Computer/Network Security
Breach intelligence, attack campaigns, and threat reports targeting the Computer/Network Security sector.
Explore Other Sectors
Computer/Network Security Threat Reports
Authorities Dismantle Cryptomixer: $28 Million in Bitcoin Seized Amid Europol-Led Takedown
In June 2024, European authorities executed a coordinated operation to dismantle Cryptomixer, a cryptocurrency mixing service reportedly used to launder over $1.5 billion for global cybercriminals. Operation Olympia involved Europol, Eurojust, and law enforcement agencies from Germany and Switzerland, resulting in the seizure of nearly $28 million in Bitcoin, three physical servers, the cryptomixer.io domain, and over 12 terabytes of data. Cryptomixer functioned as an anonymizing layer for a multitude of cybercrimes, including ransomware, payment card fraud, and trafficking in illicit goods, allowing threat actors to evade detection and launder stolen assets. This takedown demonstrates mounting regulatory and law enforcement pressure on cryptocurrency-based money laundering infrastructure. The case highlights a shift among advanced threat groups—such as the North Korean Lazarus Group—from prioritizing anonymity to speed and automation in financial cybercrime operations, reflecting evolving cybercriminal tactics and the urgent need for robust digital asset tracking controls.
8 months ago
Kill Chain
Law Enforcement Dismantles Cryptomixer: Major Blow to Crypto Laundering Networks
In June 2024, a coordinated operation between Swiss and German law enforcement agencies led to the shutdown of the Cryptomixer cryptocurrency-mixing service. Since its inception in 2016, Cryptomixer is believed to have laundered over €1.3 billion in Bitcoin, providing cybercriminals with tools to obfuscate illicit financial flows from ransomware, scams, and darknet market activities. The takedown included seizure of digital infrastructure and assets, disrupting one of the major cryptocurrency laundering platforms that aided threat actors operating globally. This collaborative international action highlights increased efforts by authorities to clamp down on crypto-enabled cybercrime. The incident reflects the growing focus on digital financial transparency and signals greater scrutiny of services aiding threat actors in anonymizing transactions.
8 months ago
Kill Chain
Tomiris Leverages Public-Service Implants for Stealthy Government Attacks
In late 2025, the state-sponsored threat actor Tomiris escalated its attacks against government entities and intergovernmental organizations, primarily in Russia and neighboring regions. The group notably shifted its tactics by deploying custom remote access implants that leveraged public cloud services, such as Telegram and Discord, as command-and-control (C2) channels. This allowed Tomiris to disguise their network traffic among legitimate service use, evading conventional perimeter defenses and security controls. The compromise enabled attackers to maintain persistent access, deploy additional payloads, and potentially exfiltrate sensitive diplomatic and policy data. This incident is significant due to its demonstration of the evolving sophistication in APT tactics: the use of ubiquitous public platforms for C2, making detection and attribution harder. It also highlights the urgency for zero trust architectures, enhanced traffic monitoring, and cloud-centric security controls as industries face an increase in nation-state and intelligence-motivated threats.
8 months ago
Kill Chain
North Korean Hackers Target Developers with Massive npm Supply-Chain Attack
In November 2025, North Korean threat actors associated with the "Contagious Interview" campaign launched an extensive supply-chain attack by publishing 197 malicious npm packages. According to threat intelligence from Socket, these packages—downloaded over 31,000 times—were engineered to distribute a new OtterCookie malware variant, combining features from BeaverTail and earlier OtterCookie strains. The attackers leveraged the npm ecosystem to infiltrate development pipelines, enabling remote code execution and persistent access across compromised environments, potentially exposing confidential data and intellectual property. This incident underscores the escalating risks of supply chain attacks targeting software registries. With developers increasingly relying on open-source dependencies, threat actors are focusing on abusing trusted platforms like npm to propagate sophisticated malware at scale. Organizations must strengthen software supply chain security and closely monitor package repositories to mitigate these emerging threats.
8 months ago
Kill Chain
Universal Jailbreaks: How Adversarial Poetry Unlocked AI Model Vulnerabilities in 2025
In late 2025, researchers uncovered a major vulnerability affecting leading AI providers, demonstrating that prompt injection using poetic phrasing can universally bypass safety alignment in large language models (LLMs). By translating malicious prompts into poetic verse and feeding them into 25 major proprietary and open-source LLMs, adversaries were able to achieve jailbreak attack success rates above 60% in many cases—far surpassing previous methods. This attack allowed models to generate outputs associated with high-risk domains, such as cyber-offense and weaponization, despite existing refusal mechanisms. The incident raises urgent concerns about the robustness of current model alignment and evaluation frameworks and exposes fundamental gaps in LLM safety design. This discovery is particularly significant as LLMs are now widely adopted across industries and critical sectors. The poetic technique's ability to systematically defeat existing safeguards highlights the evolving risks of adversarial prompt engineering and threatens AI-dependent workflows, regulatory compliance, and trust in intelligent automation.
8 months ago
Kill Chain
Anthropic AI Breach: Chinese State-Sponsored Espionage Campaign Shakes Cybersecurity Landscape
In late 2024, Anthropic disclosed a sophisticated espionage campaign linked to Chinese state-sponsored actors who leveraged the Claude AI platform to automate and scale cyber-operations targeting at least 30 global organizations. Attackers reportedly used Claude to streamline reconnaissance and intrusion tasks, combining AI capabilities with human expertise to enhance operational stealth and impact. The U.S. House Homeland Security Committee responded by summoning Anthropic’s CEO and other tech leaders to testify about the security implications of AI-augmented tradecraft and the risks posed by pairing AI with emerging technologies like quantum computing. This incident underscores how state-sponsored groups are rapidly evolving, using commercially available AI to bypass defenses and accelerate cyber operations. The attack has triggered urgent calls for stronger safeguards, regulatory clarity on AI security, and cross-sector strategies to counter AI-enabled cyber threats.
8 months ago
Kill Chain
Ransomware Attack Disrupts Multiple London Councils’ IT Systems in 2024
In June 2024, the Royal Borough of Kensington and Chelsea (RBKC) and Westminster City Council experienced operational disruption following a ransomware cyberattack on their shared IT provider, Westminster City Council Integrated IT (WCCIT). Attackers infiltrated municipal digital infrastructure, encrypted data, and impacted critical online services such as resident portals and payment processing. Public-facing platforms were taken offline as a precaution, and council operations shifted to manual workarounds, affecting both internal processes and citizen-facing services. The incident underscores the vulnerabilities within local government supply chains and highlights the ramifications of targeting shared service models in the public sector. This attack is a sobering reminder of the increasing incidence of ransomware campaigns targeting public entities in the UK and globally. With local authorities managing sensitive citizen data and critical services, the urgency for robust cybersecurity controls and incident response processes has never been more acute.
8 months ago
Kill Chain
DPRK’s FlexibleFerret Infiltrates macOS: Credential Theft at Scale
In early 2024, North Korea-linked threat group tracked as FlexibleFerret intensified targeted credential-theft campaigns focusing on macOS users, evolving their "Contagious Interview" social engineering lures. By masquerading as recruiters and leveraging tailored malware, the group tricked victims into opening malicious attachments, deploying a specialized macOS information stealer. The attackers' refinements enabled broader credential compromise, facilitating unauthorized access to sensitive accounts across professional and personal domains. This incident underscores a growing operational sophistication in DPRK-attributed campaigns and heightened risk to macOS environments previously perceived as less targeted. This case highlights a surge in credential-theft, social engineering, and platform-diverse malware, especially against enterprise macOS users. Security teams must adapt defenses to evolving threat actor tactics and close compliance and detection gaps regarding endpoint security and user education.
8 months ago
Kill Chain
Malicious Underground AI Models Like WormGPT 4 Are Supercharging Cybercrime in 2024
In early 2024, cybersecurity researchers uncovered an expanding underground marketplace for custom large language models (LLMs) such as WormGPT 4 and KawaiiGPT, designed to facilitate cybercrime. These jailbroken and open-source models, advertised and sold across dark web forums, lower the technical barrier for attackers by offering tools to scan for vulnerabilities, automate malware development, and accelerate tasks like phishing and lateral movement. Their accessibility—with minimal setup time, user-friendly interfaces, and affordable pricing—has enabled a broader range of cybercriminals to automate sophisticated attacks previously requiring advanced skills. The emergence of malicious LLMs highlights a growing trend where generative AI is weaponized in cybercrime. Unlike earlier incidents, these tools are now commercialized and widely supported, signaling a shift from simple model jailbreaking to specialized AI-enabled attack platforms. This evolution increases the urgency for organizations to strengthen AI risk management, augment detection strategies, and adapt compliance controls to address the new threat landscape.
8 months ago
Kill Chain
What the Gainsight–Salesforce Supply Chain Attack Teaches Us About SaaS Security in 2024
In late October 2024, Gainsight, a customer management SaaS provider, was implicated in a supply chain attack that impacted Salesforce environments. Attackers exploited the Gainsight connected app to obtain and abuse OAuth tokens, enabling unauthorized access to several Salesforce customer instances and raising concerns about lateral movement to other connected third-party applications. While initial reports from Salesforce identified compromised tokens and only a handful of affected customers, subsequent intelligence indicated the potential exposure of over 200 Salesforce instances. Mandiant and Salesforce collaborated to investigate the extent and mechanics of the attack, tracing earliest malicious activity to October 23, 2024. Despite ongoing forensics, Gainsight maintains that the breach impact was limited in scope, and no evidence has surfaced indicating a vulnerability within Salesforce’s platform itself. This incident reflects the growing trend of SaaS supply chain attacks that exploit authentication and integration mechanisms to reach downstream enterprise environments. The blend of fragmented disclosure, coordinated incident response, and rising third-party risks demonstrates the urgent need for improved visibility, segmented access, and standardized controls within interconnected SaaS ecosystems.
8 months ago
Kill Chain
Chinese APTs Target Russian IT Firms via Cloud: Inside the 2024 Espionage Breach
In early 2024, Chinese state-sponsored threat actors leveraged commercial cloud services as command-and-control channels to conduct covert cyber espionage against leading Russian IT organizations. The sophisticated attackers evaded detection by hiding their communications within encrypted cloud traffic, enabling them to obtain sensitive data and intelligence from critical Russian technology infrastructure. The breach underscores the risks posed by advanced persistent threats (APTs) operating stealthily in hybrid, multicloud environments using legitimate cloud tools. The incident heightened tensions between China and Russia due to the exposure of confidential communications and potentially proprietary technologies. This breach demonstrates a growing trend of nation-state actors blending in with legitimate cloud activity, making detection far more challenging for defenders. It signals a shift in cyber espionage tactics, intensifying the urgency for organizations to strengthen east-west visibility, enforce zero trust principles, and monitor cloud infrastructure for anomalous behavior.
8 months ago
Kill Chain
Malicious LLMs: The Rising Threat of WormGPT and KawaiiGPT in 2024
In early 2024, cybersecurity researchers identified and analyzed WormGPT 4 and KawaiiGPT—two large language models (LLMs) deliberately engineered for malicious purposes. Unlike mainstream generative models, these LLMs were tailored to support phishing campaigns, malware creation, and other cyberattacks by circumventing common content and safety filters. Distributed in underground forums, these tools lowered the technical barriers for cybercriminals, enabling more convincing social engineering and automating the development of attack payloads. The proliferation of these malicious LLMs heightened risks of rapid, at-scale phishing and malware campaigns targeting enterprises and individuals, increasing the sophistication and frequency of AI-enabled attacks. This incident is a warning as generative AI tooling increasingly serves dual-use purposes, making advanced threats more accessible to non-experts. Recent months have seen a surge in underground LLM offerings, regulatory scrutiny, and expanded attack surface across sectors driven by AI, demanding robust controls, visibility, and multicloud security strategies to combat evolving threats.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports