ZeroHour

Search: “Cloud Software Group”

3 stories in the last 3d

BlackHatSect0r Uses DeepSeek-Powered AI Agent to Automate Attacks and Harvest 16,834 Credentials

SOCRadar linked the BlackHatSect0r crew to a DeepSeek-powered AI agent that automated scanning and harvested 16,834 credentials from exposed systems.

SOCRadar researchers found an exposed operation server with 4.9 GB across 9,299 files, including the DXSCAN scanning platform, phishing tools, extortion material and a vault holding 16,834 credentials such as AWS keys, GitHub tokens and Stripe keys. The French-speaking crew ran a Nous Research Hermes agent against a DeepSeek model with safety features removed, queuing 2,759,860 domains and reaching 726,989 hosts. Access came from misconfigurations like public cloud buckets and exposed .env files, not new vulnerabilities.

Cyber Security News · 3h agoThreat actor in the wild 4 sources1

Low-quality casino sites conceal highly dangerous threat actors

Infoblox reveals China-aligned APT groups hiding PeckBirdy malware C2 domains inside roughly 1.7 million Chinese-language illegal casino websites.

An Infoblox report says it tracks about 1.7 million Chinese-language casino sites enabling illegal gambling, some of which double as command-and-control infrastructure. China-aligned APT groups have hidden PeckBirdy framework C2 domains inside these low-quality casino sites since 2023, injecting scripts that display fake software update pages to deliver malware. Over 3 percent of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, and some sites rely on US cloud providers via 'infrastructure laundering.' Infoblox urges defenders not to dismiss casino-domain alerts as mere employee browsing violations.

The Register · Security · 1d agoThreat actor in the wild1

FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments

China-aligned APT FamousSparrow deployed a new modular backdoor, SparroWocky, against government entities across eight Latin American countries since August 2025, ESET reports.

ESET reports that China-aligned threat actor FamousSparrow replaced its SparrowDoor implant with SparroWocky, a distinct modular C++ backdoor active against governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Around 90% of the group's targets from mid-2025 into 2026 were in Latin America, which ESET links to regional competition over US influence. The backdoor arrives via a three-component DLL side-loading chain, persists through a Windows service (ProcAuditManager) or Run keys (SnapCart), captures screenshots, and exfiltrates RC4-encrypted data over TLS C2 on ports 443 and 8080. It supports in-memory Beacon Object File execution, API hashing, and SilentMoonwalk-style call-stack spoofing; IOCs for three C2 servers were released.

GBHackersupdated · 1h agofirst · 2h agoThreat actor in the wild 3 sourcesCVE-2021-26855