Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
478,000 Patients Impacted: Covenant Health Suffers Major Qilin Ransomware Breach in 2025
In May 2025, Covenant Health, a prominent Catholic healthcare provider in New England and Pennsylvania, experienced a significant ransomware attack by the Qilin group. The attackers breached the organization's systems on May 18, exfiltrated approximately 852GB of sensitive data—including names, addresses, social security numbers, medical records, and health insurance information—and subsequently encrypted essential files. Discovery of the breach occurred on May 26, with the scale initially underestimated, before forensic analysis revealed that nearly 478,000 patients were affected. The organization launched a comprehensive investigation, secured its systems, and is offering 12 months of free identity protection to impacted individuals. This breach highlights the continued targeting of healthcare organizations by sophisticated ransomware groups seeking to exploit large troves of sensitive personal and medical data. With ransomware tactics evolving and threat actors increasingly publishing stolen data for extortion, robust data protection and incident response have become critical priorities for healthcare providers.
8 months ago
Kill Chain
How Transparent Tribe’s 2026 RAT Offensive Breached Indian Government & Academia
In early 2026, the advanced persistent threat group Transparent Tribe (APT36) launched a sophisticated cyber espionage campaign targeting Indian governmental and academic institutions. Attackers distributed spear-phishing emails containing ZIP archives with malicious Windows shortcut (LNK) files, disguised as legitimate PDFs. Upon execution, these files deployed remote access trojans (RATs) by loading encrypted payloads in-memory and displaying decoy documents to evade suspicion. The malware adapted its persistence techniques based on detected antivirus solutions and enabled functions such as file management, system reconnaissance, data exfiltration, and command execution via a dynamic command-and-control infrastructure. This incident highlights the persistent evolution of state-linked cyber threats and the rising use of multi-stage spear-phishing, evasive loaders, and context-aware persistence. As state-sponsored attacks become more adaptive and target the public sector, organizations face increased regulatory and operational pressure to fortify internal security controls and monitor lateral movement.
8 months ago
Kill Chain
Kimwolf Botnet: When Residential Proxies Turn Your LAN Into a Global Attack Platform
In late 2025, a rapidly growing botnet called Kimwolf infected over two million devices worldwide, primarily through compromised Android TV boxes and digital photo frames lacking basic security controls or authentication. Attackers abused vulnerabilities in residential proxy networks—particularly via IPIDEA—to tunnel through external firewalls, gaining direct access to devices inside private networks. Kimwolf malware leveraged DNS tricks and default-enabled Android Debug Bridge (ADB) to enable lateral movement, turning victim devices into nodes for ad fraud, account takeovers, content scraping, and high-volume DDoS attacks, demonstrating unprecedented attacker reach into home and small business LANs. Kimwolf's swift expansion and post-takedown resilience reveal a new class of threats exploiting insecure IoT and overlooked network entry points inside residential and SMB environments. The incident highlights emerging risks from mass-produced, inadequately secured consumer tech and proxy networks, urging organizations to reconsider internal network trust assumptions and prioritize visibility, segmentation, and policy-driven controls to stop lateral movement and botnet proliferation.
8 months ago
Kill Chain
2025 Cloud Provider Breach: Multi-Vector Ransomware and the East-West Security Imperative
In early 2025, a sophisticated multi-vector cyberattack struck a leading multinational cloud services provider. Threat actors leveraged a combination of zero-day exploits, lateral movement, and exploited east-west traffic weaknesses to progressively compromise internal workloads across hybrid and multicloud environments. Utilizing encrypted channels, they evaded detection and ultimately deployed pervasive ransomware, resulting in widespread data exfiltration, service disruptions, and significant financial and reputational damage. Despite existing controls, gaps in segmentation and egress policy enforcement were exploited, with the incident exposing vulnerabilities in both cloud-native and on-premise environments. This breach highlights an escalating trend: attackers using complex, multi-stage TTPs that blend cloud-native exploits with traditional ransomware vectors. Security leaders must prioritize zero trust segmentation, real-time east-west inspection, and enforceable multicloud security controls to address rapidly evolving threat landscapes.
8 months ago
Kill Chain
RondoDox Botnet Weaponizes Critical React2Shell Flaw: Lessons from a Global IoT Hijack
From March to December 2025, the RondoDox botnet orchestrated a widespread campaign by exploiting the critical React2Shell (CVE-2025-55182) vulnerability to compromise over 90,000 Internet of Things (IoT) devices and web servers globally, with a major concentration in the U.S. Attackers conducted phased operations, ranging from reconnaissance and mass scanning to the automated deployment of advanced Mirai-based payloads and cryptocurrency miners. Capable of remote code execution, RondoDox’s malware loader established persistence, eliminated rival threats, and enabled command-and-control operations for further lateral movement and resource hijacking. This breach highlights an alarming trend of botnets swiftly weaponizing zero-day vulnerabilities in widely used frameworks like React and Next.js, amplifying both organizational and regulatory risk across hybrid and IoT environments. Growing sophistication in persistence mechanisms and targeted east-west attacks underscores the urgent need for robust segmentation, continuous monitoring, and zero trust advances.
8 months ago
Kill Chain
GhostAd Drain 2026: How Multi-Vector Malware and Botnets Are Redefining Cyber Risk
In early January 2026, a sophisticated cyber campaign dubbed "GhostAd Drain" targeted organizations across multiple sectors with a blend of malware, proxy botnets, and cloud service exploits. Attackers deployed malicious payloads primarily via phishing emails and poisoned advertisements, leveraging advanced evasion tactics such as encrypted east-west traffic, dynamic segmentation bypass, and multicloud movement. The campaign quickly compromised endpoint devices—including macOS systems—establishing proxy botnets for command-and-control while siphoning sensitive data through encrypted channels. As a result, affected organizations faced operational disruptions, data exfiltration, and heightened recovery costs. This incident underscores a marked escalation in threat actor capability, blending classic malware with adaptive, multi-vector Tactics, Techniques, and Procedures (TTPs) to evade traditional controls. The campaign’s success highlights the pressing need for organizations to adopt zero trust segmentation, enhance multicloud visibility, and enforce robust east-west traffic controls to mitigate modern, polymorphic attack patterns.
8 months ago
Kill Chain
Trust Wallet Chrome Extension Breach: $8.5M Lost in Shai-Hulud Supply Chain Attack
In December 2025, Trust Wallet suffered a major supply chain attack targeting its Google Chrome browser extension. Attackers exploited leaked GitHub secrets to gain unauthorized access to Trust Wallet's source code and Chrome Web Store API keys, bypassing the firm’s standard release reviews. Malicious actors then uploaded a trojanized extension update that harvested user wallet mnemonic phrases and exfiltrated them to attacker-controlled infrastructure. The breach led to a rapid compromise of at least 2,520 digital wallets and the theft of approximately $8.5 million in cryptocurrency, prompting a large-scale reimbursement and investigation effort by Trust Wallet. This incident highlights the escalating trend of supply chain attacks exploiting trusted software dependencies and underscores the urgent need for rigorous release controls and key management in the software lifecycle.
8 months ago
Kill Chain
SmarterMail 2025: Critical Pre-Auth File Upload Flaw Threatens Global Email Servers
In December 2025, Singapore's Cyber Security Agency (CSA) issued an alert concerning a critical pre-authentication vulnerability (CVE-2025-52691) in SmarterTools SmarterMail email servers. The flaw allows unauthenticated remote attackers to upload arbitrary files to any location on the server, leveraging an unvalidated GUID parameter for path traversal via the '/api/upload' endpoint. An attacker could exploit this for remote code execution, potentially resulting in full compromise of the server, with malicious files executed under system privileges. Although no in-the-wild exploitation has been confirmed, more than 16,000 vulnerable public-facing servers were identified globally. This incident underscores growing risks from exposed infrastructure and rapid exploitation of high-severity application flaws. With threat actors increasingly targeting business-critical communication platforms, organizations face mounting pressure to quickly remediate vulnerabilities and bolster segmentation and detection capabilities in line with zero trust frameworks.
8 months ago
Kill Chain
Kimwolf Botnet 2025: The Largest IoT Attack Forces Rethink of DDoS and Proxy Security
In 2025, a record-shattering wave of distributed denial-of-service (DDoS) and proxy attacks targeted high-profile websites including KrebsOnSecurity.com, Google, and Cloudflare. Initial attribution pointed to the Aisuru botnet, but subsequent investigation by XLab and others revealed the underlying infrastructure was largely driven by the Kimwolf botnet, comprising over 1.8 million compromised Internet-of-Things (IoT) devices. The attackers leveraged vulnerable connected devices worldwide, harnessing them not only for disruptive DDoS campaigns but also for proxy rental services that enabled cybercriminal anonymity, exposing widespread insecurity in IoT ecosystems. This incident underscores a concerning shift: major botnets are evolving from sporadic attacks to persistent, multi-purpose criminal platforms. It highlights the urgent need for enterprises to address IoT security gaps and for cloud providers to enforce robust countermeasures against residential proxy abuse and large-scale botnet activity.
8 months ago
Kill Chain
Silver Fox Exploits Income Tax Phishing to Deploy ValleyRAT in India (2025)
In December 2025, the Chinese-origin threat group Silver Fox launched a sophisticated phishing campaign targeting Indian users with income tax-themed emails. Victims received emails purportedly from India’s Income Tax Department containing decoy PDF attachments. When recipients opened the PDFs, they were redirected to a malicious website serving a ZIP file with a trojanized installer. The infection leveraged DLL hijacking and a legitimate executable to sideload malware, ultimately installing ValleyRAT—a modular remote access trojan—by process hollowing. Once active, ValleyRAT enabled attackers to harvest credentials, establish persistence, and communicate via encrypted channels for ongoing control. This incident highlights the convergence of advanced phishing lures, supply chain manipulation, and evasive malware tailoring persistent access to high-value targets across public, financial, healthcare, and technology organizations. ValleyRAT’s modularity, anti-analysis features, and delayed communication underline a pivot towards low-noise, highly adaptive attacks exploiting human trust and regulatory touchpoints.
8 months ago
Kill Chain
MongoBleed 2025: Global Memory Leak Puts MongoDB Data at Risk
In December 2025, a high-severity vulnerability named MongoBleed (CVE-2025-14847) was identified in multiple MongoDB versions with default settings, allowing unauthenticated attackers to leak sensitive server memory, including credentials and access tokens. Public disclosure and proof-of-concept code triggered a surge in exploitation, leaving more than 75,000 vulnerable instances exposed globally. Security researchers highlight the ease of exploitation, scale of potentially affected organizations, and absence of forensic evidence, which complicates post-incident investigations and raises the risk of undetected data exposure. Countries most affected include China, the United States, and several European and Asian nations. This incident underscores the urgent risk posed by memory-leak vulnerabilities in widely deployed open-source technologies and highlights the accelerating cycle from disclosure to weaponization. It also signals how reduced staffing during holiday periods can hinder detection and response, contributing to lingering risks and delayed mitigation.
8 months ago
Kill Chain
Coupang’s $1.17B Insider Data Breach Puts Spotlight on Retail Security
In June 2024, Coupang, South Korea’s largest online retailer, announced a data breach impacting 33.7 million customers after discovering unauthorized access to customer data in May 2024. The breach, attributed to an insider threat, exposed sensitive information including names, contact details, and purchase histories. Coupang committed $1.17 billion (1.685 trillion KRW) in compensation, underlining the massive scale and business impact. Investigations revealed misuse of privileged access led to the data exfiltration, making this one of Korea’s most significant consumer data breaches. This incident highlights escalating risks from insider threats amid expanding data footprints in retail and e-commerce. In the wake of regulatory scrutiny and increasing consumer privacy demands, organizations face mounting pressure to implement advanced east-west traffic monitoring, zero trust segmentation, and comprehensive anomaly detection to protect sensitive customer data.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports