• The Federal Bureau of Investigation (FBI) has issued urgent warnings about cybercriminals spoofing the official Internet Crime Complaint Center (IC3) website to conduct phishing attacks and steal sensitive personal information.

    These fake sites mimic the legitimate www.ic3.gov portal with near-perfect replicas, borrowing content, layouts, and visuals to deceive users into submitting names, addresses, phone numbers, emails, and banking details.

    Recent screenshots reveal impostor domains like “ichelpindex.com,” flagged as non-official, appearing in security scans such as VirusTotal searches for “ic3.”

    Threat actors exploit victims’ trust in the IC3, the FBI’s primary hub for reporting cybercrimes like fraud and scams. Users often land on these fakes via search engines, sponsored links, or manipulated online forums where scammers pose as fellow victims, directing traffic to phony IC3 recovery services.

    In one variant, fraudsters impersonate IC3 staff via Telegram, promising fund recovery but extracting more data for account takeovers. The FBI noted over 100 such impersonation reports between late 2023 and early 2025, with spoofed sites surging in 2025, prompting PSAs in April and September.​

    Spotting Fake IC3 Sites

    Silent Push observed these phishing pages replicate the real site’s welcome message and complaint form but use altered domains with misspellings or non-.gov top-level domains.

    Security tools highlight discrepancies, such as suspicious search rankings excluding the official ic3.gov. Victims, believing they’ve filed legitimate reports, unwittingly aid further crimes like financial theft or identity fraud.​

    IndicatorReal IC3 (www.ic3.gov)​Fake Sites
    DomainEnds in .govAlternate spellings or TLDs like .com
    Access MethodType directly in browserSearch engines, sponsored ads
    RequestsNo payments for recoveryDemands personal/financial info
    Social MediaNoneFake profiles directing to sites
    GraphicsProfessional U.S. gov styleMay have low-quality artifacts

    The FBI urges typing www.ic3.gov directly into browsers, avoiding sponsored search results, and verifying .gov endings. Never share sensitive data on unverified sites, and report suspicions only via the official portal.

    malicious websites

    IC3 maintains no social media and never requests payments for fund recovery. Recent FBI social posts on November 25 reinforced these alerts amid rising complaints.​

    Public vigilance remains crucial as scammers evolve tactics, targeting prior scam victims seeking recourse. By sticking to direct navigation and skepticism, users can thwart these sophisticated phishing operations.​

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post FBI Warns of Fake Internet Crime Complaint Center (IC3) Website Used for Phishing Attacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Akira ransomware group has begun weaponizing vulnerabilities in SonicWall SSL VPN devices, turning merger-and-acquisition (M&A) processes into high-speed launchpads for cyberattacks.

    This trend exposes dangerous blind spots for businesses acquiring smaller companies, as inherited SonicWall devices often serve as easy entry points for attackers.

    How Akira Ransomware Targets M&A Environments

    During mergers and acquisitions, acquiring companies often inherit IT infrastructure with outdated security practices.

    Akira operators exploit these weaknesses, swiftly exfiltrating sensitive data and deploying ransomware.

    According to Relia Quest, in recent incidents analyzed between June and October 2025, attackers gained initial access to larger enterprise networks using SonicWall SSL VPN appliances left over from smaller, acquired companies.

    Once inside, Akira’s operators seek out privileged credentials, many of which are carried over during the M&A transition.

    These credentials, usually unknown to the acquiring business and left unmonitored, provide rapid access to vital systems.

    In some cases, attackers moved from initial compromise to a domain controller in just five hours, well before defenders could respond.

    Small- and medium-sized businesses value SonicWall SSL VPNs for their affordability and ease of use. However, these benefits come with risks:

    • Widespread deployment: Popular among smaller firms, SonicWall devices often end up in environments acquired during M&A.
    • Default configurations: Many appliances operate with unchanged passwords, legacy admin accounts, and outdated settings.
    • Unpatched vulnerabilities: Hasty deployments and resource constraints often lead to patching being overlooked.
    • Exposed features: Remote access tools are sometimes accessible from the internet, leaving sensitive systems unprotected.

    These factors make SonicWall devices reliable entry points for ransomware groups looking to exploit inherited security weaknesses.

    Once Akira operators compromise a SonicWall device, they rapidly scan for high-value hosts.

    Predictable naming conventions inherited from the acquired business make it easy for attackers to locate targets such as domain controllers and file servers.

    In several cases, attackers exfiltrated data within minutes of gaining access, then laterally moved to deploy ransomware within an hour.

    One particular weakness was inconsistent endpoint protection. Inherited networks frequently lacked modern EDR (Endpoint Detection and Response) solutions or had disabled protection.

    Akira operators exploited these gaps by using DLL sideloading to disable defenses before encrypting systems.

    The rapid adoption of SonicWall devices in smaller companies, paired with inherited security debt, creates complex risks during M&A:

    • Stale credentials: Old admin accounts from managed service providers remain active and unmonitored post-acquisition.
    • Missing inventories: Not all assets are tracked during integration, giving attackers places to hide.
    • Mix-and-match security: Different security tools and protocols can leave gaps, which attackers exploit to move unobstructed.

    Without rigorous asset discovery and credential hygiene, defenders are left vulnerable, with inherited weaknesses exposing the entire organization.

    With fast-moving ransomware like Akira, early action is key to preventing devastating breaches and protecting sensitive data.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Akira Ransomware Uses SonicWall VPN Exploit to Exfiltrate Sensitive Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers at Socket have uncovered a deceptive Chrome extension called Crypto Copilot that masquerades as a legitimate Solana trading tool while secretly siphoning SOL from users’ swap transactions. The malicious extension, published on June 18, 2024, extracts undisclosed fees by injecting hidden transfer instructions into every transaction users execute. Crypto Copilot markets itself on […]

    The post Chrome Extension Malware Secretly Adds Hidden SOL Fees to Solana Swap Transactions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated ClickFix campaign dubbed “JackFix” that uses fake adult websites to hijack screens with realistic Windows Update prompts, tricking users into running multistage malware payloads.

    Attackers mimic popular adult sites like xHamster clones to lure victims, likely via malvertising on shady platforms. Interaction with the phishing page triggers a full-screen overlay resembling a critical Windows security update, complete with animations, progress bars, and blue-screen styling.

    fake Windows update screen

    This “screen hijacking” combines urgency from the update theme with embarrassment from adult content, pressuring hasty compliance.

    The attack’s entry point often involves fake adult websites, such as clones of popular platforms like xHamster and PornHub, which are likely promoted through malvertising.

    Once a user interacts with one of these sites, the “JackFix” attack is triggered. The browser is forced into full-screen mode, displaying a convincing “Critical Windows Security Updates” screen, complete with animations and progress counters.

    Fake Jakefix Attack

    JackFix Attack Leverages Windows Updates

    This screen-locking technique, reminiscent of older screen-locker malware, pressures the victim into following on-screen instructions to resolve a fabricated security issue.

    The fake interface disables standard escape keys like Escape and F11, though not fully effectively in tested browsers. This method preys on a user’s sense of urgency and familiarity to compromise their systems.

    The threat actors have implemented several advanced methods to evade detection. The campaign not only obfuscates its malware payloads but also the very commands used to initiate the ClickFix attack, allowing it to bypass many current prevention tools.

    Furthermore, the malicious URLs used in the attack employ a clever redirection strategy. If accessed directly, they redirect to benign sites like Google or Steam, but they deliver the malicious payload only when accessed via specific PowerShell commands.

    powers

    This tactic helps the attacker’s infrastructure avoid being flagged as malicious by security analysis tools like VirusTotal.

    Once the victim is tricked into running the initial commands, a multistage attack chain is initiated. The process begins with mshta, which leads to a PowerShell downloader.

    This second-stage script bombards the user with User Account Control (UAC) prompts, effectively rendering the machine unusable until administrative privileges are granted. After gaining elevated access, the script proceeds to deploy a staggering number of malware samples simultaneously.

    In what researchers describe as a “spray and prey” strategy, a single infection can execute eight different malware variants. The deployed malware includes the latest versions of potent info-stealers like Rhadamanthys, Vidar 2.0, and RedLine, as well as the Amadey botnet client and various loaders and Remote Access Trojans (RATs).

    This massive deployment ensures that even if some payloads are blocked, others are likely to succeed, posing a severe risk of data theft, including passwords and cryptocurrency wallets.

    The researchers noted that this unique combination of psychological manipulation, advanced obfuscation, and multi-payload delivery makes the “JackFix” campaign a significant and evolving threat.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post New “JackFix” Attack Leverages Windows Updates into Executing Malicious Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A cybercriminal operating under the alias ByteToBreach has emerged as a prominent figure in the underground data trade, orchestrating a series of high-profile breaches targeting critical sectors worldwide. Active since at least June 2025, ByteToBreach has leveraged a blend of technical proficiency, aggressive self-promotion, and cross-platform operations to become one of the most publicized threat […]

    The post Massive Data Leak: ByteToBreach Offers Stolen Global Airline, Banking, and Government Records appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • More than two decades after its initial discovery, the NTLM authentication protocol continues to plague Windows systems worldwide.

    What started in 2001 as a theoretical vulnerability has evolved into a widespread security crisis, with attackers actively weaponizing multiple NTLM flaws to compromise networks across different regions.

    The New Technology LAN Manager (NTLM) protocol was designed to authenticate clients and servers in Windows environments using a three-step handshake.

    Although Microsoft has announced plans to retire NTLM entirely, beginning with Windows 11 24H2 and Windows Server 2025, the protocol remains embedded in millions of systems.

    This persistence creates an open window for cybercriminals who continue to discover and exploit new vulnerabilities in NTLM’s outdated mechanisms.

    Multiple Attack Vectors Under Active Exploitation

    NTLM flaws enable several dangerous attack techniques. Hash leakage occurs when attackers craft malicious files that trick Windows into sending authentication hashes without requiring user interaction.

    CVE IDSeverityAffected SystemsImpactKnown Campaigns
    CVE-2024-43451HighWindows (Multiple Versions)Hash Leakage, Credential CompromiseBlindEagle (Remcos RAT), Head Mare
    CVE-2025-24054/CVE-2025-24071HighWindows 11, Windows ServerHash Leakage, Unauthorized AccessTrojan Distribution in Russia (AveMaria/Warzone)
    CVE-2025-33073HighWindows (SMB Client)Privilege Escalation to SYSTEM LevelUzbekistan Financial Sector Attack

    Coercion-based attacks force systems to authenticate to attacker-controlled services.

    Once credentials are compromised, attackers use credential-forwarding techniques such as Pass-the-Hash to move laterally across networks and escalate privileges without knowing the actual passwords.

    Man-in-the-middle attacks remain particularly effective, with NTLM relay remaining the most impactful method for two decades. Attackers position themselves between clients and servers to intercept authentication traffic and capture credentials.

    Security researchers have identified several critical NTLM vulnerabilities that are currently being actively exploited in 2024 and 2025.

    CVE-2024-43451 enables NTLMv2 hash leakage through malicious .url files. Simply interacting with these files clicking, right-clicking, or moving them automatically connects to attacker servers running WebDAV.

    The BlindEagle APT group exploited this vulnerability to distribute the Remcos RAT to Colombian targets. At the same time, the Head Mare hacktivists exploited it against Russian and Belarusian organizations.

    CVE-2025-24054 and CVE-2025-24071 target .library-ms files inside ZIP archives, causing automatic NTLM authentication to attacker-controlled servers. Researchers detected campaigns in Russia distributing the AveMaria Trojan using this method.

    CVE-2025-33073 represents a hazardous reflection attack. Attackers manipulate DNS records to trick Windows into treating external authentication requests as local, bypassing regular security checks and granting SYSTEM-level privileges.

    According to SecureList, suspicious activity exploiting this vulnerability was detected in Uzbekistan’s financial sector.

    Despite Microsoft addressing these vulnerabilities through patches, the legacy protocol’s continued presence in enterprise networks means attacks will persist.

    Organizations maintaining NTLM for compatibility with older applications remain particularly vulnerable. Security teams should prioritize migrating to Kerberos, implementing network segmentation, and monitoring for suspicious authentication attempts across their Windows infrastructure.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Exploit NTLM Authentication Flaws to Target Windows Systems appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybercriminals are now selling lifetime access to malicious AI chatbots WormGPT and KawaiiGPT for as little as $220, marking a dangerous new chapter in AI-powered cybercrime.

    These tools remove all ethical restrictions found in mainstream AI models, enabling attackers to generate phishing emails, create ransomware, and automate hacking operations with minimal technical skill.

    Large language models present a fundamental challenge for security professionals. The same capabilities that make AI useful for defense also make it powerful for attacks.

    Attackers can use AI to generate convincing phishing messages, create malware code, and automate reconnaissance activities. The line between a helpful research tool and a dangerous weapon often depends only on the user’s intent.

    WormGPT Returns with Commercial Pricing

    The original WormGPT appeared in July 2023 as one of the first commercial malicious AI tools. Built on the open-source GPT-J 6B model, it was trained on malware code, exploit guides, and phishing templates.

    WormGPT ad found on Hack Forums
    WormGPT ad found on Hack Forums.

    After media attention forced its shutdown, the brand has returned as WormGPT 4.

    The new version operates through Telegram and underground forums with transparent subscription pricing. Monthly access costs $50, annual access costs $175, and lifetime access costs $220.

    WormGPT 4 generates a rudimentary ransomware script impacting PDF files
    WormGPT 4 generates a rudimentary ransomware script impacting PDF files

    The tool has attracted over 500 subscribers to its Telegram channel since sales began around September 27, 2025.

    Unit 42 researchers tested WormGPT 4 and found that it can instantly generate working ransomware scripts.

    When asked to create code to encrypt PDF files, it produced a functional PowerShell script using AES-256 encryption with command-and-control server support. The model also creates professional ransom notes with 72-hour payment deadlines.

    KawaiiGPT Offers Free Access

    While WormGPT requires payment, KawaiiGPT provides similar capabilities completely free. First identified in July 2025, this tool is available on GitHub and can be set up in under five minutes on Linux systems.

     KawaiiGPT generates a spear phishing message
     KawaiiGPT generates a spear phishing message

    Despite its cute name and friendly interface, KawaiiGPT generates dangerous content.

    Researchers found it can create convincing spear-phishing emails that appear to come from banks, produce Python scripts for lateral network movement, and generate code for data exfiltration targeting email files.

     Example of a ransom note created from a prompt in KawaiiGPT
     Example of a ransom note created from a prompt in KawaiiGPT

    According to Palo Alto Networks, the tool claims to have over 500 registered users, with several hundred active users each week. An active Telegram community of 180 members shares tips and feature requests.

    These tools represent a significant shift in the threat landscape. Previously, creating convincing phishing campaigns or functional malware required substantial technical expertise.

    Now, anyone with internet access can use these AI tools to launch sophisticated attacks in minutes rather than days.

    Security defenders can no longer rely on traditional warning signs, such as poor grammar or sloppy code, to identify threats.

    The democratization of AI-powered cybercrime means organizations must strengthen their defenses against increasingly polished and automated attacks.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Sell Lifetime Access to WormGPT and KawaiiGPT for Just $220 appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In a significant escalation of cyber threats, Arctic Wolf Labs has identified a coordinated campaign in which the Russian-aligned RomCom threat group leverages the SocGholish malware to target a U.S.-based engineering firm with suspected ties to Ukraine. This marks the first documented instance of RomCom payloads being distributed through SocGholish’s infrastructure, signaling a dangerous convergence […]

    The post Threat Actors Use Fake Update Lures to Deploy SocGholish Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new offensive security tool developed in Rust is demonstrating a novel method for bypassing modern Endpoint Detection and Response (EDR) systems by exploiting an overlooked behavior in the Windows API.

    Dubbed Indirect-Shellcode-Executor, the tool leverages the ReadProcessMemory function to inject shellcode, effectively avoiding standard API calls that security vendors monitor for malicious activity.

    The core of this technique relies on research originally discovered by security researcher Jean-Pierre LESUEUR (DarkCoderSc). While ReadProcessMemory is designed to read data from a specific process, it contains an [out] pointer parameter named *lpNumberOfBytesRead.

    This parameter is intended to report how much data was successfully read. However, by manipulating this pointer, an attacker can force the API to write data into the process memory.

    This behavior creates a “write primitive” using a “read” function. Because the tool avoids standard memory manipulation APIs such as WriteProcessMemory or memcpy it creates a blind spot for Antivirus (AV) and EDR solutions that rely on hooking those specific functions to detect code injection.

    Rust-Based Implementation for Red Teams

    The Indirect-Shellcode-Executor, developed by researcher Mimorep, is a fully operational Proof of Concept (PoC) written in Rust. Unlike theoretical exploits, this tool is designed for immediate use in Red Team operations to test defensive postures.

    The tool compiles specifically for x32 architectures (via i686-pc-windows-msvc) and offers three distinct attack surface scenarios for operators:

    1. Remote Payload Execution: The tool can fetch shellcode directly from a remote Command and Control (C2) server (e.g., hiding a payload inside a PNG file) and execute it in memory.
    2. Terminal Injection: Operators can pass shellcode strings or binaries directly through the command line interface for immediate execution.
    3. File-Based Execution: The tool can read payloads concealed within local files, such as documents or temporary files, and inject them into the process.

    This tool highlights the persistent challenge facing security vendors: the Windows API is vast, and legitimate functions can often be repurposed for evasion.

    By utilizing *lpNumberOfBytesRead to construct a payload byte-by-byte, the Indirect-Shellcode-Executor operates underneath the radar of heuristic analysis that looks for rapid memory writing sequences.

    The developer has made the tool open-source to demonstrate the vulnerability, crediting DarkCoderSc for the initial discovery of the pointer vulnerability, which was documented on the Unprotect Project.

    Security teams are advised to review their API monitoring rules to account for unusual calls to ReadProcessMemory, particularly those where the output pointer targets executable memory sections.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Indirect-Shellcode-Executor Tool Exploits Windows API Vulnerability to Evade AV and EDR appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Enterprises today are expected to have at least 6-8 detection tools, as detection is considered a standard investment and the first line of defense. Yet security leaders struggle to justify dedicating resources further down the alert lifecycle to their superiors. As a result, most organizations’ security investments are asymmetrical, robust detection tools paired with an under-resourced SOC,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