✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
ASUS Live Update Supply Chain Breach: Lessons from a Sophisticated APT Attack
In 2018, ASUS suffered a major supply chain compromise in which attackers, believed to be a state-linked APT group, infiltrated the ASUS Live Update utility and distributed a malicious software update to potentially hundreds of thousands of users. The attackers inserted a sophisticated backdoor into the official ASUS update, enabling targeted compromise of devices based on specific MAC addresses. Although the vulnerability (CVE-2025-59374) has only been formally cataloged recently, the incident itself occurred years ago, impacting trust in widely used supply chain components. This breach remains relevant due to the ongoing risk of similar supply chain tactics by advanced threat actors and the late inclusion of legacy vulnerabilities in compliance and threat feeds. Security leaders must recognize that historic supply chain compromises may resurface in compliance audits or be exploited in future campaigns through neglected, end-of-life software.
6 months ago
Kill Chain
University of Phoenix 2024 Clop Ransomware Breach Exposes Millions
In August 2023, the University of Phoenix suffered a significant data breach after the Clop ransomware gang exploited a vulnerability in the MOVEit file transfer software. Attackers gained unauthorized access to sensitive personal data belonging to nearly 3.5 million individuals, including current and former students, staff, and suppliers. The breach led to the theft of names, Social Security numbers, and other confidential records, severely impacting the institution’s ability to assure data privacy. Public disclosure came in June 2024 after investigation and notification procedures were completed. This incident underlines the escalating damage caused by ransomware groups leveraging supply chain vulnerabilities. Higher education institutions remain high-value targets due to large volumes of personal data and often fragmented security postures, highlighting an urgent need for proactive risk management and compliance with data protection regulations.
6 months ago
Kill Chain
Uzbekistan 2025: Wonderland Android Malware Campaign Steals Millions via Mobile Banking Fraud
In late 2025, a sophisticated cybercrime operation in Uzbekistan targeted Android users through the deployment of advanced dropper apps that installed the Wonderland malware. Disguised as legitimate Google Play or popular media files, these malicious APKs leveraged social engineering and fake landing pages to trick users into installation after enabling 'unknown sources.' The threat actor group, TrickyWonders, coordinated their campaign via Telegram, using heavily obfuscated droppers (MidnightDat and RoundRift) and dynamic C2 infrastructure. Once on a device, Wonderland enabled real-time SMS and OTP theft, phone number hijacking, lateral propagation via Telegram session compromise, and banking fraud, resulting in significant financial losses for victims. This incident underscores a broader trend: attackers are rapidly iterating their methods, shifting towards deceptive dropper-based infection chains, robust C2 agility, and hierarchically structured cybercrime operations. The campaign’s evolution, paired with similar threats like Cellik, Frogblight, and NexusRoute, signals an urgent need for improved mobile endpoint security, user awareness, and regulatory vigilance.
6 months ago
Kill Chain
MacSync Malware Bypasses macOS Gatekeeper with Notarized Infostealer in 2024
In June 2024, security researchers identified a new MacSync infostealer variant targeting macOS devices. The malware is delivered through a digitally signed and notarized Swift application that successfully evades Apple’s Gatekeeper checks, allowing it to run without typical security warnings. Once executed, MacSync exfiltrates sensitive user information including credentials, browser data, and files—leveraging encrypted command-and-control channels to avoid detection. The sophisticated dropper uses advanced evasion techniques to bypass standard macOS security controls, elevating risks for individuals and organizations running unpatched systems. This attack illustrates an evolving landscape where threat actors exploit trusted developer channels and novel evasion tactics to compromise macOS environments. With the growing adoption of macOS in enterprise and remote work settings, organizations are urged to review their controls, respond proactively, and address malware risks that legacy security tools may not detect.
