• Reports of a possible law enforcement operation against Rhadamanthys Stealer infrastructure have created waves in the cybersecurity community.

    The information stealer, which has been active in the threat landscape for several months, appears to have suffered a major disruption to its command and control servers.

    Users of the malware-as-a-service platform have reported difficulties accessing their control panels, while the main onion domains associated with Rhadamanthys remain unavailable.

    The situation came to light when the malware administrator issued an urgent message to customers, advising them to pause their operations and reinstall servers immediately.

    This unusual directive suggests that the infrastructure may have been compromised or taken over by authorities.

    The timing and nature of these events point to a coordinated takedown effort, though official confirmation from law enforcement agencies has not yet been released.

    Threat intelligence analyst Gi7w0rm, who has been closely monitoring the situation, reported that Rhadamanthys domains appear to be under active law enforcement control.

    The analyst also noted that customers were being advised to delete all servers. Security researcher g0njxa confirmed multiple reports of the infrastructure disruption, stating that users were experiencing login problems to their control panels.

    Infrastructure Disruption and Operational Impact

    The apparent seizure has created immediate problems for threat actors who rely on Rhadamanthys for their malicious operations.

    The stealer, known for its ability to extract sensitive data including credentials, cryptocurrency wallets, and browser information, operates through a network of command and control servers.

    When these servers go offline or fall under law enforcement control, the entire operation becomes ineffective. Stolen data cannot be transmitted back to the attackers, and new infections cannot receive updated instructions or configurations.

    The admin’s instruction to reinstall servers indicates an attempt to rebuild the infrastructure on new, uncompromised systems.

    However, this process requires significant effort and may leave the operation vulnerable during the transition period.

    For organizations previously targeted by Rhadamanthys, this disruption provides a window of opportunity to strengthen their defenses before the threat actors can fully reestablish their operations.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Rhadamanthys Stealer Servers Possibly Seized – Admin Urges to Reinstall Servers appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Malware families like Rhadamanthys Stealer, Venom RAT, and the Elysium botnet have been disrupted as part of a coordinated law enforcement operation led by Europol and Eurojust. The activity, which is taking place between November 10 and 13, 2025, marks the latest phase of Operation Endgame, an ongoing operation designed to take down criminal infrastructures and combat ransomware enablers

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The English-speaking cybercriminal ecosystem, commonly known as “The COM,” has transformed from a niche community of social media account traders into a sophisticated, organized operation fueling some of the world’s most damaging cyberattacks.

    What started as simple forums for trading rare social media handles has evolved into a professional, service-driven criminal marketplace targeting multinational corporations, government agencies, and critical infrastructure across the globe.

    The COM’s growth accelerated during the cryptocurrency boom between 2020 and 2021, when cybercriminals shifted their focus from stealing social media accounts to draining digital wallets containing millions of dollars.

    This shift introduced new attack methods and monetization strategies that fundamentally changed the landscape of cybercrime.

    The ecosystem now operates as a comprehensive supply chain where specialized roles work together seamlessly to execute coordinated attacks.

    CloudSEK security analysts identified that The COM’s operational structure mirrors legitimate business models.

    Different threat actors specialize in specific roles—some handle social engineering through vishing calls, others manage credential theft, and specialized teams handle data exfiltration and money laundering.

    This specialization allows criminal operations to scale rapidly while distributing risk across multiple independent actors.

    The emergence of groups like Lapsus$ and ShinyHunters demonstrated The COM’s evolution into theatrical, publicity-driven operations.

    Lapsus$ became infamous for breaching major tech companies, including NVIDIA, Samsung, and Microsoft, by manipulating customer support staff through social engineering.

    The group pioneered a “leak-and-brag” approach, publicly taunting victims and law enforcement while threatening data releases to accelerate ransom payments.

    The Attack Mechanism: Targeting the Human Perimeter

    CloudSEK security researchers noted that The COM’s most effective weapon is social engineering rather than technical exploits.

    The primary infection vector involves human manipulation through vishing crews who impersonate IT support staff, telecom providers, or corporate help desk personnel.

    These operators deceive employees into revealing credentials, approving remote access, or executing system commands that grant attackers entry to corporate networks.

