ZeroHour

Search: “memory systems”

3 stories in the last 24h

FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoornew

ESET attributes a new SparroWocky backdoor to espionage group FamousSparrow, deployed via exploited internet-facing Exchange servers across Latin American governments.

ESET's Welivesecurity team reports FamousSparrow gained initial access by exploiting publicly reachable Microsoft Exchange servers, with roughly 90 percent of targets since mid-2025 in Latin America, including governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group's new modular C-language backdoor SparroWocky replaces SparrowDoor and uses a three-part loader: a legitimate executable, a malicious DLL side-loaded in memory, and an encrypted payload. It persists via Windows services or Registry Run keys, supports screenshots, file operations, TCP proxying, Beacon Object Files, TLS/RC4-encrypted C2, and anti-forensics such as call-stack spoofing. IOCs including loader SHA-1 hashes and C2 IP addresses were published.

Cyber Security News · 15m agoThreat actor in the wild 3 sources

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.

Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.

The Hacker Newsupdated · 3h agofirst · 20h agoThreat actor in the wild 5 sourcesCVE-2020-0688CVE-2019-0708CVE-2021-26855+1 CVEs1

BlackHatSect0r Uses DeepSeek-Powered AI Agent to Automate Attacks and Harvest 16,834 Credentials

SOCRadar linked the BlackHatSect0r crew to a DeepSeek-powered AI agent that automated scanning and harvested 16,834 credentials from exposed systems.

SOCRadar researchers found an exposed operation server with 4.9 GB across 9,299 files, including the DXSCAN scanning platform, phishing tools, extortion material and a vault holding 16,834 credentials such as AWS keys, GitHub tokens and Stripe keys. The French-speaking crew ran a Nous Research Hermes agent against a DeepSeek model with safety features removed, queuing 2,759,860 domains and reaching 726,989 hosts. Access came from misconfigurations like public cloud buckets and exposed .env files, not new vulnerabilities.

Cyber Security News · 1h agoThreat actor in the wild 4 sources1