Investigation led by South Korean authorities revealed that leading mobile carrier KT Corp. had hidden multiple malware infections and breaches that resulted in a recent cyberattack involving illegal micro base stations, according to the Yonhap News Agency.
The attack, uncovered in July 2025, featured a phishing campaign using password-protected archives to distribute a new backdoor called BackDoor.ShellNET.1.
Windows machines' Hyper-V hypervisors are being targeted by Russia-linked threat operation Curly COMrades to establish a concealed Alpine Linux-based virtual machine enabling long-term network compromise and malware delivery as part of an attack campaign that commenced in July, The Register reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.