The U.S. Treasury Department's Office of Foreign Assets Control has imposed sanctions on Russian bulletproof hosting service provider Aeza Group over its support of ransomware and information-stealing malware operations aimed at U.S. technology firms and defense organizations.
Bogus software installers leveraged in novel Chinese malware attack SecurityWeek reports that Chinese advanced persistent threat group Silver Fox has been using counterfeit installers for widely used software, such as WPS Office, DeepSeek, and Sogou, to facilitate compromise with Sainbox RAT, a variant of Gh0stRAT, and the Hidden rootkit.
Hacking operation UAC-0226 has upgraded its GIFTEDCROOK information-stealing malware to allow intelligence gathering in attack campaigns between April and June, according to The Hacker News.
Attacks involving malware masquerading as widely used software and services have impacted nearly 8,500 small and medium-sized business users during the first four months of 2025, GBHackers News reports.