6 months ago
Kill Chain
Nissan Customer Data Exposed After Red Hat Supply Chain Breach
In September 2023, Nissan Motor Co. Ltd. confirmed that the personal information of thousands of its customers was compromised due to a supply chain data breach at Red Hat, a leading software vendor. The breach stemmed from unauthorized access to customer data managed by Red Hat, which affected Nissan’s customer records, including names and contact information. While there is no current evidence of financial or highly sensitive information being lost, Nissan has notified the individuals impacted and is working with Red Hat to further assess and contain the breach’s full scope. This incident highlights the ongoing risk posed by third-party vendors in the automotive and technology sectors, as organizations increasingly rely on external service providers for software and infrastructure. The Nissan-Red Hat breach underscores the rising threats targeting supply chains, emphasizing the urgent need for robust vendor security controls and visibility into partner ecosystems.
6 months ago
Kill Chain
How Multi-Vector Attacks in 2025 Exposed Firewall and Internal Security Gaps
In December 2025, several global organizations faced a coordinated multi-vector cyber campaign in which threat actors leveraged recent vulnerabilities across enterprise firewalls, browser plugins, and connected devices. Attackers stealthily exploited zero-day flaws in network perimeter devices to access east-west traffic, deploy lateral movement, and exfiltrate sensitive data using encrypted channels. Both commercial and open-source threat detection struggled to identify activity quickly, resulting in significant operational disruptions, regulatory notification requirements, and data privacy liabilities affecting numerous sectors worldwide. This incident is indicative of a new threat paradigm in which attackers favor multi-tool, insider-style techniques, combining supply chain vulnerabilities with stealthy movements inside trusted IT environments. Security and compliance teams must now contend with adversaries who bypass traditional controls and exploit overlooked components, highlighting urgent needs for zero trust segmentation, improved traffic visibility, and robust egress monitoring.
6 months ago
Kill Chain
Malicious npm Package Exposes WhatsApp Accounts in 2025 Supply Chain Attack
In May 2025, a malicious npm package named "lotusbail" was uploaded to the JavaScript ecosystem, masquerading as a fully functional WhatsApp API. Created by a user known as "seiren_primrose," the package was downloaded over 56,000 times before discovery. Behind its legitimate capabilities, "lotusbail" stealthily exfiltrated WhatsApp credentials, intercepted all messages, harvested contacts, installed a persistent backdoor, and linked attacker devices to victims’ WhatsApp accounts for continuous unauthorized access. Data was encrypted and exfiltrated to attacker-controlled servers, with covert device pairing persisting even after package removal, compounding the risk to both individuals and organizations reliant on WhatsApp for communication. This incident highlights the growing risk of advanced supply chain attacks via trusted open-source repositories. Attackers increasingly use sophisticated evasion tactics—like anti-debugging, code obfuscation, and reputation laundering—to slip past static and reputation-based security controls. As software supply chain threats intensify, organizations must urgently reassess the hygiene, monitoring, and zero trust posture of their development pipelines.
6 months ago
Kill Chain
Iranian Infy APT Returns: 2025 Malware Campaign Exposes New Espionage Threats
In December 2025, the Iranian nation-state APT group known as Infy ("Prince of Persia") resurfaced after years of dormancy, launching a covert cyber espionage campaign using upgraded versions of its Foudre and Tonnerre malware. The attack targeted high-value individuals and organizations across Iran, Iraq, Turkey, India, Canada, and several European countries. Entry was achieved primarily via malicious Excel attachments in phishing campaigns, enabling long-term surveillance, data exfiltration, and direct access to encrypted communications such as Telegram chats. The attackers employed advanced tactics such as a Domain Generation Algorithm for resilient C2, RSA-based C2 validation, and selective victim targeting to remain undetected and persist in victim environments. The Infy resurgence illuminates how persistent APT actors adapt tools and methods for stealth operations, leveraging social engineering and technical innovation. This case illustrates the increasing threat of highly-targeted, identity-driven espionage attacks that undermine both personal privacy and organizational security.
