Normal view

There are new articles available, click to refresh the page.
Before yesterdayGBHackers

Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers

21 July 2026 at 09:51

Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to […]

The post Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops

21 July 2026 at 09:27

In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as […]

The post New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge

21 July 2026 at 08:40

Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year‑over‑year surge in Qilin activity that reshapes the threat landscape. The data points to a structurally higher operating tempo, a middle‑market pivot, and attacker visibility that often outpaces defenders’ own understanding of their […]

The post 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT

21 July 2026 at 07:42

Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly […]

The post Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data

21 July 2026 at 06:57

JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential […]

The post JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows

21 July 2026 at 05:48

AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows and exposing high‑value developer and CI/CD environments to remote access, credential theft, and further lateral movement. Malicious versions were shipped for @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, and @asyncapi/specs@6.11.2 and 6.11.2-alpha.1, together accounting for […]

The post AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

21 July 2026 at 04:40

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is […]

The post Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware

21 July 2026 at 03:34

AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent‑readable READMEs, public AI registries, and GitHub trust signals into a weaponized “AI capability supply chain,” attackers now […]

The post AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets

21 July 2026 at 02:44

Fileless stealer and PureRAT operators are abusing a WebDAV‑backed “malware delivery lab” to raid browser passwords, Telegram sessions, and cryptocurrency wallets in a campaign that blends fileless info‑stealing with a modular .NET RAT. The incident began with an MDR alert tied to a user executing content retrieved from a WebDAV server via rundll32.exe, with telemetry […]

The post Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids

21 July 2026 at 01:48

Bit2Watt is a newly disclosed cyber‑physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid‑scale threat surface. Measurements on NVIDIA accelerators show sub‑millisecond power ramps where a single Volta V100 or RTX‑series GPU swings from low-load phases to near‑TDP draw, […]

The post Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments

21 July 2026 at 01:08

Hackers are increasingly blending malicious traffic with legitimate services, and a newly uncovered campaign shows how far this tactic has evolved. The activity has been attributed to a threat actor with links to East Asia, with researchers uncovering a previously undocumented malware suite comprising TELESHIM, MIXEDKEY, and a final-stage implant dubbed BINDCLOAK. The campaign demonstrates […]

The post Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details

20 July 2026 at 09:28

A rapidly evolving malware family dubbed TELEPUZ, a modular and lightweight threat that is gaining traction through a ClickFix–VIDAR infection chain. Despite a relatively small command-and-control (C2) footprint, the pace of development and distribution suggests an emerging large-scale operation. The infection begins with ClickFix social engineering, where victims are tricked into executing a malicious PowerShell […]

The post TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor

20 July 2026 at 06:44

A newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in July 2026, alongside a CISA advisory, confirm that multiple vulnerabilities are already being weaponized against […]

The post One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million

20 July 2026 at 02:42

U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That enabled widespread cyberattacks against critical sectors, causing losses exceeding $62 million across at least 21 U.S. states and multiple countries. The defendants Alexander Alexandrovich Volosovik, 43, Kirill Andreevich Zatolokin, 34, […]

The post U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack

20 July 2026 at 02:03

GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015 and, since 2024, has consistently leveraged stolen or abused code-signing certificates to bypass Windows SmartScreen […]

The post GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images

20 July 2026 at 01:39

A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking DPRK-linked activity note that the campaign continues to impersonate recruiters and job interview workflows, luring […]

The post North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets

17 July 2026 at 09:40

A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed “Starland RAT,” alongside a stealthy in-memory PowerShell implant known as the “WLDR agent.” The operation targets users across the United States and parts of Europe, with a primary focus on […]

The post New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla

17 July 2026 at 09:22

Hackers are increasingly abusing trusted file formats and lightweight scripting environments to evade detection, with a newly observed campaign leveraging Lua-based loaders. Disguised as TrueType (.ttf) font files to deploy commodity malware, including Remcos RAT, Agent Tesla, XWorm, and Snake Keylogger variants. The campaign impersonates legitimate businesses and brands in email lures, often using payment-themed […]

The post Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day

17 July 2026 at 08:28

Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain observed in June 2026. The campaign reflects a fast-paced, hands-on-keyboard intrusion combined with automated lateral movement, signaling a threat actor capable […]

The post Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure

17 July 2026 at 06:55

NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform. In early July 2026, researchers identified NadMesh as a high‑volume Go-written botnet that was aggressively deploying bot agents across internet‑facing […]

The post New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