• A sophisticated Windows remote-access trojan known as ValleyRAT has emerged as a high-confidence indicator of targeted intrusions against Chinese-language users and organizations. ValleyRAT’s operational model relies on a carefully orchestrated delivery chain comprising four distinct components: the downloader, loader, injector, and RAT payload. First observed in early 2023, this multi-stage malware combines advanced evasion techniques, […]

    The post ValleyRAT Campaign Targets Windows via WeChat and DingTalk appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cl0p, a prominent ransomware group operating since early 2019, has emerged as one of the most dangerous threats in the cybersecurity landscape.

    With over 1,025 confirmed victims and more than $500 million in extorted funds, this Russian-linked group has consistently targeted corporate and private networks worldwide while strategically avoiding CIS countries.

    The group earned its name from the “.cl0p” file extension it appends after encryption, though the term also translates to “bedbugs” in Russian, reflecting its persistent nature in compromising systems.

    The ransomware group’s latest campaign showcases a sophisticated approach to zero-day exploitation, particularly leveraging CVE-2025-61882, a critical vulnerability discovered in Oracle E-Business Suite.

    This ERP application, widely used for order management, procurement, and logistics functions across enterprises globally, presents an attractive target for threat actors seeking rapid network penetration and data exfiltration.

    Representing Cl0p Usual Path (Source - The Raven File)
    Representing Cl0p Usual Path (Source – The Raven File)

    The vulnerability was initially observed in June 2025 but has become increasingly active in recent months.

    THE RAVEN FILE analysts noted that the exploitation infrastructure demonstrates a significant technical breakthrough.

    Upon investigating the initial indicators of compromise shared by Oracle in October 2025, researchers discovered two outbound IP addresses directly associated with active attacks.

    Through detailed fingerprint analysis and scanning with tools like Shodan and FOFA, analysts uncovered 96 distinct IP addresses sharing identical SSL certificate fingerprints with the initial attack infrastructure.

    This clustering revealed the group’s operational patterns and network preferences across multiple geographic regions.

    Infrastructure Reuse and Network Analysis: A Critical Pattern

    The most striking technical discovery involves Clop’s deliberate infrastructure reuse strategy. Researchers identified that 41 subnet IPs from the current Oracle EBS exploitation were previously utilized during the 2023 MOVit vulnerability attacks (CVE-2023-34362).

    Clop Exploited CVEs (Source - The Raven File)
    Clop Exploited CVEs (Source – The Raven File)

    This pattern indicates the group maintains persistent hosting relationships and rotates infrastructure strategically rather than building entirely new networks between campaigns.

    Analysis of the 96 identified IPs shows geographic distribution patterns, with Germany leading at 16 addresses, followed by Brazil (13) and Panama (12).

    However, the underlying ASN infrastructure reveals concentrated use of Russian-based providers, despite geographic diversification efforts designed to evade traditional IP-based blocking strategies.

    Further investigation uncovered that Clop employs sophisticated sub-netting techniques, with 77.8 percent of identified subnets showing repeated usage across multiple attack campaigns.

    The hosting entity analysis revealed Alviva Holdings Limited as a primary infrastructure provider, hosting 15 identified addresses.

    This consistent reuse pattern provides defenders with valuable intelligence for threat hunting and network monitoring.

    The combination of zero-day exploitation capability, persistent infrastructure reuse, and geographic sophistication demonstrates why Cl0p remains among the most effective ransomware operations currently active in the threat landscape.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Clop Ransomware Actors Exploiting the Latest 0-Day Exploits in the Wild appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Three well-known threat groups have consolidated into a unified cybercriminal entity that represents a significant shift in underground tactics.

    Scattered LAPSUS$ Hunters (SLH) emerged in early August 2025 as a federated alliance combining Scattered Spider, ShinyHunters, and LAPSUS$, creating what researchers describe as the first consolidated alliance among mature cybercriminal clusters.

    Channel announcement referencing ‘Sh1nySp1d3r’ as a proposed ransomware offering (Source – Trustwave)

    This consolidation marks a deliberate strategic move within the cybercriminal underground, where established threat actors are merging reputational assets and operational capabilities to create a more formidable collective.

    The alliance entered the threat landscape through Telegram, leveraging the platform as its primary operational base and marketing channel.

    Telegram channels and activity periods (Source – Trustwave)

    Unlike traditional cybercriminal actors who maintain minimal visibility, SLH adopted a highly performative approach, combining sensationalist messaging with proof-of-compromise announcements and public engagement strategies.

    The group’s first verified channel appeared on August 8, 2025, establishing what would become a consistent pattern of theatrical branding and coordinated communication that blurs the line between attention-driven hacktivism and financially motivated cybercrime.

    Since its inception, Trustwave analysts have noted that the group has demonstrated remarkable operational persistence despite repeated platform disruptions.

    Telegram channels have been removed and recreated at least sixteen times under varying name iterations, yet SLH consistently re-established its presence within hours, signaling extraordinary determination to maintain public visibility and control over narrative construction.

    Trustwave researchers identified sophisticated technical capabilities underlying SLH’s operations.

    Technical Infrastructure and Exploitation Capabilities

    The collective exhibits genuine exploit development and acquisition competencies, particularly targeting high-value enterprise systems including CRM platforms, Database Management Systems, and SaaS infrastructure.

    Members leverage AI-automated vishing campaigns combined with credential harvesting techniques, followed by systematic lateral movement for privilege escalation and rapid data exfiltration.

    Notable vulnerabilities tied to SLH operations include CVE-2025-61882 (Oracle E-Business Suite) and claims of exploitation targeting CVE-2025-31324 (SAP NetWeaver), suggesting capability development or code acquisition from external sources.

    Code snippets circulated within channels demonstrate legitimate exploit proof-of-concepts, while documented local privilege escalation techniques show command execution access to sensitive system files.

    This technical arsenal reflects convergence of skills drawn from the three merged organizations, enabling simultaneous deployment of social engineering, exploitation, and extortion methodologies that amplify operational impact across their targets and enhance their market positioning within the cybercriminal ecosystem.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Three Infamous Cybercriminal Groups Form a New Alliance Dubbed ‘Scattered LAPSUS$ Hunters’ appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated Remote Access Trojan (RAT) is actively targeting North Korean Human Rights Defenders (HRDs) through a campaign leveraging stolen code-signing certificates to evade antivirus detection. The newly discovered “EndClient RAT,” delivered via a malicious Microsoft Installer package disguised as “StressClear.msi,” represents a significant escalation in threats against civil society organizations working on North Korean […]

    The post EndClient RAT Leverages Compromised Code-Signing to Slip Past Antivirus appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  •  Authorities across nine countries executed a coordinated crackdown on one of the largest credit card fraud networks ever dismantled. Operation Chargeback, led by German prosecutors and the Bundeskriminalamt, brought down criminal organizations responsible for defrauding over 4.3 million cardholders globally. The investigation, which began in December 2020, resulted in 18 arrest warrants and more than […]

    The post Authorities Dismantle Large-Scale Credit Card Fraud Scheme Affecting 4.3 Million Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hyundai AutoEver America has disclosed a significant data breach that compromised sensitive personal information of customers, including Social Security numbers and driver’s license details.

    The cybersecurity incident highlights growing concerns about data protection in the automotive technology sector.​

    Hyundai AutoEver America discovered the cyber incident on March 1, 2025, when unauthorized activity was detected within its information technology environment.

    The company immediately launched an investigation with external cybersecurity experts to assess the full scope of the breach.

    Forensic analysis revealed that unauthorized access began on February 22, 2025, and the last observed malicious activity occurred on March 2, 2025, spanning approximately 9 days of potential data exposure.​

    Compromised Personal Information

    The breach exposed a range of sensitive personal data belonging to affected individuals. According to the official breach notification, compromised information included full names along with additional data elements that could enable identity theft.

    While the notice template does not specify exact numbers, the company confirmed that Rhode Island residents were among those impacted.

    The exposed data includes Social Security numbers, driver’s license information, and other personally identifiable information that could be exploited for fraudulent purposes.​

    Upon discovering the intrusion, Hyundai AutoEver immediately terminated the unauthorized third party’s access to affected systems and engaged specialized cybersecurity firms to conduct a comprehensive investigation.

    The company also coordinated with law enforcement agencies throughout the response process. The extensive nature of the incident required significant time and resources to analyze forensic data and determine which information was accessed.​

    Hyundai AutoEver is offering affected customers complimentary two-year credit monitoring services through Epiq Privacy Solutions, including three-bureau credit monitoring and identity protection.

    Affected individuals are encouraged to remain vigilant by monitoring account statements, reviewing credit reports regularly, and considering fraud alerts or security freezes to prevent unauthorized credit applications.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hyundai AutoEver Confirms Data Breach Exposing Users’ Personal Information and SSNs appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cybersecurity landscape stands at a critical inflection point as organizations prepare for unprecedented challenges in 2026.

    Google Cloud researchers have released their annual Cybersecurity Forecast, revealing a stark reality: threat actors are transitioning from experimenting with advanced technologies to embedding them as standard operational tools.

    This shift represents a fundamental change in how attacks are orchestrated, detected, and defended against across enterprise networks.

    The upcoming year will be defined by rapid evolution on both sides of the security equation. While defenders prepare their defenses, adversaries are actively reshaping their tactics with emerging technologies.

    Google Cloud analysts identified multiple threat vectors that will dominate the threat landscape, ranging from enterprise-targeted attacks to nation-state operations designed for long-term espionage and strategic advantage.

    Google Cloud analysts and researchers noted that threat actors have moved decisively from using advanced technologies as occasional tactical advantages to employing them as the foundation of their operations.

    This normalization of sophisticated attack methodologies signals a maturation in the threat ecosystem, where scale and speed define success. Organizations must fundamentally rethink their defensive postures to address this reality.

