ZeroHour

Search: “threat actors”

8 stories in the last 24h

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.

Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.

The Hacker Newsupdated · 6h agofirst · 22h agoThreat actor in the wild 5 sourcesCVE-2020-0688CVE-2019-0708CVE-2021-26855+1 CVEs2

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Iranian state-linked hackers use CHOSEN BRICK Windows malware, spread via Telegram and WhatsApp social engineering, to spy on dissidents and journalists worldwide.

US, UK, and Dutch cyber agencies with the FBI issued a joint advisory on Iranian state-linked hackers deploying a Windows malware strain called CHOSEN BRICK against dissidents, activists, and journalists, primarily in the US, UK, and Netherlands. Attacks begin with messages on WhatsApp or Telegram impersonating trusted contacts or technical support, tricking victims into running malicious files disguised as apps such as Pictory, RunwayML, Norton Antivirus, Telegram, and KeePass. The malware persists via Registry Run keys, adds Microsoft Defender exclusions, and uses a per-victim Telegram bot for command-and-control while stealing email, Telegram and WhatsApp data, screenshots, and audio. Stolen data is exfiltrated via Telegram or cloud services like VultrObjects and StorjShare, and sometimes appears on pro-Iranian leak sites, increasing physical risk for dissidents abroad.

BleepingComputerupdated · 15m agofirst · 17h agoThreat actor in the wild 9 sources

APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal

Pakistan-linked APT36 deployed a Rust malware suite, including RUSTYSHADE and USB-spreading RUSTYMOVE, against Indian and Afghan government and defense targets.

Zscaler ThreatLabz tracks the August 2026 activity as Operation RapidRust, introducing the Rust-based RUSTYSHADE backdoor, the RUSTYMOVE removable-media propagation utility, and PSNATCH and BASHNATCH file stealers for Windows and Linux. RUSTYSHADE uses private GitHub repositories as C2 with AES-256-GCM-encrypted traffic, supporting shell commands, screenshots, webcam capture, and encrypted exfiltration, while PSNATCH collects Office documents, archives, images, and databases from user folders and drives D: through H:. Typosquat domains spoofing ThePrint and India Today staged payloads with Backblaze storage, and persistence used scheduled tasks impersonating OneDrive and Microsoft Edge updates.

GBHackersupdated · 3h agofirst · 4h agoThreat actor in the wild 3 sources

FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments

China-aligned APT FamousSparrow deployed a new modular backdoor, SparroWocky, against government entities across eight Latin American countries since August 2025, ESET reports.

ESET reports that China-aligned threat actor FamousSparrow replaced its SparrowDoor implant with SparroWocky, a distinct modular C++ backdoor active against governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Around 90% of the group's targets from mid-2025 into 2026 were in Latin America, which ESET links to regional competition over US influence. The backdoor arrives via a three-component DLL side-loading chain, persists through a Windows service (ProcAuditManager) or Run keys (SnapCart), captures screenshots, and exfiltrates RC4-encrypted data over TLS C2 on ports 443 and 8080. It supports in-memory Beacon Object File execution, API hashing, and SilentMoonwalk-style call-stack spoofing; IOCs for three C2 servers were released.

GBHackersupdated · 2h agofirst · 2h agoThreat actor in the wild 4 sourcesCVE-2021-26855

16-31 August 2026 Cyber Attacks Timeline

Hackmageddon logs 110 confirmed cyber incidents in 16-31 August 2026, with malware the top vector (35) and public-facing app exploitation (T1190) leading initial access.

Hackmageddon's timeline recorded 110 confirmed incidents in the second half of August 2026. Cyber crime accounted for roughly four-fifths of attacks (86 of 110), and malware was the leading vector at 35 incidents (31.8%). Exploitation of public-facing applications (T1190) was the top initial access vector with 33 incidents, while state-linked espionage motivated 16 incidents. Information and Communication was the hardest-hit sector with 29 of 132 sector mentions.

Hackmageddon · 4h agoThreat actor in the wild 2 sources1

Israeli contractor BlackCore trained Angolan officials in online influence operations

Citizen Lab links Israeli firm BlackCore to training Angolan officials to run covert influence campaigns with fake personas and pro-government content.

Citizen Lab documents show Israeli influence-for-hire firm BlackCore ran a 14-week training and operations program for Angolan officials, producing more than 40 pro-government content pieces through a fictitious outlet called Agita News. Posts received roughly 20,000 likes, with some later approaching 50,000, in a country with an estimated six million active Facebook users. France's Viginum previously linked BlackCore to interference targeting France Unbowed and suspected operations in New York, Scotland and Togo, and Meta disrupted a related Israel-origin network in August.

The Record · 1h agoThreat actor

BlackHatSect0r Uses DeepSeek-Powered AI Agent to Automate Attacks and Harvest 16,834 Credentials

SOCRadar linked the BlackHatSect0r crew to a DeepSeek-powered AI agent that automated scanning and harvested 16,834 credentials from exposed systems.

SOCRadar researchers found an exposed operation server with 4.9 GB across 9,299 files, including the DXSCAN scanning platform, phishing tools, extortion material and a vault holding 16,834 credentials such as AWS keys, GitHub tokens and Stripe keys. The French-speaking crew ran a Nous Research Hermes agent against a DeepSeek model with safety features removed, queuing 2,759,860 domains and reaching 726,989 hosts. Access came from misconfigurations like public cloud buckets and exposed .env files, not new vulnerabilities.

Cyber Security News · 4h agoThreat actor in the wild 4 sources1

SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firmsnew

Hunt.io links SpiceRAT C2 infrastructure to the China-nexus SilkParasite espionage cluster targeting Central Asian governments, telecoms, and energy firms.

Hunt.io analysis expanded the SpiceRAT command-and-control footprint tied to SilkParasite, a China-nexus espionage cluster (medium confidence per Bitdefender) targeting government, telecommunications, and energy entities across Central Asia. Five active servers coordinated from mid-March 2026 were clustered via reused hostnames, TLS certificates, and a byte-identical clone of RTX Corporation's webpage found on 13 IPs; a certificate for azure.uzrailwaystax[.]com appeared across eight servers. Domains impersonated Türkmengaz, Tojiktelecom, Turkmenistan's Foreign Ministry, and Uzbek and Kyrgyz bodies, with passive DNS history dating to mid-2022. Impersonated organizations were not confirmed as compromised; Cisco Talos previously linked SpiceRAT to SneakyChef's LNK/HTA infection chains.

GBHackers · 49m agoThreat actor in the wild 2 sources