6 months ago
Kill Chain
RansomHouse's 2025 Encryption Leap: The Rise of 'Mario' and Multi-Layered Ransomware
In December 2025, the RansomHouse ransomware-as-a-service (RaaS) group unveiled a major upgrade to its encryptor, dubbed ‘Mario’, shifting from a basic linear technique to a complex multi-layered encryption process. This variant leverages dynamic chunking, dual encryption keys, sophisticated memory organization, and non-linear file processing, making data recovery and reverse engineering significantly more challenging. Targeting environments such as VMware ESXi, the upgraded tooling enables attackers to encrypt large volumes of files efficiently, evidenced by attacks on organizations including Japanese e-commerce giant Askul, leading to substantial operational disruption and customer data compromise. RansomHouse’s encryption evolution underscores the continuing professionalization of RaaS groups, complicating detection and recovery for defenders. As multi-layered and adaptive ransomware proliferates, organizations face heightened risks, regulatory scrutiny, and the need to adopt advanced segmentation, visibility, and threat response controls.
6 months ago
Kill Chain
US DOJ Indicts 54 for Ploutus Malware ATM Jackpotting: Tren de Aragua’s US Crime Wave, 2025
In December 2025, the U.S. Department of Justice charged 54 individuals associated with the Tren de Aragua criminal gang in a far-reaching ATM jackpotting operation across the United States. By deploying Ploutus malware onto automated teller machines, the group manipulated hardware to force cash withdrawals—ultimately stealing millions of dollars. The multi-state scheme involved coordinated physical access to ATMs, installation of malicious software, and cash-out teams, highlighting significant vulnerabilities in banking infrastructure and ATM security controls. This incident underscores an escalating wave of financially motivated attacks leveraging sophisticated malware and organized criminal networks. With jackpotting attacks resurging globally and law enforcement intensifying their response, organizations must prioritize layered defenses, real-time anomaly detection, and compliance with evolving regulatory requirements.
6 months ago
Kill Chain
Cisco VPNs and Email Service Campaigns: How Multi-Vector Attacks Are Changing the Cyber Risk Landscape
In early 2024, Cisco VPN appliances and various enterprise email services were targeted in two distinct but nearly simultaneous cyber campaigns. The first, a highly coordinated attack, leveraged zero-day vulnerabilities and credential harvesting to infiltrate corporate VPNs, granting attackers lateral access to sensitive networks. Around the same period, a separate 'spray-and-pray' phishing wave indiscriminately targeted a wide swath of business email services, seeking to exploit weak authentication and unpatched systems. Combined, the incidents led to multiple business disruptions, credential leaks, and prompted extensive incident response efforts across affected organizations. This incident is part of a larger trend where cybercriminals simultaneously exploit both remote-access infrastructure and cloud-based email, reflecting a shift toward multi-vector, blended attacks. Organizations are facing heightened regulatory and operational pressure to defend against ever more sophisticated and opportunistic threats targeting identity, access points, and critical communications systems.
6 months ago
Kill Chain
Critical WatchGuard Firebox Firewall Flaw Enables RCE Attacks in 2025
In December 2025, WatchGuard disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-14733) impacting numerous Firebox firewall models running Fireware OS versions 11.x and later. The flaw, stemming from an out-of-bounds write bug, allows unauthenticated attackers to deploy malicious code on unpatched devices via low-complexity attacks, without user interaction. Exploitation is linked to IKEv2 VPN configurations, including those previously deleted but with lingering branch office VPN settings, making many organizations vulnerable. Active exploitation was observed, prompting WatchGuard to provide urgent mitigation steps and indicators of compromise to aid detection and response. The incident poses serious risks to over 250,000 businesses worldwide, as Firebox devices are extensively used in SMBs and managed service environments. This breach highlights the ongoing escalation of attacks targeting network infrastructure, particularly security appliances that underpin VPN and edge services. With similar device vulnerabilities making headlines throughout 2025, attackers are increasingly exploiting remote access flaws to establish persistence, demonstrating a worrying trend for organizations that depend on always-on network security.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports