✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Android Spyware Masquerades as Messaging Apps in UAE: ESET Uncovers 2024 Mobile Threats
In June 2024, ESET researchers uncovered two Android spyware campaigns—ProSpy and ToSpy—masquerading as popular messaging apps Signal and ToTok, specifically targeting residents in the United Arab Emirates. The malware was distributed via third-party websites impersonating legitimate app stores, such as the Samsung Galaxy Store, and required users to manually install them. Upon installation, the spyware requested extensive permissions, gaining access to contacts, messages, stored files, audio, images, and more, enabling extensive data exfiltration. The campaigns utilized regional delivery tactics to focus on UAE users, exploiting trusted local app brands. These findings highlight a persistent threat trend: attackers disguising malware as legitimate communication apps to bypass official channels and exploit regional trust. With increased scrutiny on privacy and secure messaging, such campaigns pose heightened operational and compliance risks for organizations and individuals alike, underscoring the urgent need for enhanced mobile security measures and user awareness.
6 months ago
Kill Chain
Android Spyware Campaigns Target Signal and ToTok Users in Sophisticated 2025 Attack
In June 2025, cybersecurity firm ESET uncovered targeted Android spyware campaigns, dubbed ProSpy and ToSpy, which impersonated upgrades and plugins for the popular messaging apps Signal and ToTok. Threat actors distributed malicious APK files via websites masquerading as official app sites and third-party stores, luring users primarily in the United Arab Emirates. Once installed, these spyware variants harvested sensitive data including device information, contacts, SMS, files, and backups, using sophisticated persistence mechanisms and disguising themselves as legitimate apps. Data exfiltration was conducted using encrypted channels to evade detection. This incident underscores the increasing threat of mobile malware leveraging convincing social engineering tactics and fake branding. It highlights a macro trend of attackers exploiting trust in widely used apps to infiltrate user devices, reflecting rising complexity in mobile threat landscapes and growing regulatory pressure on app distributors.
6 months ago
Kill Chain
Confucius Launches Targeted Campaign Against Pakistan with WooperStealer and Anondoor Malware
In October 2025, the advanced persistent threat group Confucius launched a sophisticated phishing campaign targeting Pakistani government, defense, and critical industry sectors. Leveraging spear-phishing emails and malicious documents, the attackers deployed two custom malware strains—WooperStealer and Anondoor—to infiltrate victim environments. These tools enabled the exfiltration of sensitive information and lateral movement across internal networks, potentially exposing military secrets and compromising operational capabilities. The attack underlines the evolving TTPs used by regional espionage actors and demonstrates substantial gaps in defending east-west traffic and data exfiltration from secure environments. This incident highlights the growing prevalence of specialized information-stealing malware and the targeting of governmental infrastructure by geopolitical adversaries. It reflects broader trends in cyber-espionage and underscores heightened regulatory expectations for securing critical east-west and outbound traffic flows.
6 months ago
Kill Chain
ShinyHunters Target Salesforce: Social Engineering Breach Exposes SaaS Security Gaps
In early 2024, Google’s Mandiant research team identified a targeted campaign by the ShinyHunters threat group leveraging advanced social engineering techniques against Salesforce environments. The attackers—tracked as UNC6040—used convincing phishing lures and manipulation of Salesforce user credentials to gain unauthorized access to sensitive corporate data. By circumventing authentication measures and exploiting insufficient internal network segmentation and monitoring, ShinyHunters exfiltrated confidential business records, customer data, and intellectual property. The breach highlighted the group’s evolving tactics and the risks posed to organizations that rely on cloud SaaS platforms like Salesforce for critical operations. This incident underscores the increasing sophistication of social engineering attacks, with criminals exploiting both technical and human vulnerabilities in cloud platforms. As SaaS adoption accelerates, similar threats are expected to rise, placing renewed emphasis on identity security, comprehensive threat detection, and adherence to zero trust principles.
6 months ago
Kill Chain
Android Spyware Attack Impersonates UAE Government App in 2024
In early June 2024, security analysts uncovered a sophisticated campaign in which attackers distributed Android spyware posing as a well-known UAE government surveillance app. By leveraging convincing social engineering and impersonation tactics, the threat actors tricked users into installing malicious software capable of exfiltrating sensitive data, monitoring communications, and maintaining persistent control over compromised devices. The spyware utilized encrypted and covert exfiltration methods, giving attackers broad access to user data while evading standard detection. The incident quickly raised concerns among organizations and citizens in the region about mobile device security and privacy. This attack is part of a growing trend using brand impersonation and sophisticated spyware packaging, targeting both individuals and potentially organizations. The resurgence of mobile surveillance threats underscores the evolving risks facing users in high-risk regions and highlights the need for robust mobile device security and compliance with privacy frameworks.
6 months ago
Kill Chain
Klopatra Trojan: VNC-Powered Android Banking Attacks Sweep Europe in 2025
In March 2025, a newly identified Android trojan named Klopatra emerged, targeting over 3,000 devices across Europe by masquerading as a legitimate IPTV and VPN app. Researchers from Cleafy discovered that this banking and remote access trojan—believed to be operated by a Turkish-speaking cybercrime group—leveraged VNC-based remote control, overlay attacks, anti-analysis techniques, and Accessibility Service abuse to steal banking credentials, manipulate transactions, exfiltrate clipboard and keystroke data, and harvest cryptocurrency wallet information. The malware sidestepped Google Play protections by distributing its dropper app on unofficial websites and continuously evolving, with at least 40 builds detected since its appearance. This incident underscores the growing sophistication and adaptability of Android malware, including the deployment of advanced evasion techniques and real-time remote access capabilities. As mobile banking adoption rises globally, such attacks signal an urgent need for stronger app vetting, user awareness, and holistic endpoint security strategies in enterprise and consumer environments.
6 months ago
Kill Chain
TOTOLINK X6000R Routers: 2025 Vulnerabilities Uncovered in Edge Devices
In June 2025, three new critical vulnerabilities (CVE-2025-52905, CVE-2025-52906, CVE-2025-52907) were discovered in TOTOLINK X6000R routers by Palo Alto Networks' Unit 42 researchers. These flaws exposed the devices to remote code execution and unauthorized access, potentially allowing attackers to gain persistent control over affected networks. The vulnerabilities stem from insecure input validation, weak authentication mechanics, and flaws in firmware that could be exploited over the internet. Immediate patching and network segmentation were recommended to prevent exploitation while vendor mitigation efforts commenced. This incident highlights ongoing risks to consumer and small business gateway devices, demonstrating how router vulnerabilities remain a rich attack surface for cyber actors. The event underscores the urgency for continuous vulnerability research, robust patch management, and defense-in-depth to counter the accelerating trend of targeting edge and IoT devices.
6 months ago
Kill Chain
Phantom Taurus: China-Linked Espionage Group Infiltrates Diplomatic Targets with Undetected Malware
In early 2024, Palo Alto Networks' Unit 42 uncovered a newly confirmed China-linked espionage group, dubbed Phantom Taurus, employing advanced stealth techniques and novel malware to infiltrate nearly a dozen high-value targets in the Middle East, Africa, and Asia. The group relied on exploiting unpatched, internet-facing devices to gain initial access before deploying a custom malware suite designed for in-memory execution and deep evasion, allowing them to establish persistent access and exfiltrate sensitive diplomatic and governmental data over periods stretching up to two years. While Phantom Taurus shares some infrastructure traits with other Chinese threat actors, its custom tooling, extended operational security, and unique tactics distinguish it from other known groups, and it remains active with recent campaigns expanding to new regions. This incident highlights an escalation in the sophistication and reach of nation-state cyber espionage. The emergence of Phantom Taurus signals a growing trend of attackers prioritizing stealth and long-term intelligence gathering, making it more difficult for organizations to detect and respond to breaches within high-value sectors.
6 months ago
Kill Chain
Medusa Ransomware’s Failed Insider Recruitment at BBC (2025)
In July 2025, cybercriminals claiming affiliation with the Medusa ransomware group attempted to compromise the BBC by recruiting a journalist as an insider. The threat actor contacted the BBC’s cybersecurity correspondent via Signal, offering a percentage of any ransom if the journalist would provide internal access. Their plan relied on leveraging the journalist’s BBC credentials to infiltrate systems, download sensitive data, and initiate a high-value ransomware attack. The attackers used multiple social engineering tactics, including MFA fatigue (MFA bombing), but the journalist reported the approach to BBC’s security team, preventing a breach and prompting immediate incident response measures. This incident highlights the increasing risk of ransomware groups seeking insiders for network access, as well as the sophistication of social engineering tactics. As double-extortion attacks and insider recruitment surge, organizations must enhance vigilance and reinforce controls to mitigate identity-driven threats.
6 months ago
Kill Chain
Dutch Teens Arrested for Espionage Attempt Targeting Europol via WiFi Sniffer
In September 2025, Dutch authorities arrested two 17-year-old boys who attempted to spy on Europol and other international entities in The Hague using WiFi sniffer devices. The teenagers, allegedly recruited via Telegram to work for Russian interests, conducted reconnaissance outside the offices of Europol, Eurojust, and the Canadian embassy, aiming to intercept wireless traffic. A tip-off from the Dutch intelligence service (AIVD) led to their arrest before any confirmed data breach occurred. Europol reported no compromise of its systems but is maintaining heightened vigilance. This incident underscores the evolving threat landscape where state-sponsored actors increasingly recruit and exploit minors for espionage activities. With attacks targeting wireless infrastructures and leveraging easily accessible tools, organizations must strengthen controls, enhance insider threat awareness, and expand security measures to non-traditional attack vectors.
6 months ago
Kill Chain
China-Linked PlugX and Bookworm Malware Strike Asian Telecoms in Advanced Attack
In mid-2025, a coordinated advanced persistent threat (APT) campaign linked to China targeted telecommunications and manufacturing entities across Central and South Asia. Attackers leveraged new PlugX and Bookworm malware variants, utilizing DLL side-loading techniques via legitimate applications to achieve persistence and evade detection. The intrusions allowed the threat actors to perform extensive reconnaissance, deploy additional payloads, and exfiltrate sensitive operational data from ASEAN and Asian telecom networks, demonstrating a high degree of stealth and sophistication in lateral movement. This incident underscores a growing uptick in nation-state cyber activity against Asian critical infrastructure, highlighting emerging malware evolution and increasingly covert lateral movement. With similar TTPs proliferating, organizations must elevate east-west traffic security and anomaly detection to stay ahead.
6 months ago
Kill Chain
New XCSSET Variant Hits macOS: Browser Credential Theft and Clipper Risk for Developers
In September 2025, researchers identified a sophisticated new variant of the macOS XCSSET malware, targeting Apple devices with an updated focus on browser credential theft, clipboard hijacking (clipper), and improved persistence. Initially delivered through tainted Xcode projects, the malware leveraged encrypted and obfuscated code to avoid detection, and incorporated a persistence module for sustained access. Key changes included deeper targeting of browsers like Firefox, allowing attackers to intercept credentials, exfiltrate sensitive data, and potentially escalate attacks to other platforms or accounts. The XCSSET variant’s rise mirrors broader trends in information-stealing malware exploiting developer platforms and macOS. This incident highlights growing attacker interest in macOS ecosystems, the sophistication of obfuscation techniques, and the urgent need for endpoint monitoring and microsegmentation across development environments.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports