ZeroHour

Search: “mount”

13 stories

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.

Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.

The Hacker Newsupdated · 5h agofirst · 21h agoThreat actor in the wild 5 sourcesCVE-2020-0688CVE-2019-0708CVE-2021-26855+1 CVEs2

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic disrupted APT29-linked GTG-20006, which used Claude to autonomously rebuild malware, hijack hotel Wi-Fi DNS, and target 20-plus Ukrainian, European, and US-linked organizations.

Anthropic attributed the campaign to GTG-20006, aligned with Midnight Blizzard (APT29/Cozy Bear), which developed an AI-driven process that monitors its implants against security products and autonomously rebuilds and redeploys detected malware. Targets included military intelligence, diplomatic, and defense organizations in Ukraine and Europe, plus Middle East and Asian maritime agencies; the actor compromised at least three hotel Wi-Fi vendors via DNS hijacking and served ClickFix lures delivering Windows, Android, and iOS malware such as PowerChrome, GiftDrop, and DarkSword. Operations also included a North African breach exfiltrating over 300,000 national identity records and 500,000-plus company registry entries, an Embassy Kit device-code phishing campaign stealing Microsoft 365 tokens from at least eight organizations, and WhatsApp account takeover using headless browsers. The campaign overlaps with CaptiveCrunch reporting from ReliaQuest, Microsoft, Google, and Lumen Black Lotus Labs.

The Hacker Newsupdated · 19h agofirst · 5d agoThreat actor in the wild 20 sources2

Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

Zscaler details Operation RapidRust: APT36 deploys four new tools including RUSTYSHADE, a Rust backdoor using private GitHub repos for encrypted C2.

Zscaler ThreatLabz documents Operation RapidRust, a campaign by Pakistan-aligned APT36 deploying four new tools: RUSTYSHADE, a 64-bit Rust Windows backdoor that uses attacker-controlled private GitHub repositories with a hardcoded PAT and AES-256-GCM-encrypted messages for C2; RUSTYMOVE; PSNATCH, a PowerShell file stealer that scans Office documents, archives, media, and databases modified in the last 120 days and exfiltrates up to 5 GB per run to per-machine GitHub repositories; and BASHNATCH. The backdoor was dropped via PowerShell from attacker-controlled Backblaze B2 storage and supports screenshots, webcam capture, file listing, downloads, and shell command execution.

Zscaler ThreatLabzupdated · 3h agofirst · 22h agoThreat actor in the wild 3 sources

Officials disrupt Chinese espionage operation that hit multiple federal agencies

FBI and DOJ seized QTFY infrastructure, disrupting a Chinese state-sponsored group that compromised federal agencies and critical infrastructure since 2018.

Authorities seized three domains powering QScan and QTRouter, the hacking suite of QTFY, a Chinese government-funded group operating through front company Nanjing Xinjiuwei Network Technology. Targets include the Departments of Energy, Justice, and Health and Human Services, the Federal Reserve, NASA, NIH, financial institutions, defense contractors, utilities, telecoms, and hospitals; the group exploited zero-days in Ivanti, Pulse Secure, Fortinet, Citrix, and others, intruding three DOE national labs in September 2024. QScan carried over 200 proof-of-concept exploits and processed more than two million scanning tasks in a single day in 2024.

CyberScoop · 21d agoThreat actor in the wild1

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

Bitdefender reports SilkParasite, a China-nexus espionage cluster targeting Central Asian governments with seven RATs, five newly documented, delivered via spearphished RAR archives.

Bitdefender Labs assesses with medium confidence that SilkParasite, first discovered in late 2025, is a China-nexus cluster targeting government bodies in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan, and Georgia. Attacks use password-protected RAR archives with malicious Office documents, macro-triggered DLL sideloading, and checks for running Kaspersky AV before execution. The arsenal spans seven RAT families in .NET, C++, Go, and JavaScript with plugin architectures and diverse C2 channels including Google Drive and HTTP cookie/ETag headers; roughly 65 DriveSilkRAT infections were observed, mostly in Asia. Ties to China include BLOODALCHEMY (a Deed RAT/ShadowPad descendant) and an improved SpiceRAT used by SneakyChef, with traces of AI-assisted development in the tooling and lures.

The Hacker News · 28d agoThreat actor in the wild

Threat Brief: Ongoing Russia and Ukraine Cyber Activity

Ukrainian government sites were defaced via OctoberCMS CVE-2021-32648 while Microsoft-attributed actor DEV-0586 deployed destructive WhisperGate malware.

Unit 42 tracks January 2022 attacks against Ukrainian government websites that were defaced or made inaccessible, which Ukraine attributed to Russia. Attackers exploited CVE-2021-32648, an account takeover flaw in OctoberCMS prior to 1.0.472, by submitting a boolean true as the password reset code to bypass validation. Separately, WhisperGate malware, attributed by Microsoft to DEV-0586, disabled Windows Defender and corrupted files across multiple Ukrainian organizations, using a ransomware-appearing first stage and an HTTPS-beaconing second stage with LOLBINs and anti-analysis techniques.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wildCVE-2021-326481