attack hypothetically, its feasibility and potential impact make it a serious concern.,” Reliaquest warned.</p><p>As a result, organizations should reassess the security of their infrastructure now, Reliaquest urged, stating that in particular, they should look to harden their rules around sensitive attributes, monitor and restrict key registrations, and enforce conditional access policies.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/life-after-lockbit-a-fragmented-landscape-and-wayward-affiliates-will-still-cause-chaos-for-enterprises">Life after LockBit: A fragmented landscape and wayward affiliates will still cause chaos for enterprises</a></li><li><a href="https://www.itpro.com/security/ransomware/8base-ransomware-gang-arrests">8Base ransomware members snared in global police crackdown</a></li><li><a href="https://www.itpro.com/security/ransomware/cisco-kraken-breach-claims">Cisco dispels Kraken data breach claims, insists stolen data came from old attack</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using a new AI chatbot to wage cyber attacks: GhostGPT lets users write malicious code, create malware, and curate phishing emails – and it costs just $50 to use ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/hackers-are-using-a-new-ai-chatbot-to-wage-cyber-attacks-ghostgpt-lets-users-write-malicious-code-create-malware-and-curate-phishing-emails-and-it-costs-just-usd50-to-use</link>
                                                                            <description>
                            <![CDATA[ Researchers at Abnormal Security have warned about the rise of GhostGPT, a new chatbot used by cyber criminals to create malicious code and malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CeXMuWh83zuzDaibbydcmB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RpYYNVNkkquBAGU6u8BeaY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Jan 2025 13:42:53 +0000</pubDate>                                                                                                                                <updated>Wed, 29 Jan 2025 14:37:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RpYYNVNkkquBAGU6u8BeaY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GhostGPT concept image showing AI circuit board with interconnected data points.]]></media:description>                                                            <media:text><![CDATA[GhostGPT concept image showing AI circuit board with interconnected data points.]]></media:text>
                                <media:title type="plain"><![CDATA[GhostGPT concept image showing AI circuit board with interconnected data points.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RpYYNVNkkquBAGU6u8BeaY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are using an uncensored chatbot dubbed GhostGPT to help write malware, highlighting how AI can be twisted to "illegal activities". </p><p>That's according to Abnormal Security, which laid out details of GhostGPT in a <a href="https://abnormalsecurity.com/blog/ghostgpt-uncensored-ai-chatbot"><u>blog post</u></a>, saying the chatbot lacks the guardrails of standard AI tools such as ChatGPT, making it a helpful tool for cyber criminals. </p><p>It's not the first <a href="https://www.itpro.com/security/cyber-crime/what-is-hackbot-as-a-service-and-are-malicious-llms-a-risk"><u>hackbot-as-a-service</u></a>, however. WormGPT arrived in 2023 offering a similar chatbot subscription service for writing phishing emails and business email compromise attacks. </p><p>That, Abnormal Security noted, was followed by WolfGPT and EscapeGPT, suggesting GhostGPT is a sign malicious actors see value in AI helping them commit cyber crime. </p><p>The security company explained that GhostGPT was specifically designed for cyber crime purposes and that enterprises should be wary of its potential looking ahead.</p><p>"It likely uses a wrapper to connect to a jailbroken version of ChatGPT or an <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today">open source large language model (LLM)</a>, effectively removing any ethical safeguards," the blogpost explained. </p><p>"By eliminating the ethical and safety restrictions typically built into AI models, GhostGPT can provide direct, unfiltered answers to sensitive or harmful queries that would be blocked or flagged by traditional AI systems."</p><h2 id="what-can-ghostgpt-do">What can GhostGPT do?</h2><p>Abnormal shared a screenshot of an advertisement for the GhostGPT service that claimed the <a href="https://www.itpro.com/networking/27171/what-is-a-chatbot">chatbot </a>was fast and easy-to-use, offered uncensored responses, and had a strict no-logs policy, saying "protecting our users' privacy is our top priority." </p><p>Abnormal noted that GhostGPT was marketed for coding, malware creation, and exploit development, but could also be used to write material for <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC) scams</a>. The advertisement noted its various features make GhostGPT "a valuable tool for cybersecurity and various other applications."</p><p>"While its promotional materials mention "<a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>" as a possible use, this claim is hard to believe, given its availability on cyber crime forums and its focus on BEC scams," the Abnormal post added. </p><p>"Such disclaimers seem like a weak attempt to dodge legal accountability — nothing new in the cybercrime world."</p><p>Indeed, Abnormal's researchers asked GhostGPT to write a <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> email; it outputted a template that could be used to trick victims. </p><h2 id="easy-access-for-all-hackers">Easy access for all hackers</h2><p>GhostGPT is accessible as a Telegram bot, making it easy for attackers to make use of without having technical skills or taking the time to set up their own systems, Abnormal noted. </p><p>"Because it’s available as a Telegram bot, there is no need to <a href="https://www.itpro.com/security/jailbreaking-chatgpt-researchers-swerved-gpt-4s-safety-guardrails-and-made-the-chatbot-detail-how-to-make-explosives-in-scots-gaelic">jailbreak ChatGPT</a> or set up an open source model," the blog post noted. " Users can pay a fee, gain immediate access, and focus directly on executing their attacks."</p><p>A report in <a href="https://www.darkreading.com/cloud-security/cyberattackers-ghostgpt-write-malicious-code"><u><em>DarkReading</em></u></a><em> </em>noted that prices for GhostGPT were relatively cheap, too: $50 for a week, $150 for a month, and $300 for three months. </p><h2 id="fresh-challenge-for-security">Fresh challenge for security</h2><p>By lowering the barrier of entry to would-be hackers, such chatbots make it easier for cyber criminals without extensive skills to attack anyone — potentially sparking a real challenge for personal and organizational security. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nLNm7ZoGs6qDMtA8J8Na" name="Empowering Enterprises with AI: Entering the Era of Choice" caption="" alt="Empowering Enterprises with AI: Entering the Era of Choice" src="https://cdn.mos.cms.futurecdn.net/nLNm7ZoGs6qDMtA8J8Na.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/empowering-enterprises-with-ai-entering-the-era-of-choice"><em>Unlock your data</em>'s <em>potential</em></a></p></div></div><p>Chatbots also make it faster and easier to launch cyber crime campaigns by enabling threat actors to create more effective malware, realistic-looking phishing emails, and so on. </p><p>"With its ability to deliver insights without limitations, GhostGPT serves as a powerful tool for those seeking to exploit <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a> for malicious purposes," Abnormal said. </p><p>Because cyber criminals are shifting to AI, so too must security professionals, says Abnormal, as tools like GhostGPT will make it easier to slip phishing emails and malware past traditional filters. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US authorities just purged malware from thousands of devices across the world ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/us-authorities-just-purged-malware-from-thousands-of-devices-across-the-world</link>
                                                                            <description>
                            <![CDATA[ After taking control of the PlugX malware’s command-and-control server, the coalition were able to trigger a self-delete mechanism to remove the malicious program ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QHGyXTBxdqZ4jhtDVALjp9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N9ygzncFbwS3sNjicve3JK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jan 2025 11:23:55 +0000</pubDate>                                                                                                                                <updated>Thu, 16 Jan 2025 17:09:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N9ygzncFbwS3sNjicve3JK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware bug symbol in red floating abouve digital circuitry concept design]]></media:description>                                                            <media:text><![CDATA[Malware bug symbol in red floating abouve digital circuitry concept design]]></media:text>
                                <media:title type="plain"><![CDATA[Malware bug symbol in red floating abouve digital circuitry concept design]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N9ygzncFbwS3sNjicve3JK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US Justice Department and <a href="https://www.itpro.com/security/cyber-crime/358946/fbi-over-4-billion-lost-to-cyber-crime-in-2020">FBI</a> have revealed a joint operation with international partners was able to delete <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> injected by Chinese threat actors to thousands of devices around the world.</p><p><a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed" target="_blank">Announced</a> on 14 January, the months-long operation was conducted in collaboration with <a href="https://www.itpro.com/security/cyber-attacks/358618/france-identifies-wide-reaching-solarwinds-esque-cyber-attack">French law enforcement</a> in which the <a href="https://www.itpro.com/security/32630/ncsc-accuses-china-of-targeting-global-msps-in-malicious-cyber-campaign">PlugX malware</a> was removed from more than 4,200 computers worldwide.</p><p>According to court documents, the group behind the attack, referred to alternatively as Twill Typhoon or Mustang Panda, has been active from around 2014 and was paid by the PRC to develop a specific version of the PlugX malware for the intrusion campaign.</p><p>In the <a href="https://www.justice.gov/opa/media/1384136/dl" target="_blank">affidavit</a>, the FBI stated that the malware was used by the attackers to exfiltrate files and other information held on the computers of government agencies and private enterprises in the US, ostensibly for espionage purposes.</p><p>Foreign entities were also targeted, the FBI noted, with notable targets including European shipping companies in 2024 and a number of <a href="https://www.itpro.com/security/cyber-attacks/359960/eu-draft-plans-for-bloc-wide-cyber-task-force">European governments</a> between 2021 and 2023.</p><p>The joint operation was able to <a href="https://www.itpro.com/security/malware-cyber-security/28066/how-to-remove-malware-from-your-computer-3">remove the malware</a> from the target devices in this instance after a French law enforcement agency gained access to a command-and-control (C2) server that could send commands to infected devices.</p><p>French law enforcement identified the <a href="https://www.itpro.com/security/malware/two-notorious-infostealer-malware-operations-were-just-knocked-offline">malware’s infrastructure</a> included a native ‘self-delete’ functionality which they were able to leverage once they had control of the C2 server.</p><p>Once triggered, the mechanism deleted all the files created by the PlugX malware on the target device and all PlugX <a href="https://www.itpro.com/microsoft-windows/31861/a-hackers-guide-to-the-windows-registry">registry keys</a> used to automatically run the PlugX malware when the system is booted, as well as removing the PlugX application once it is stopped running. </p><h2 id="what-is-plugx">What is PlugX?</h2><p>The PlugX malware family has been observed in attacks from as early as 2008. It has been leveraged by multiple threat actors but researchers have typically associated its use with espionage-focused groups linked to China, including Mustang Panda.</p><p>Chris Jones, incident response analyst at <a href="https://www.itpro.com/channel/370212/check-point-software-snaps-up-former-td-synnex-boss-to-lead-channel-efforts">Check Point Software</a>, described PlugX as a modular malware with a variety of capabilities, all suited for espionage objectives.</p><p>“PlugX is a powerful remote access <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus">Trojan</a> (RAT) often used in targeted cyber-espionage campaigns. Its modular design allows attackers to tailor its capabilities to their specific needs, enabling activities like data theft, keylogging, file manipulation, and executing commands on infected systems,” he explained.</p><p>“It is typically spread through <a href="https://www.itpro.com/software/google-docs/361922/researchers-spot-spear-phishing-exploit-in-google-docs">spear-phishing</a> campaigns, exploiting vulnerabilities, or using malicious attachments to gain access.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ayY2eqwwgoPAZnhjhJrwDa" name="Bridging the gap_ How security teams can engage developers in security programs.jpg" caption="" alt="Bridging the gap: How security teams can engage developers in security programs" src="https://cdn.mos.cms.futurecdn.net/ayY2eqwwgoPAZnhjhJrwDa.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bridging-the-gap-how-security-teams-can-engage-developers-in-security-programs"><em>Strategies to engage developers in a security program</em></a></p></div></div><p>He added that efforts to neutralize the threat posed from <a href="https://www.itpro.com/security/hackers-are-taking-advantage-of-ai-hallucinations-to-sneak-malicious-software-packages-onto-enterprise-repositories">malicious tools</a> like PlugX usually revolve around targeting the infrastructure the malware relies on for execution, much like this most recent operation carried out by US and French law enforcement.</p><p> "Law enforcement agencies seizing servers used to facilitate PlugX operations are adding to efforts like the 2019 seizure of servers linked to the Imminent Monitor RAT. These coordinated actions demonstrate an ongoing commitment to dismantling cybercriminal infrastructure and protecting users from <a href="https://www.itpro.com/security/malware/361190/fontonlake-sophisticated-malware-targets-linux-systems">sophisticated malware</a> and privacy threats."</p><p>Matthew G. Olsen, assistant attorney general of the Justice Department’s National Security Division, said such operations rely on security agencies working together, praising the efforts of the French government in this instance.</p><p>“This operation, like other recent technical operations against Chinese and Russian hacking groups like <a href="https://www.itpro.com/security/cyber-crime/the-infamous-volt-typhoon-hacker-group-is-back">Volt Typhoon</a>, Flax Typhoon, and APT28, has depended on strong partnerships to successfully counter malicious cyber activity. I commend partners in the French government and private sector for spearheading this international operation to defend global cybersecurity.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Open source malware surged by 156% in 2024 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/open-source-malware-surged-by-156-percent-in-2024</link>
                                                                            <description>
                            <![CDATA[ Hackers are taking advantage of lax verification and surging demand to distribute and scale malware in record time ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Pxw3S5fvo9zuN4rU6Htq8i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Dec 2024 13:48:09 +0000</pubDate>                                                                                                                                <updated>Thu, 12 Dec 2024 11:15:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:description>                                                            <media:text><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:text>
                                <media:title type="plain"><![CDATA[Malware Detected Warning Screen with abstract binary code 3d digital concept]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qG3459Gnf43CVyu33sP7si-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The growth of open source <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> has continued apace in 2024, according to new <a href="https://www.sonatype.com/resources/whitepapers/2024-open-source-malware-threat-report" target="_blank">research</a>, with cyber criminals taking advantage of the proliferation of open source software.</p><p>A report from software <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1">supply chain management</a> firm Sonatype found there was a 156% increase in malicious packages identified on open source repositories over the past year.</p><p><a href="https://www.itpro.com/channel/370378/sonatype-expands-partner-benefits-with-new-partner-acceleration-program">Sonatype</a> has identified 778,529 malicious open source packages since it began tracking them in 2019, which it noted was an increase of 70,000 since its annual report was published in October.</p><p><a href="https://www.itpro.com/software/28109/what-is-open-source">Open source</a> malware are malicious packages that disguise themselves as legitimate open source software (OSS) to infiltrate software supply chains.</p><p>The three distinct characteristics of open source malware listed in the report were their intentional insertion into <a href="https://www.itpro.com/development/open-source/369920/350000-open-source-projects-vulnerable-15-year-old-python-bug">open source repositories</a> for malicious purposes, their specific targeting of developers, and ability to evade conventional detection methods.</p><p>Sonatype said this approach is able to circumvent <a href="https://www.itpro.com/security/endpoint-security/356810/bios-security-the-next-frontier-for-endpoint-protection">traditional security measures</a> and poses a unique threat to enterprises.</p><p>“This unique distribution method — compromised open source repositories — exploits gaps in <a href="https://www.itpro.com/software/development/red-hat-adds-trio-of-new-tools-to-its-trusted-software-supply-chain">dependency management tooling</a> and development build pipelines, bypassing conventional security mechanisms in order to attack software developers directly,” the report warned.</p><h2 id="npm-accounts-for-over-98-of-malicious-open-source-packages">Npm accounts for over 98% of malicious open source packages</h2><p>Sonatype noted that software repositories like npm and <a href="https://www.itpro.com/security/cyber-attacks/pypi-attack-targeting-of-repository-shows-no-sign-of-stopping">PyPI</a> process trillions of open source package requests each year, featuring a publishing model that is designed to ensure speed of delivery with the aim of helping foster agile development and innovation.</p><p>The unintended consequence of this model is that it makes it far easier for hackers to smuggle their malicious packages onto the platforms unnoticed. </p><p>For example, the report noted that npm, the world’s largest <a href="https://www.itpro.com/development/30202/what-is-javascript-and-why-should-i-learn-it">JavaScript</a> package registry, was disproportionately impacted by the plague of malicious packages.</p><p>Overall, npm accounted for 98.5% of the malicious packages identified by Sonatype over the course of 2024; whereas PyPI, the official package repository for <a href="https://www.itpro.com/software/development/368919/programming-with-python-time-to-upgrade-to-fancy-ansi">Python</a>, represented just 1% of open source malware Sonatype detected.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tvawFkCaNr5vdotoTDCE6Z" name="The life sciences guide to AI-driven innovations.jpg" caption="" alt="The life sciences guide to AI-driven innovations" src="https://cdn.mos.cms.futurecdn.net/tvawFkCaNr5vdotoTDCE6Z.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: AWS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/the-life-sciences-guide-to-ai-driven-innovations"><em>Why 9 out of the top 10 pharma companies choose AWS</em></a></p></div></div><p>In total, Sonatype found over 540,000 malicious components hosted on npm, dwarfing the roughly 5,000 <a href="https://www.itpro.com/security/three-million-docker-hub-repositories-are-being-used-to-spread-malware">malicious assets</a> identified on PyPI.</p><p>Sonatype said the ease of publishing on <a href="https://www.itpro.com/development/programming-languages/355022/microsoft-plans-to-integrate-npm-with-github-following">npm</a>, which allows devs to publish packages with minimal verification, means they can “upload malicious components quickly and at scale”.</p><p>The report added that npm has been a victim of surges of <a href="https://www.itpro.com/security/phishing/368899/pypi-packages-succumb-to-mailchimp-phishing-scam">spam packages</a> in recent years. </p><p>A significant proportion of this spam looks to simply <a href="https://www.itpro.com/technology/monetization-strategies-for-digital-content-creators">monetize</a> a high volume of downloads using protocols like Tea.xyz, whereas others are seeking to <a href="https://www.itpro.com/security/hackers-have-found-yet-another-way-to-trick-devs-into-downloading-malware-from-github">embed malware</a> into projects for more nefarious purposes.</p><p>Finally, the sheer scale of demand on the npm platform, which will have received an expected 4.5 trillion requests in 2024 – up 70% compared to 2023 – makes it an ideal target for threat actors looking to maximize their impact.</p><p>Speaking to <em>ITPro, </em>Steve Sandford, partner and head of digital forensics & incident response at CyXcel, outlined why npm is drawing the attention of cyber criminals over other popular open source repositories, and what businesses should be doing to mitigate the threat.</p><p>“The rise of open source malware is a growing concern as open source software becomes more integral to <a href="https://www.itpro.com/644149/gartner-enterprise-it-spending-to-show-scant-growth-in-2013">enterprise IT</a>. NPM is a popular target due to its dominance and high download volume, with minimal verification processes allowing malicious actors to introduce compromised packages easily,” he explained.</p><p>“In contrast, PyPI has a smaller user base. As technology evolves and uses increase, the threat of malware will likely grow. To mitigate these threats, enterprises should implement automated scanning tools, maintain an updated inventory of open source components, ensure regular updates and patching, conduct <a href="https://www.itpro.com/business-operations/managed-service-provider-msp/359166/the-definitive-guide-to-it-security">security assessments</a>, train employees, and develop an <a href="https://www.itpro.com/security/building-an-incident-response-strategy">incident response plan</a>.”</p><h2 id="over-15-billion-unvetted-shadow-downloads-in-2024">Over 15 billion unvetted shadow downloads in 2024</h2><p>But the report added that it discovered a large number of <a href="https://www.itpro.com/security/hackers-are-taking-advantage-of-ai-hallucinations-to-sneak-malicious-software-packages-onto-enterprise-repositories">malicious packages</a> that were bypassing repository managers altogether, and were being directly downloaded onto dev machines or shared build infrastructures.</p><p>Referred to as shadow downloads, Sonatype defines this trend as open source components taken  from a public repository but bypassing the artifact <a href="https://www.itpro.com/security/a-leaked-github-access-token-could-have-led-to-a-catastrophic-supply-chain-attack">repository manager</a>.</p><p>“This practice introduces unvetted and unobservable dependencies into projects, bypassing established <a href="https://www.itpro.com/security/data-governance-for-data-driven-organizations">governance</a>, review, and security processes," Sonatype explained</p><p>“While precise numbers vary by organization, recent insights indicate a surprising percentage in production environments originated from shadow downloads, escaping security review entirely.”</p><p>Sonatype warned that shadow downloads, which saw a 15.6 billion increase in downloads between December 2023 and November 2024, undermine <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-rife-this-is-what-developers-need-to-watch-out-for">software supply chain vulnerabilities</a> in several ways.</p><p>Firstly the lack of visibility of shadow downloads means they often go unnoticed, making it far more difficult to <a href="https://www.itpro.com/software/34583/avast-business-patch-management-review-don-t-give-up-the-day-job-just-yet">manage updates</a>. </p><p>Secondly, they expose systems to unvetted components, increasing the likelihood of introducing malicious packages, such as those associated with dependency confusion or typosquatting, Sonatype added.</p><p>Finally, bypassing repository managers means organizations no longer have the ability to enforce policies, such as release integrity checks or <a href="https://www.itpro.com/security/penetration-testing/357806/how-cyber-attack-simulations-differ-from-penetration-tests-and">vulnerability scans</a>, on the components.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two notorious infostealer malware operations were just knocked offline ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/two-notorious-infostealer-malware-operations-were-just-knocked-offline</link>
                                                                            <description>
                            <![CDATA[ Infrastructure linked to two major infostealer malware strains has been seized in a joint law enforcement operation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n7QDgqzmFDzEC4jv2EGMeN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Oct 2024 13:16:33 +0000</pubDate>                                                                                                                                <updated>Thu, 31 Oct 2024 14:49:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blue and gold mockup of motherboard with lock denoting malware and security]]></media:description>                                                            <media:text><![CDATA[Blue and gold mockup of motherboard with lock denoting malware and security]]></media:text>
                                <media:title type="plain"><![CDATA[Blue and gold mockup of motherboard with lock denoting malware and security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A joint operation of global law enforcement agencies has dismantled the operations of two prominent strains of infostealer <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>.</p><p>Operation Magnus, was a collaboration between Dutch National Police, the FBI, and agencies from Australia, Belgium, Portugal, and the UK, targeting the infrastructure underpinning the RedLine and Meta infostealers.</p><p>RedLine and Meta steal data including login credentials, as well as addresses, phone numbers, <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> wallets, and email addresses stored in web forms.</p><p>The tools can also be used by threat actors to bypass <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a> through the theft of authentication cookies and other system information.</p><p>“After retrieving the personal data, the infostealers sold the information to other criminals through criminal marketplaces. The criminals who purchased the personal data used it to steal money, cryptocurrency and to carry out follow-on hacking activities,” according to a <a href="https://www.eurojust.europa.eu/news/malware-targeting-millions-people-taken-down-international-coalition"><u>statement</u></a> from the European Union Agency for Criminal Justice Cooperation.</p><p>The statement added that investigations into the two malware operations began after victims came forward and a security company notified authorities about possible servers in the Netherlands linked to the campaign.</p><p>The authorities later discovered that over 1,200 servers in dozens of countries were running the malware.</p><p>On 28 October, the coalition of international agencies seized three servers in the Netherlands, two domains, and took two people into custody in Belgium.</p><p>Law enforcement also retrieved a database of clients from RedLine and Meta, which they state will be used in future investigations into criminals attempting to leverage the stolen data in future attacks.</p><h2 id="history-shows-cybercriminals-will-always-find-a-way">History shows cybercriminals will always find a way</h2><p>In conjunction with the disruption efforts, the US Justice Department unsealed charges against Maxim Rudometov, one of the developers and administrators of RedLine.</p><p>Rudometov could face a maximum penalty of 35 years, according to the Attorney’s Office for the Western District of Texas, if convicted, facing charges of access device fraud, conspiracy to commit computer intrusion, and money laundering.</p><p>This follows a number of operations carried out by law enforcement agencies aimed at disrupting the operations of high profile cyber crime groups around the world. </p><p>In December 2023, US authorities seized the leak site of <a href="https://www.itpro.com/security/ransomware/alphv-leak-site-seized-by-law-enforcement-as-decryption-tool-released">ALPHV/BlackCat</a>, one of the most prolific ransomware collectives of recent years, which was hailed as a significant blow to the operation. </p><p>Yet just two months later in February 2024, <a href="https://www.itpro.com/security/what-is-cisa">CISA</a> issued an updated advisory warning of a new version of the group’s ransomware locker, which had been observed targeting healthcare organizations in the US.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ayY2eqwwgoPAZnhjhJrwDa" name="Bridging the gap_ How security teams can engage developers in security programs.jpg" caption="" alt="Bridging the gap: How security teams can engage developers in security programs" src="https://cdn.mos.cms.futurecdn.net/ayY2eqwwgoPAZnhjhJrwDa.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bridging-the-gap-how-security-teams-can-engage-developers-in-security-programs"><em>Engage developers in security programs</em></a></p></div></div><p>Since then, in September 2024 researchers reported a new ransomware encryptor dubbed ‘Cicada3301’ appeared to be a more advanced iteration of the encryptor used by BlackCat, indicating the group’s impact on the cyber crime industry will be harder to stamp out.</p><p>In February 2024, a joint operation took control of the infrastructure used by the prominent <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> collective LockBit, including its primary administration environment, leak site, platform source code, and a vast amount of intelligence about the group’s activities gleaned from the seized systems.</p><p>Days after the breach, security experts told <em>ITPro </em>they expected <a href="https://www.itpro.com/security/ransomware/life-after-lockbit-a-fragmented-landscape-and-wayward-affiliates-will-still-cause-chaos-for-enterprises">LockBit affiliates</a> to quickly find a new ransomware operator to work with, and the ransomware industry was far from being brought to its knees.</p><p><a href="https://www.itpro.com/security/ransomware/lockbit-takedown-is-a-huge-win-for-law-enforcement-but-lets-not-celebrate-too-soon-security-experts-warn">LockBit</a> re-emerged in September 2024, claiming responsibility for a cyber attack on Canada’s largest school board in Toronto, but analysts said this was likely a fabrication in an attempt to rebuild the group’s waning reputation.</p><p>On 5 July 2024, a joint operation led by Europol shut down almost 600 servers used to conduct malicious attacks leveraging the Cobalt Strike threat simulation tool.</p><p>Despite the significant disruption caused by the operations, security pros warned it would not put an end to the malicious use of <a href="https://www.itpro.com/security/cyber-crime/hundreds-of-cobalt-strike-servers-have-been-taken-offline-in-a-major-law-enforcement-sting">Cobalt Strike</a> by threat actors. </p><p>Although the operation was a ‘big win’ for law enforcement, they noted there were plenty of opportunities for threat actors to continue using the tool for malicious purposes.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>