    The most immediate concern centers on how threat actors are weaponizing modern technologies. Prompt injection attacks represent a critical emerging threat that manipulates systems to bypass security restrictions and execute hidden attacker commands.

    These targeted assaults on enterprise AI systems will accelerate significantly, exploiting the growing reliance on machine learning-driven platforms.

    Additionally, voice cloning technology enables hyperrealistic impersonations of executives and IT personnel, making traditional social engineering far more convincing and difficult to identify.

    Infrastructure vulnerabilities compound these concerns. Virtualization layers, historically overlooked by mature security programs, have become critical blind spots.

    Adversaries are systematically pivoting toward underlying virtualization infrastructure, where a single successful compromise grants complete control over an entire digital estate and can render hundreds of systems inoperable within hours.

    The Multi-Layered Threat Landscape

    The convergence of ransomware, data theft, and extortion continues to represent the most financially damaging cybercrime category.

    Organizations face pressure from threat actors exploiting zero-day vulnerabilities to exfiltrate massive datasets and hold systems hostage.

    Third-party providers remain prime targets, as compromising supply chain partners grants attackers access to numerous downstream customers with a single successful breach.

    Beyond cybercrime, nation-state operations are intensifying. China’s cyber operations maintain unprecedented volume and sophistication, targeting edge devices and exploiting zero-day vulnerabilities with strategic precision.

    Russian cyber operations are undergoing fundamental restructuring, shifting from tactical Ukraine-focused activities toward long-term strategic capability development.

    North Korean groups continue financing regime activities through targeted financial operations, while Iranian actors maintain resilience across espionage, disruption, and semi-deniable hacktivist activities.

    Organizations must adopt proactive threat intelligence frameworks to stay ahead of these evolving challenges and implement multi-layered defense strategies that address both conventional and emerging attack vectors.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Cybersecurity Forecast 2026 – Google Warns Threat Actors Use AI to Enhance Speed and Effectiveness appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The threat actor known as Curly COMrades has been observed exploiting virtualization technologies as a way to bypass security solutions and execute custom malware. According to a new report from Bitdefender, the adversary is said to have enabled the Hyper-V role on selected victim systems to deploy a minimalistic, Alpine Linux-based virtual machine. “This hidden environment, with its lightweight

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at Google Threat Intelligence Group (GTIG) have identified a significant shift in how threat actors are leveraging artificial intelligence in their operations. The discovery of experimental malware called PROMPTFLUX marks a watershed moment in cyber threats, demonstrating that attackers are no longer using AI merely to boost productivity they are now deploying AI-enabled […]

    The post Google Warns of PROMPTFLUX Malware That Uses Gemini API for Self-Rewriting Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated Android-based NFC relay attack dubbed NGate has emerged as a serious threat to banking security across Poland, targeting financial institutions and their customers through coordinated social engineering and technical exploitation.

    Cert.PL analysts identified new malware samples in recent months that orchestrate unauthorized ATM cash withdrawals without requiring physical theft of payment cards.

    Rather than stealing cards directly, threat actors employ a relay mechanism that captures NFC communication from victims’ Android phones and forwards it to attacker-controlled devices positioned at ATMs.

    The attack chain combines multiple deception tactics to succeed. Victims initially receive phishing messages via email or SMS claiming technical problems or security incidents, directing them to install a fake banking application.

    Following installation, scammers impersonate bank employees through phone calls requesting identity verification, further legitimizing the fraudulent application.

    The victim is then prompted to tap their physical payment card against the phone for verification purposes while entering their PIN through an on-screen keypad.

    Cert.PL analysts noted the sophisticated technical architecture underlying NGate’s operations.

    Once the victim taps their card, the malware captures all NFC exchanges identical to legitimate terminal communications and transmits them to the attacker’s C2 server operating at IP 91.84.97.13:5653.

    Payment verification (Source - Cert.PL)
    Payment verification (Source – Cert.PL)

    The attacker’s device then replays this data to the ATM, and with both the card information and PIN already compromised, they execute unauthorized cash withdrawals.

    Infection mechanism

    The infection mechanism reveals advanced evasion techniques. The application registers itself as a Host Card Emulation (HCE) payment service on Android, enabling it to function as a virtual card.

    Configuration data containing the C2 server address remains hidden in an encrypted asset bundled within the application.

    This encryption employs the SHA-256 hash of the APK signing certificate as an XOR key, derived through JNI function calls that retrieve certificate data from the Android PackageManager.

    Technical analysis shows the app establishes cleartext TCP connections using a framed protocol structure containing length markers and opcodes.

    The malware captures card data including PAN, expiration dates, AIDs, and APDUs before immediately exfiltrating PIN information through dedicated protocol messages.

    Users can protect themselves by downloading banking applications exclusively from official stores and verifying unexpected bank calls through direct contact with their financial institution.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post NGate Malware Enables Unauthorized Cash Withdrawals at ATMs Using Victims’ Payment Cards appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