ZeroHour

Search: “Mexico”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America

Unit 42 says Latin American attackers used LLMs to automate post-exploitation in campaigns hitting Mexican government, water utilities, and Brazilian financial firms.

Unit 42 identified two campaigns in Latin America whose operators used commercial LLMs (Claude, GPT-4.1) behind a self-hosted NextChat interface to generate and debug post-exploitation scripts. Cluster CL-CRI-1131 compromised a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador, using native Windows tools and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit. Cluster CL-CRI-1163 targeted Brazilian financial organizations with job-themed phishing, custom RATs, and a Go-based reverse SOCKS5 tunneling utility called SockTz, with nine versions deployed within roughly two hours. Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064.

GBHackersupdated · 6d agofirst · 6d agoThreat actor in the wild 2 sources1

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Mexico's 2025-2030 Cybersecurity Plan sets a national roadmap to counter threats including ransomware and build durable cyber defenses.

Mexico published its 2025-2030 national Cybersecurity Plan, outlining the country's threat landscape — with ransomware highlighted as a key risk — and a roadmap for strengthening national cyber defenses. The plan defines priorities for building durable defensive capabilities over the five-year period.

Recorded Future · 22d agoPolicy & legal

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

Banking trojan Grandoreiro resurfaces in Mexico using DLL sideloading, now accounting for 40% of detections after its 2024 disruption.

Grandoreiro, a banking trojan disrupted in 2024, is active again with a new DLL sideloading technique. Mexico now accounts for 40% of the malware's detections. The resurgence signals renewed targeting of banking customers in Latin America.

Infosecurity Magazine · 28d agoMalware

Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

Unit 42 documents two AI-assisted intrusion campaigns against Latin American government, utility, and financial organizations using LLM-orchestrated tooling.

Palo Alto Networks Unit 42 tracks two ongoing intrusion clusters, CL-CRI-1131 (Mexican transportation, federal ministries, municipal water utilities) and CL-CRI-1163 (Brazilian financial sector), both using living-off-the-land techniques, SOCKS5 relays, and custom RATs. The attackers appear to orchestrate operations via commercial LLMs like Claude and GPT-4.1, evidenced by iterative batch scripts and AI-generated tunneling tool naming. The Mexican campaign (also reported as Operation Escaneo by CloudSEK) exfiltrated sensitive data via dynamic-DNS infrastructure with rotated multi-SAN TLS certificates between February and June 2026. This signals broader adoption of AI-enhanced operations by diverse threat groups in the region.

Palo Alto Unit 42 · 13d agoThreat actor in the wild1

Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites

Fortinet details Casbaneiro banking Trojan campaign hitting Latin American bank customers via invoice-themed PDF phishing, with AutoIt loading, RegSvcs.exe injection, and bank-site-triggered activation.

Fortinet identified an August 2026 Casbaneiro banking Trojan campaign targeting users in Argentina, Peru, Colombia, and Mexico through phishing PDFs styled as urgent invoices or legal notices. The staged chain uses IP-based geo-filtering, a Base64-encoded ZIP, an HTA file, and a legitimate AutoIt interpreter before injecting into RegSvcs.exe or mobsync.exe and persisting via a Startup shortcut. The Trojan exfiltrates address book and Outlook data unencrypted, stays dormant until victims visit targeted bank sites, then accepts commands for keyboard control, clipboard pasting, file execution, and command execution. It uses an expected HTTP 403 response from a second server and malformed HTTP requests to complicate network analysis.

Cyber Security News · 2d agoMalware in the wild

ChatGPT-using lawyer punished for citing fake testimony from made-up witnesses

New Mexico Supreme Court holds lawyer in contempt for filing a ChatGPT-generated brief citing fabricated witness testimony; fined $5,000 and referred to disciplinary board.

The New Mexico Supreme Court held criminal defense lawyer Stephen Aarons in direct contempt for filing a murder-appeal brief containing false testimony from wholly fabricated witnesses, including Officer Michelle Amarillo and Officer Sanchez, plus misrepresented legal authority. Aarons admitted feeding a computer-generated trial transcript into ChatGPT, powered by the OpenAI o3 model, and filing the output without verifying factual claims or telling his client. He was fined $5,000, referred to a disciplinary board, and barred from appearing before the court pending proceedings; the court struck all briefs and ordered new counsel for client Oscar Renee Sandoval.

Ars Technica · AIupdated · 4d agofirst · 4d agoAI safety & security 2 sources

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

US sanctions individuals tied to Iranian hacking-for-hire group the Mabna Institute over cyber-attacks.

The United States has imposed sanctions on individuals connected to the Mabna Institute, an Iran-based hacking-for-hire group. The move targets the actors behind Iranian cyber-attack operations. Sanctions are a government enforcement action rather than a new technical threat.

Infosecurity Magazine · 22d agoPolicy & legal

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Trump's Executive Order 14420 declares a national emergency to restrict foreign-made bulk-power grid equipment over cyber, sabotage and supply-chain risks.

Executive Order 14420, signed August 26, declares a national emergency regarding the foreign supply of bulk-power system electric equipment to the United States. It empowers the Energy Secretary to restrict transactions with designated Covered Foreign Entities involving equipment, software, firmware, digital services, maintenance services, and remote-access capabilities. Covered equipment includes transformers, generators, inverters, RTUs, PLCs, intelligent electronic devices, and protective relays, with transmission rated 69 kV or higher in scope while local distribution is excluded. Already-installed foreign equipment may be subject to identification, isolation, monitoring, or replacement requirements, with phased compliance and pre-qualified vendor exemptions permitted.

Security Affairs · 18d agoPolicy & legal

Exploring the Latest Mispadu Stealer Variant

Unit 42 found a new Mispadu infostealer variant targeting Mexican users via malicious .url files exploiting the SmartScreen CVE-2023-36025 bypass.

Unit 42 discovered a new variant of Mispadu Stealer, a Delphi-based banking trojan first reported in 2019, found while hunting for the Windows SmartScreen bypass CVE-2023-36025. The campaign uses crafted .url files referencing UNC network-share paths with an HTTP port (@80) that forces payload retrieval over WebDAV via rundll32.exe, avoiding SmartScreen warnings. Analyzed samples (~4 KB, compiled 2023-11-12) predate the CVE publication, and ZIP payloads were likely distributed as email attachments, primarily targeting users in Mexico.

Palo Alto Unit 42 · Aug 17, 2026Malware in the wildCVE-2023-360251

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police arrested four over a €30 million bank fraud exploiting a payment provider's faulty software update, seeking three more in Europe.

Operation Klonen executed 21 search-and-seizure warrants across seven Brazilian cities on August 13, arresting four people while three more suspects are pursued in Spain and Bulgaria. The ring exploited a vulnerability in a German payment service provider's booking process, caused by a faulty software update, to carry out unauthorized withdrawals totaling around €30 million within four days starting in late 2023. Funds were moved to Brazil through payment cards issued without consent, pass-through accounts, companies and virtual asset platforms, and courts ordered seizure of assets worth about R$106 million (~$20.7 million). The operation involved Brazil's Polícia Federal, Germany's BKA and the Frankfurt prosecutor's ZIT cybercrime unit.

Help Net Security · Aug 17, 2026Policy & legal

Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

A Chinese-language cybercriminal group is compromising Brazilian government and education servers to host gambling-themed phishing sites via a reverse-proxy network.

Dark Reading reports that a Chinese-language cybercriminal group is hacking Brazilian government and education websites to build a reverse-proxy network used to serve gambling-themed phishing sites. The available text gives limited detail on the number of compromised servers or specific victim organizations.

Dark Reading · 8d agoThreat actor in the wild

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

AI-orchestrated campaign exploited PaperCut NG/MF RCE (CVE-2026-81578/82078), compromising 440+ instances at 395 organizations in 48 countries.

GreyNoise tracked a likely Russian-speaking actor using AI (OpenAI Codex harness plus a DeepSeek model) to develop, test, and deploy exploits for PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078) starting 31 August 2026. The actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, achieving domain admin at 12 victims — fastest time to domain admin was five minutes and a US high school was fully compromised in seven minutes. Attack paths involved LSASS memory and registry secret harvesting, pass-the-hash to domain controllers, noPac attacks, account additions to Domain Admins, and DCSync to exfiltrate full NTDS.DIT credential dumps. Impact scope suggests access development potentially for handoff, with prior PaperCut intrusions historically leading to extortion.

GreyNoise · 7d agoThreat actor in the wildCVE-2026-81578CVE-2026-82078CVE-2021-42278+1 CVEs1

Norway announces investigations into telecom Telenor’s work with Myanmar junta

Norwegian police opened crimes-against-humanity and sanctions investigations into Telenor's data handovers to Myanmar's junta, raiding its Oslo headquarters.

Norway's National Criminal Investigation Service is investigating Telenor for complicity in crimes against humanity for repeatedly handing over historical customer traffic data to Myanmar's military regime between the February 2021 coup and the March 2022 subsidiary sale. The Police Security Service is separately probing sanctions violations because the sale to M1 Group included sanctioned surveillance equipment transferred without foreign ministry permission. The subsequent resale passed historical call data of over 18 million people to junta-linked owners, and a class action on behalf of 1,200 people alleges the data enabled arrests, torture, and at least one execution.

The Record · 21h agoPolicy & legal

Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids

Meta's AI ad-detection failed to catch 350+ CSAM video ads on Facebook, Instagram, and Threads, some depicting images of real children.

The Tech Transparency Project found over 250 additional ads containing child sexual abuse material on Meta platforms since August, on top of ~53 previously removed, exceeding 350 total since late last year. Some ads used images of real children, including a European royal family minor and teen influencers, morphed into graphic sexual videos via AI face-swapping. Ads linked to nudification apps from Chinese developers and reached over 29,000 EU accounts plus thousands in the US, UK, Australia, and India.

WIRED · Security · 8d agoAI safety & security

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Check Point identifies Chinese-speaking group Gambling Goblin hijacking Brazilian government domains via malicious Apache modules for SEO-manipulated gambling phishing.

Check Point Research tracks a sustained campaign since mid-2025 against Brazilian government and educational organizations by Gambling Goblin, a Chinese-speaking cybercrime cluster linked to Earth Berberoka. Attackers compile and install malicious Apache modules that silently reverse-proxy visitors to phishing pages impersonating Google Play, Microsoft Store, and Amazon, chaining compromised high-reputation domains to inflate search rankings. The group deploys a heavily obfuscated Linux toolkit including DownPro, AlphaAgent, oRAT, a 3snake-based credential stealer, and SSH brute-forcers, with parallel phishing networks localized for Vietnamese, Spanish, and English victims.

Check Point Research · 14d agoThreat actor

The Government is Monitoring Anti

Fusion center bulletins reveal US law enforcement monitoring anti-Flock social media accounts and warning police ahead of the DeFlock Week of Action against license plate readers.

Public records requests by 404 Media and journalist Dan Boguslaw exposed intelligence bulletins from fusion centers in Colorado, Wisconsin, and Florida tracking anti-Flock sentiment, camera vandalism videos, and the DeFlock National Week of Action against automated license plate readers scheduled for August 16-22. The bulletins highlight Instagram accounts like Nomark.Project posting daily camera takedowns, and a device found during a June 25 traffic stop that could locate Flock cameras. Police are advised to increase patrols around ALPR locations and warned about upcoming DeFlock events, including 11 Florida cities signed up. DeFlock creator Will Freeman said the project never called for vandalism and that over 100 surveillance contracts have been canceled through civic engagement.

404 Media · Aug 12, 2026Policy & legal

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Academics linked Chinese vendor Geedge Networks' Tiangou Secure Gateway source code to one of the Great Firewall's three traffic filtering capabilities.

US researchers presenting at USENIX Security reconstructed Geedge Networks' Tiangou Secure Gateway firmware from over 100,000 leaked files, including Git repositories with commit history, and matched its filtering behavior to sections of China's Great Firewall. They found only 1 of 3 characterized DNS injectors matched Geedge code, noted the system relies on memory-unsafe C components and copied third-party code, and said its bugs could aid future circumvention tools. Geedge also exports censorship tools to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The newsletter additionally rounds up multiple breaches.

Risky Business News · 26d agoResearch2

Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt

Five Venezuelan nationals pleaded guilty to failed ATM jackpotting attempts in Kansas as the FBI reports 700+ US incidents in 2025.

The five defendants traveled from Indiana to Kansas in December 2025 and tried to install malware on ATMs in Wamego and Manhattan, planning to remotely trigger the machines to dispense cash. Both attempts failed — one triggered an alarm — and the men were arrested days later after surveillance captured the thefts. All five pleaded guilty to conspiracy to commit bank larceny; one has received a nine-month prison sentence. The FBI counted more than 700 jackpotting incidents in 2025 with over $20 million in losses, part of 1,900 incidents since 2020.

Security Affairs · 15d agoPhishing & fraud

Meta debuts its Muse AI agent. Will consumers trust it?

Meta launched Muse, a consumer AI agent powered by Muse Spark that connects to users' apps to execute tasks like emailing, booking travel, and payments.

Meta introduced Muse, a personal AI agent for US users that connects to email, calendars, payments, shopping, and other services to execute tasks such as booking travel, lowering bills, and completing purchases via Link by Stripe. The agent runs in a dedicated Muse Secure VM with a separate Sentinel agent kept apart at the system level, and Meta claims it cannot see passwords or payment data and does not share conversations with ad systems. Muse is free to start, with Power ($20/month) and Maximum ($100/month) subscription tiers, and is available on the web, iOS, Android, and WhatsApp, with Meta AI glasses support planned. The launch follows Meta's $18 billion multistate consumer-harms settlement and comes as rivals like Gemini Spark and Claude Cowork push agentic AI.

TechCrunch · AI · 7d agoAI industry 3 sources1

Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actors

Cyble's H1 2026 report attributes 2,188 of 3,836 global ransomware attacks (57%) to the Americas, with North America absorbing 1,981 incidents.

Cyble Research and Intelligence Labs tracked 3,836 ransomware incidents worldwide in the first half of 2026, with North and South America combining for 2,188 attacks, more than 57% of the global total. North America alone accounted for 1,981 attacks, driven by a mature multi-group Ransomware-as-a-Service economy competing for market share. The report dissects regional attack patterns and profiles the dominant ransomware actors across the two sub-regions.

Cyble · Aug 14, 2026Research

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

US Coast Guard and FBI boarded two foreign tankers bound for the US after indications their vessel networks were compromised, investigating possible Iranian involvement.

The Coast Guard and FBI conducted joint offshore security boardings of two commercial ships in the Gulf of Mexico on August 21 and 24 to examine their operational and IT systems following indications both networks were compromised. The vessels reportedly carried oil and natural gas, and one was hacked in the Strait of Gibraltar and lost communications for over 30 hours. No operational disruptions, vessel instability, or environmental impacts have been reported, and authorities are investigating whether Iran or another group exploiting US-Iran tensions was behind the attacks.

CyberScoop · 2h agoData breach in the wild

17th August – Threat Intelligence Report

Colombia's Ministry of Justice suffered a ransomware attack disrupting drug-monitoring and legal public services, per Check Point's 17 August 2026 threat intelligence report.

Check Point Research's weekly threat intelligence bulletin for 17 August 2026 leads with a ransomware attack on Colombia's Ministry of Justice. The attack affected part of the ministry's technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were impacted; the bulletin also aggregates other cyber research and attack discoveries from the week.

Check Point Research · Aug 17, 2026Ransomware

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

Group-IB says GoldFactory's Gigabud Android trojan uses Vwork, a weaponized Shelter fork, to clone banking apps into isolated Work Profiles and evade bank-side detection.

Group-IB's 'Hook for Gold' investigation found GoldFactory ships Vwork, a modified fork of the open-source Shelter app, alongside its Gigabud Android banking trojan, active since 2022. Vwork abuses Android Work Profile provisioning to clone banking apps into an isolated environment, weakening the link between detected malware signals and fraudulent transactions. Gigabud has targeted victims in Southeast Asia, Latin America, the Middle East, Africa, and beyond via fake airline, tax, and government apps requesting Accessibility and overlay permissions. In Indonesia, telemetry recorded about 1,469 compromised devices and roughly $960,939 in estimated losses between February and July 2026.

GBHackers · 7d agoMalware in the wild

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

Check Point links Gambling Goblin, a Chinese-speaking cluster, to malicious Apache modules hijacking Brazilian government servers to promote betting sites.

Check Point Research tracks Gambling Goblin, a Chinese-speaking cluster, installing malicious Apache reverse-proxy modules on compromised Brazilian government and education web servers since mid-2025. The modules divert visitors to gambling and fake app-store pages while stripping the site's security headers, likely for large-scale SEO manipulation. The group's Linux arsenal includes DownPro, AlphaAgent, oRAT, a 3snake-based credential stealer, and SSH brute-forcing tools, and it is tied to Trend Micro's Earth Berberoka. Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io.

The Hacker News · 14d agoThreat actor in the wild

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

Anthropic reports Claude was misused by Midnight Blizzard, ShinyHunters, disinformation campaigns, and bioweapon attempts; roundup also covers Xinbi takedown.

Anthropic's new report documents eight months of Claude misuse: Russian state-sponsored hackers (Microsoft-named Midnight Blizzard) used it for reconnaissance against Ukrainian and European government networks, stealing data and maintaining access, while ShinyHunters used it across hacking and extortion campaigns, and users attempted bioweapon development. Anthropic says it disrupted the activity. The WIRED roundup also covers the US seizure and sanctioning of Xinbi Guarantee, a Telegram black market with $30 billion-plus in sales mostly laundering pig-butchering scam proceeds, plus DOJ raids on 13 scam compounds in Madagascar and a four-year prison sentence for a Conti ransomware member. Meta faces scrutiny over AI child abuse ads and a class action over photo harvesting for AI training.

WIRED · Security · 4d agoAI safety & security in the wild 15 sources

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 12d agoPolicy & legal

The Smishing Deluge: China-Based Campaign Flooding Global Text Messages

Unit 42 attributes a global smishing campaign with 194,000+ phishing domains impersonating tolls, banks, and couriers to the Smishing Triad.

Palo Alto Unit 42 attributes ongoing smishing texts about toll violations and package misdelivery to the Smishing Triad, targeting U.S. residents since April 2024. Researchers identified 194,345 FQDNs across 136,933 root domains registered since January 2024, mostly via Hong Kong registrar Dominet (HK) Limited with Chinese nameservers and hosting concentrated on U.S. cloud services. The decentralized campaign impersonates banking, cryptocurrency, e-commerce, healthcare, law enforcement, and social media services, and its scale points to a large phishing-as-a-service operation. Phishing pages harvest national ID numbers such as Social Security numbers, home addresses, payment details, and login credentials.

Palo Alto Unit 42 · Aug 17, 2026Phishing & fraud in the wild1

Meta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case

Meta settles states' kids' online safety lawsuit for $17 billion, agreeing to landmark usage limits, age restrictions, and independent auditing.

Meta agreed to pay $17 billion to settle a civil suit from nearly every US state and territory alleging it hid research showing Facebook and Instagram are addictive to minors and violated COPPA by collecting data on children under 13. The settlement imposes reforms including two-hour daily limits for users under 18, a midnight-to-6am usage block, non-personalized feed options, and an independent auditor. Meta also settled separately with Texas for about $1 billion.

The Record · 20d agoPolicy & legal

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Group-IB reports the Gigabud Android banking trojan uses a cloned work profile to hide from banking app malware checks, with infections confirmed in Indonesia.

Group-IB says Gigabud installs a helper app called Vwork, derived from the open-source Shelter tool, which creates an Android work profile and drops a tampered banking app inside it, hiding the trojan from banking apps' malware scans. Gigabud, active since 2022 and linked by Group-IB to the GoldFactory group, abuses Accessibility access and overlay screens to steal credentials and run fraudulent payments while a black screen conceals the operator's actions. Group-IB confirmed the full attack chain on infected devices in Indonesia, counting about 1,469 compromised devices and estimated losses of roughly $960,000 between February and July 2026. Vwork-compatible Gigabud samples have been found targeting 11 countries including Brazil, Mexico, Indonesia, Thailand, and Türkiye, though only the Indonesian chain is confirmed.

The Hacker Newsupdated · 5d agofirst · 6d agoMalware in the wild 3 sources1

Revolut confirms customer data breach through fake government requests

Revolut disclosed customer identity data, including passports and possibly selfies, to an attacker using a legitimate government email domain.

Attackers impersonating a government agency used a legitimate agency email domain to submit fraudulent information requests, prompting Revolut to disclose customer identity and contact data to an unauthorized third party. Exposed data included birth dates, postal and email addresses, phone numbers, passport and driver's license copies, and possibly verification selfies, account statements, and transaction histories. Revolut said a limited number of customers were affected, blocked the email address, and notified the agency, law enforcement, and regulators, adding that systems and customer funds were unaffected. Security researcher ZachXBT reported the scam appeared to target high net worth users of the fintech, which serves over 80 million customers.

TechCrunch · Securityupdated · 2d agofirst · 4d agoData breach in the wild 3 sources3

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM

Hacker News ThreatsDay roundup: Defender BTR.sys driver abuse, DoJ charges 17 Mabna Institute members over IRGC-linked intrusions, Grandoreiro sideloading, OpenAI monitoring.

Check Point researchers showed Microsoft's signed Defender Boot-Time Removal driver (BTR.sys) can be repurposed as a universal kernel operation engine to bypass endpoint security without BYOVD. The DoJ charged 17 members of Iran's Mabna Institute, which on behalf of the IRGC stole over 31 TB of academic data from 144 US universities and compromised roughly 8,000 of 100,000 targeted professor accounts; the State Department offered a $10 million reward for five defendants. Separately, Acronis tracked a Grandoreiro campaign abusing DLL sideloading in the Duplicate Files Finder app across Latin America and Spain, while ErrTraffic ClickFix campaigns deliver Cruciferra (BYOVD) and Remus Stealer. OpenAI also previewed Private Safety Processing, a privacy-centric approach to monitoring model misuse without retaining customer content.

The Hacker News · 26d agoThreat actor1

A Secretive DHS ‘Predictive Policing’ Unit is Analyzing Americans’ Financial Habits and Pulling Them Over

404 Media reveals DHS Border Patrol's secretive Predictive Intelligence Targeting Teams (PITT) analyzing Americans' financial activity and feeding intelligence to local police for traffic stops.

404 Media identified Predictive Intelligence Targeting Teams (PITT) in the Spokane Sector (Washington) and Laredo Sector (Texas), which review law enforcement-sensitive databases including Americans' financial activity and pass intelligence to local police. In one case, a PITT analyst flagged financial patterns associated with narcotics activity, leading Montana Highway Patrol to stop a driver for an obstructed license plate and charge him with DUI and possession with intent to distribute. CBP declined to say what financial data is monitored or whether warrants are obtained; the program extends AP's earlier reporting on ALPR-based predictive policing.

404 Media · 8d agoPolicy & legal

Meta to Pay Up to $18B Over Teen Social Media Use

Meta agreed to pay up to $18 billion and cap teen Facebook and Instagram use at two hours daily, settling child-safety lawsuits from most US states.

Meta settled claims that it deliberately designed Facebook and Instagram to addict children, ending a federal trial as Instagram head Adam Mosseri began testifying and Mark Zuckerberg was expected to testify. Of roughly $16.7 billion for 47 states and territories, $12.7 billion is guaranteed and $5 billion is contingent on Snapchat, TikTok and YouTube adopting similar teen protections. The deal also resolved state privacy claims tied to Cambridge Analytica for an additional $459 million, while New Mexico (a $567 million ruling) and Florida opted out of the settlement.

Security Affairs · 20d agoPolicy & legal

Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection

GoldFactory-linked Gigabud and Vwork malware clone banking apps into hidden Android work profiles to evade fraud detection across 11+ countries.

Group-IB links Vwork, a modified version of the open-source Shelter app cloner, to the GoldFactory group and its Gigabud Android RAT, which clones victim banking apps into an isolated work profile so fraud sessions look clean to banks. From February through July 2026, researchers observed about 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated losses near $960,939. Targets span Brazil, Colombia, Egypt, Indonesia, Mexico, Morocco, the Philippines, Thailand, Türkiye, Laos, and a GCC state; delivery uses fake airline, tax, government, and banking apps pushed via phishing sites, messaging apps, and social media.

Cyber Security News · 7d agoMalware in the wild

NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

Unit 42 links NOKKI malware to North Korea's Reaper group, uncovering the Final1stspy dropper that deploys the DOGCALL RAT in politically motivated attacks.

Unit 42 analyzed the NOKKI malware family used in politically themed attacks against Russian and Cambodian speakers since July 2018. The researchers linked NOKKI to the Reaper group, publicly attributed to North Korea, whose custom DOGCALL RAT uses third-party hosting services to upload data and receive commands. A previously unreported family, Final1stspy, was found deploying DOGCALL, sharing a unique base64-to-hex deobfuscation routine with NOKKI droppers. Attacks used malicious Microsoft Word macros that download and execute payloads while opening decoy documents.

Palo Alto Unit 42 · Aug 17, 2026Malware

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

Casbaneiro banking Trojan targets Latin American bank users via phishing PDFs, geofencing, AutoIt staging, and distributed C2 servers to evade detection.

FortiGuard Labs detailed a Casbaneiro banking Trojan campaign observed in August 2026 targeting users in Argentina, Peru, Colombia, and Mexico via fake invoice and legal-notice emails. The operation uses geofenced landing pages, an HTA downloader with WMI-based sandbox checks, a legitimate AutoIt interpreter, and process injection into RegSvcs.exe (fallback mobsync.exe). C2 activation is conditional on victims visiting banking websites, enabling keyboard control, clipboard manipulation, and fake overlay windows for bank-focused fraud, while distributed exfiltration servers and unusual HTTP 403-based signaling hinder analyst correlation.

GBHackers · 2d agoMalware in the wild1

Gigabud Uses Android App Cloning to Evade Fraud Detection

Group-IB reports the Gigabud Android banking trojan clones bank apps into isolated work profiles via the Vwork tool to evade fraud detection, with roughly $960,000 in losses in Indonesia.

Group-IB found Gigabud now ships dedicated code to work with Vwork, a weaponized fork of the open-source Android cloning app Shelter it attributes to GoldFactory, exposing cloning functions so any installed app can call them. After installing via phishing sites and messengers posing as airline, tax and government apps, operators request accessibility and overlay permissions, then clone the victim's banking app into a new work profile where it is invisible to signature-based detection in the personal profile. Fake login screens and overlays capture credentials while cloned-app transactions appear to banks as coming from an unrecognized, malware-free device. Between February and July 2026 in Indonesia, Group-IB observed about 1,469 compromised devices, 1,281 potentially compromised logins and estimated losses of roughly $960,939, with Vwork-enabled samples targeting 11 countries including Brazil, Mexico, Egypt and Thailand.

Infosecurity Magazine · 7d agoMalware in the wild