    The technique operates through a simple principle: compromising a person is easier than compromising a device. Attackers use detailed victim profiling gathered through open-source intelligence and breached data, enabling highly targeted campaigns.

    Once inside networks, attackers leverage legitimate tools like Remote Desktop Protocol and cloud services to move laterally, avoiding detection by blending with regular administrative traffic.

    This approach has proven devastatingly effective against even organizations with advanced security infrastructure, making human-focused security measures increasingly critical for enterprise defense strategies moving forward.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post English-Speaking Cybercriminal Ecosystem ‘The COM’ Drives a Wide Spectrum of Cyberattacks appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Law enforcement agencies disrupted a vast network of cybercrime tools between November 10 and 14, 2025, coordinated from Europol’s headquarters in The Hague, Netherlands.

    Dubbed the latest phase of Operation Endgame, the effort targeted three notorious malware families: the infostealer Rhadamanthys, the Remote Access Trojan (RAT) VenomRAT, and the Elysium botnet.

    These stealers and botnets have contributed to ransomware attacks and data theft globally, impacting hundreds of thousands of victims and stealing millions in credentials and cryptocurrency.

    Rhadamanthys stealer
    Rhadamanthys stealer

    The operation, led by Europol and Eurojust, united authorities from 11 countries, including Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, the United Kingdom, and the United States.

    Private sector partners played a pivotal role, with contributions from cybersecurity firms like Cryptolaemus, Shadowserver, SpyCloud, Proofpoint, CrowdStrike, Lumen, Abuse.ch, Have I Been Pwned, Spamhaus, DIVD, and Bitdefender. Their expertise in threat intelligence, sinkholing, and malware analysis helped identify and neutralize the infrastructure.

    The dismantled network comprised hundreds of thousands of compromised computers holding millions of stolen credentials.

    Rhadamanthys alone granted its operators access to over 100,000 cryptocurrency wallets, potentially valued at millions of euros.

    Many victims remain unaware of infections, underscoring the stealthy nature of these threats. Infostealers quietly harvest login details, while RATs like VenomRAT enable remote control for espionage or ransomware deployment, and botnets like Elysium amplify distributed denial-of-service (DDoS) attacks and spam campaigns.

    Web page seized
    Web page seized

    Europol’s command post in The Hague buzzed with over 100 officers from participating nations, facilitating real-time intelligence sharing on seized servers, suspects, and data transfers. Eurojust supported legal tools like European Arrest Warrants and Investigation Orders.

    Operation Endgame, focused on ransomware enablers since its inception, signals no end to the fight. Authorities urge individuals to check for infections using resources like politie.nl/checkyourhack and haveibeenpwned.com.

    As cybercriminals adapt, this phase highlights the power of global collaboration in disrupting underground economies. Victims and researchers alike should monitor for residual threats, as the next move in this cyber chess game looms.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Operation Endgame – 1,000+ Servers Used by Rhadamanthys, VenomRAT, and Elysium Dismantled appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Between November 10 and 14, 2025, law enforcement agencies executed one of the most significant coordinated operations against cybercriminals in recent history. Operation Endgame, coordinated from Europol’s headquarters in The Hague, successfully dismantled three major threats to global cybersecurity: the infamous Rhadamanthys infostealer, the VenomRAT remote access trojan, and the Elysium botnet. This remarkable international […]

    The post Operation Endgame: Authorities Takedown 1,025 Servers Linked to Rhadamanthys, VenomRAT, and Elysium appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Behind every click, there’s a risk waiting to be tested. A simple ad, email, or link can now hide something dangerous. Hackers are getting smarter, using new tools to sneak past filters and turn trusted systems against us. But security teams are fighting back. They’re building faster defenses, better ways to spot attacks, and stronger systems to keep people safe. It’s a constant race — every

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Elastic has released a security advisory addressing an origin validation error in Kibana that could expose systems to Server-Side Request Forgery (SSRF) attacks. The vulnerability, tracked as CVE-2025-37734, affects multiple versions of the popular data visualization and exploration platform and has prompted immediate patching across all affected deployments. CVE ID Vulnerability Affected Versions CVSS Score Fixed Versions […]

    The post Kibana Vulnerabilities Expose Systems to SSRF and XSS Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new ClickFix campaign is tricking users with a fake Windows update that runs in their browser. Called “Fake OS Update,” this scam takes advantage of people’s trust in the familiar blue screen of death (BSOD) from Microsoft.

    It delivers malware and shows how social engineering can be more effective than technical tricks.

    Cybersecurity researcher Daniel B., who works at the UK’s National Health Service, first spotted the attack last month while probing malicious online threats.

    As detailed in his LinkedIn post, the scam operates primarily on the domain groupewadesecurity[.]com. Simply visiting the site often via malvertising or spam links triggers a full-screen overlay mimicking a Windows OS crash or update prompt.

    The fake BSOD, complete with error codes and progress bars, appears on both PCs and smartphones, creating panic and urgency.

    What sets this apart from earlier ClickFix variants is its multi-step deception. After the initial screen, victims are instructed to perform three “manual fixes” using keyboard shortcuts: pressing Ctrl+Alt+Del to “restart services,” entering a bogus command in a simulated command prompt, and finally downloading a “recovery tool” from a linked malicious site.

    In reality, these actions grant attackers remote access or install infostealers and ransomware loaders. The campaign’s sophistication lies in its cross-device compatibility and avoidance of immediate redirects, making it harder for browser protections to flag.

    ClickFix attacks, which trick users into “fixing” non-existent issues via clicks, have plagued browsers since 2020. But as attackers refine their tactics employing hyper-realistic graphics, localized languages, and timely lures tied to real events like Patch Tuesday, this variant proves especially insidious.

    Indicators of compromise, including URLs and payloads, are cataloged on platforms such as ThreatFox and urlscan.io under the “Fake OS Update” tag, aiding threat hunters in tracking the spread.

    Experts warn that such campaigns highlight a critical gap: while endpoint detection tools catch many automated threats, human error remains the weakest link.

    “User vigilance and regular cybersecurity training are as vital as firewalls,” notes a spokesperson for the UK’s National Cyber Security Centre (NCSC).

    Organizations should prioritize awareness programs that simulate these scenarios, alongside browser extensions such as uBlock Origin to block suspicious domains.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post New ClickFix Attack Tricks Users with ‘Fake OS Update’ to Execute Malicious Commands appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have uncovered a sophisticated supply chain attack disguised as a legitimate cryptocurrency wallet. Socket’s Threat Research Team discovered a malicious Chrome extension called “Safery: Ethereum Wallet,” published on the Chrome Web Store on November 12, 2024, that employs an ingenious technique to steal user seed phrases through hidden blockchain transactions. The extension, identified […]

    The post Malicious Chrome Extension Grants Full Control Over Ethereum Wallet appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dell Technologies has disclosed a critical security vulnerability in its Data Lakehouse platform that could allow remote attackers to escalate privileges and compromise system integrity.

    The flaw, tracked as CVE-2025-46608, affects all versions before 1.6.0.0 and has been assigned a CVSS score of 9.1, placing it in the critical severity category.

    The security flaw stems from an improper access control vulnerability in Dell Data Lakehouse. A highly privileged attacker with remote access could exploit this weakness to elevate their privileges beyond their authorized level.

    Dell Data Lakehouse Vulnerability

    The vulnerability is particularly concerning because it requires low attack complexity and no user interaction. Making exploitation relatively straightforward for attackers who have already gained high-level access to the system.

    The vulnerability can be exploited over the network, with a broader scope, potentially affecting resources beyond the vulnerable component.

    CVE IDAffected productCVSS ScoreAffected VersionsPatched Version
    CVE-2025-46608Dell Data Lakehouse9.1 (Critical)Prior to 1.6.0.01.6.0.0 or later

    Successful exploitation could result in high impact on the security, integrity, and availability of the system.

    Dell Technologies has classified this vulnerability as critical due to its potential to grant unauthorized access with elevated privileges, leading to complete compromise of system integrity and customer data.

    Attackers exploiting this flaw could access sensitive information, modify critical data, or interrupt system operations.

    Dell has released version 1.6.0.0 of Data Lakehouse to address this vulnerability. The company strongly recommends that all customers upgrade to the latest version immediately to mitigate the risk.

    Users running affected versions should contact Dell Technical Support and reference advisory DSA-2025-375 for assistance with the upgrade process.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Critical Dell Data Lakehouse Vulnerability Let Remote Attacker Escalate Privileges appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