✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
HybridPetya: Ransomware That Bypasses UEFI Secure Boot with CVE-2024-7344
In September 2025, researchers at ESET identified a new ransomware variant named HybridPetya that combines destructive Petya/NotPetya traits with advanced UEFI attack capabilities. Leveraging the CVE-2024-7344 vulnerability, attackers were able to bypass UEFI Secure Boot, allowing the malware to execute at a privileged level prior to OS load. Initial infection vectors appear to include phishing emails and software supply-chain compromises, leading to widespread disruption of targeted organizations’ endpoints, encrypted data, and in some instances, bricked devices. The attack highlights a disturbing escalation in ransomware sophistication and targeting, with significant operational downtime and financial losses reported in affected sectors. HybridPetya represents an evolution in ransomware, merging firmware exploitation with traditional payload delivery to maximize impact. This incident underscores the expanding threat landscape as adversaries weaponize newly discovered vulnerabilities and aim higher up the trust chain, intensifying pressure on organizations to harden their endpoints and update defenses in real time.
6 months ago
Kill Chain
HiddenGh0st, Winos & kkRAT Malware: How SEO & Cloud Hosting Fueled a 2025 Chinese-Focused Attack
In September 2025, a sophisticated malware campaign targeted Chinese-speaking users through SEO poisoning and fake software sites, resulting in the widespread distribution of HiddenGh0st, Winos, and kkRAT malware. Attackers manipulated search results using SEO plugins, registered lookalike domains, and leveraged GitHub Pages to host malicious files. Unsuspecting users, believing they were downloading legitimate utilities, instead installed remote access trojans that enabled full compromise of their systems, data theft, and prolonged adversary presence. The campaign demonstrates coordinated threat actor use of both social engineering and modern cloud hosting platforms to bypass traditional security controls. This incident highlights an escalating trend of threat actors combining SEO manipulation with cloud-native infrastructure to launch convincing malware campaigns at scale. The use of popular developer tools like GitHub Pages for payload delivery complicates traditional egress controls, detection, and response, requiring organizations to bolster threat intelligence, web filtering, and zero-trust segmentation strategies.
6 months ago
Kill Chain
AI-Powered Villager Tool: How Cyberspike's PyPI Release Raised Global Supply-Chain Alarm
In 2025, a China-based group known as Cyberspike released an AI-powered penetration testing framework called 'Villager' on the Python Package Index (PyPI). Garnering nearly 11,000 downloads, Villager was marketed as a red teaming tool but drew significant attention after security researchers highlighted its dual-use potential for both legitimate and malicious activities. The framework’s advanced automation and stealth features make it attractive for attackers seeking to exploit software supply chains and pivot across cloud and hybrid environments, raising the risk profile for developers and organizations using open-source components. This incident underscores growing concerns about the unintended consequences of democratized offensive security tooling, particularly when distributed through popular code repositories. The rapid adoption and potential for supply-chain compromise highlight the urgency for heightened code vetting, continuous monitoring, and robust supply-chain security policies.
6 months ago
Kill Chain
Mass Browser-Based Attack Hits Enterprises: 2025’s Session Hijacking Wakeup Call
In August 2025, a sophisticated wave of browser-based attacks exploited vulnerabilities in popular browser components to hijack user sessions across multiple financial and technology firms simultaneously. Attackers leveraged phishing lures and malicious advertising to distribute payloads capable of intercepting authentication tokens and session cookies, enabling widespread unauthorized access. The campaign, attributed to a financially motivated eCrime group, enabled lateral movement within compromised cloud and SaaS applications, resulting in significant data exfiltration, temporary access loss, and incident-driven downtime for several affected organizations. This incident underscores a dramatic uptick in browser-native TTPs targeting identity, session integrity, and trusted cloud access. Threat actors are exploiting the growing reliance on web-based workflows and overlooked intra-browser security, making enhanced endpoint monitoring and Zero Trust controls more urgent than ever.
6 months ago
Kill Chain
Self-Replicating Worm Strikes npm: 2025 Supply Chain Attack Exposes Critical Credential Risks
In September 2025, a major supply chain attack targeted the npm ecosystem, compromising over 40 packages and impacting projects worldwide. Attackers utilized a self-replicating worm delivered via manipulated npm modules; these modules would download, alter, and republish themselves by embedding malicious scripts directly into package files. As a result, sensitive developer credentials and system access tokens were harvested at scale, putting thousands of developer environments and downstream applications at risk, eroding trust in open-source software supply chains. This campaign highlights the growing risk and sophistication of supply chain attacks leveraging automated propagation across trusted developer channels. With the expanding reliance on open-source components and increasing regulatory scrutiny, organizations must urgently strengthen controls around development pipelines and dependency security.
6 months ago
Kill Chain
Phoenix RowHammer: How Advanced DDR5 Memory was Hacked in 2025
In August 2025, researchers from ETH Zürich and Google unveiled "Phoenix," a sophisticated RowHammer attack variant (CVE-2025-6202, CVSS 7.1) targeting SK Hynix DDR5 memory chips. Despite modern hardware defenses, Phoenix exploits advanced memory vulnerabilities to flip bits in protected memory rows, fully bypassing current mitigation technologies. The attack achieved successful exploitation in as little as 109 seconds, highlighting a critical weakness in memory protection schemes and raising concern for sensitive computing environments, from cloud servers to critical infrastructure. This incident demonstrates the evolving threat landscape for hardware-level attacks, emphasizing the urgency for chipmakers and enterprises to scrutinize and enhance DDR5 memory protections. Ongoing research into side-channel and memory-based exploitation, alongside increasing hardware reliance, make this a timely warning for organizations relying on modern DRAM.
6 months ago
Kill Chain
Multilingual Phishing: FileFix Variant Delivers StealC Infostealer in 2025
In September 2025, security researchers identified a sophisticated phishing campaign delivering a new variant of the StealC information-stealer malware via a convincing, multilingual phishing website impersonating popular brands such as Facebook Security. The attackers leveraged advanced social engineering tactics, widespread language support, heavy anti-analysis measures, and advanced obfuscation to successfully bypass traditional security detections. The campaign’s initial access was achieved through social engineering, leading victims to download malicious payloads disguised as legitimate files, which, once executed, exfiltrated credentials and sensitive data at scale. This incident highlights an ongoing surge in multilingual, highly tailored phishing approaches that utilize advanced anti-detection techniques, making detection and mitigation more difficult. Organizations face mounting pressure to strengthen controls against information stealers as attackers adapt proven TTPs to bypass endpoint protection and target a global victim base.
6 months ago
Kill Chain
Chaos Mesh Critical GraphQL Flaws Put Kubernetes Clusters at Risk in 2025
In September 2025, multiple critical vulnerabilities were discovered in Chaos Mesh, a popular cloud-native chaos engineering platform, exposing Kubernetes clusters to remote code execution (RCE) via unauthenticated GraphQL endpoints. Attackers with minimal in-cluster network access could exploit these flaws to execute arbitrary code, trigger disruptive fault injections (such as pod deletion and network outages), and ultimately achieve full cluster takeover. The vulnerability stemmed from insufficient access controls and improper GraphQL API handling, allowing adversaries to escalate privileges and compromise cluster workloads. As a result, organizations relying on Chaos Mesh in production faced heightened risk to workload integrity and business continuity until patches were applied. This breach highlights the increasing threat to supply-chain components in cloud-native environments, where tools with high privileges can inadvertently expose entire clusters. The rapid disclosure and fix cycle signals a need for strict RBAC, vigilant monitoring, and timely patching as attacker focus shifts towards exploiting platform-level risks.
6 months ago
Kill Chain
Microsoft & Cloudflare Dismantle RaccoonO365 Global Phishing Network (2025)
In September 2025, Microsoft’s Digital Crimes Unit (DCU), in partnership with Cloudflare, coordinated a global takedown of the RaccoonO365 phishing network. The PhaaS operation leveraged 338 domains to deliver convincing Microsoft 365 phishing campaigns, compromising over 5,000 credentials across 94 countries since July 2024. By obtaining a court order from the Southern District of New York, DCU seized infrastructure used by the financially motivated RaccoonO365 group, disrupting ongoing credential theft and reducing further business email compromise (BEC) risk to organizations worldwide. This incident underscores the rapid evolution and global scale of phishing-as-a-service networks, which are automating credential theft across cloud platforms. As attackers exploit trusted SaaS brands with commodity toolkits, vigilance around cloud identity and supply chain access is now a critical board-level concern.
6 months ago
Kill Chain
TA558 Leverages AI-Generated Scripts to Deploy Venom RAT in 2025 Brazilian Hotel Attacks
In the summer of 2025, the threat actor group TA558 launched a series of targeted phishing campaigns against hotels and the hospitality sector in Brazil and other Spanish-speaking regions. Leveraging AI-generated scripts, TA558 distributed Remote Access Trojans (RAT) such as Venom RAT via malicious email attachments disguised as business invoices. The attackers gained unauthorized access to hotel infrastructure, enabling surveillance, data theft, and lateral movement within targeted environments. Kaspersky researchers attributed the activity to the RevengeHotels cluster and noted reliance on sophisticated social engineering and automation. This incident exemplifies the rising integration of AI in cyberattacks, increasing the efficacy and resilience of threat actors like TA558. Organizations in hospitality and other sectors with valuable customer data face growing risks from AI-driven malware and must adapt their defenses to faster-evolving adversarial techniques.
6 months ago
Kill Chain
AI-Enhanced Malware: How EvilAI’s Stealth Attacks Redefined Cyber Threats in 2024
In early 2024, cybersecurity researchers identified a widespread campaign leveraging 'EvilAI'—a threat actor embedding artificial intelligence into seemingly legitimate productivity apps to deliver advanced malware. These AI-backed tools enable the malware to evade traditional antivirus detection, utilizing encrypted traffic and adaptive, stealthy behavior to propagate across organizational networks. The primary attack vectors were phishing emails and malicious downloads, which provided initial access before lateral movement was observed within compromised environments. As a result, hundreds of companies worldwide suffered business disruptions, data theft, and increased recovery costs from incident response efforts. This incident highlights the escalating sophistication of malware campaigns driven by artificial intelligence. The fusion of classic malware tactics with AI-enabled evasion makes traditional security controls less effective, underlining the urgency for organizations to adopt advanced, behavior-based defenses and prioritize zero trust architectures to mitigate evolving threats.
6 months ago
Kill Chain
KillSec Ransomware Campaign Targets Brazilian Healthcare Supply Chain
In April 2024, the KillSec ransomware group orchestrated a cyberattack against a major Brazilian healthcare software provider, targeting a core element of the nation’s healthcare technology supply chain. According to cybersecurity researchers, the attackers leveraged sophisticated ransomware tactics to breach the provider’s environment, exfiltrate sensitive patient data, and subsequently encrypt vital systems, disrupting normal operations. The breach involved the theft of confidential healthcare records, potentially exposing personally identifiable information (PII) as well as critical medical data, raising alarms across Brazil’s healthcare sector. As a result, provider services experienced significant operational delays and financial impact, and the wider ecosystem faces cascading risks from the exposed data. This incident is particularly noteworthy due to the healthcare sector’s growing vulnerability to ransomware attacks, with supply chain vectors increasingly exploited by threat actors like KillSec. The event reflects a concerning trend of ransomware groups shifting toward critical infrastructure and service-provider targets, amplifying regulatory, compliance, and patient safety pressures.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports