Multiple Windows LNK files have been used by the XDSpy cyberespionage operation to compromise Eastern European government organizations with the XDigo malware in March, The Hacker News reports.
BleepingComputer reports that attacks exploiting Signal chats to deploy novel BeardShell and SlimAgent payloads have been launched by Russian state-sponsored hacking group APT28, also known as UAC-001, against Ukrainian government targets.
Newly emergent threat operation Mocha Manakin has leveraged the ClickFix attack technique to deploy the novel NodeInitRAT malware as part of an attack campaign initially observed earlier this year, reports Cyber Security News.
GBHackers News reports that at least 695 servers around the world have been compromised with the Pickai stealer backdoor in attacks involving critical flaws impacting the popular artificial intelligence image-generation model ComfyUI since March.
Security Affairs reports that malicious cheat tool-impersonating Java or .NET stealers spread through the Stargazers distribution-as-a-service network have been compromising Minecraft players with multi-stage malware since March.
Threat actors have deployed a more advanced fileless version of the Masslogger credential-stealing malware as part of a new campaign aimed at French users, Cyber Security News reports.
More than 3,775 Android devices have been infected with the AntiDot Android malware-as-a-service botnet across 273 attack campaigns, reports The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.