ZeroHour

Search: “key extraction”

4 stories in the last 24h

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russianew

Kaspersky reports the NightEagle espionage group (APT-Q-95) expanded from China-focused targets to Russian companies, backdooring Microsoft Exchange servers with GhostContainer using stolen VPN credentials.

Kaspersky investigated several incidents over the past year at Russian businesses attributed to NightEagle (APT-Q-95), a group active since at least 2023 and previously focused on Chinese defense, semiconductor, AI, and quantum technology targets. Hackers used stolen credentials to access corporate networks through VPNs, targeted Microsoft Exchange servers, and installed the GhostContainer backdoor, believed deployed by extracting Exchange encryption keys and executing the payload in memory via Microsoft's web application framework. The group stored hacking tools in GitHub repositories disguised as legitimate software such as AdobeSync and TrueConf, exploited Active Directory weaknesses for privilege escalation and lateral movement, and targeted domain controllers. Attribution remains uncertain; Chinese researchers previously associated the group with North America.

The Record · 41m agoThreat actor in the wild 6 sources

Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware

Feral Wolf exploited Atlassian Confluence and 1C:Enterprise flaws to deploy GenieLocker ransomware across Russian retail, construction, manufacturing and IT firms.

BI.ZONE DFIR tracked Feral Wolf intrusions at Russian retail, construction, manufacturing, and IT organizations from May through August 2026. The actor exploited CVE-2023-22515 on internet-facing Confluence instances, deployed GSocket and Rust-based MQTTDoor/MatrixDoor backdoors using MQTT and Matrix C2, and used PwnKit (CVE-2021-4034) and Copy Fail (CVE-2026-31431) for privilege escalation and container-to-host escape. The group abused exposed 1C:Enterprise cluster managers and weak PostgreSQL credentials to move laterally before deploying GenieLocker ransomware.

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

SANS dissects a LausivLoader JavaScript malspam sample that passes staged payload file paths to PowerShell via process environment variables.

SANS analyzed a LausivLoader JavaScript sample caught in a customer's mail gateway from an August malspam campaign impersonating a fiber-optic procurement inquiry. The roughly 613 KB attachment (28/55 VirusTotal detections) hides code among 450 junk comment lines, drops two files into a randomized %TEMP% directory, and passes their paths to a PowerShell payload via process environment variables Kv7408 and Kv562. The final command launches PowerShell through conhost.exe with a Base64-encoded command; the script also copies itself and attempts to register a scheduled task.

SANS Internet Storm Center · 23h agoMalware in the wild

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Unit 42 exposed CL-CRI-1171, a pay-per-install operation spreading OfferLoader and Insomnia RAT via YouTube and SEO poisoning to corporate and government targets.

The ThreatsDay bulletin leads with Unit 42's disclosure of CL-CRI-1171, a pay-per-install marketplace using YouTube channels and SEO-poisoning funnels to push trojanized software and the OfferLoader loader, which delivered Docro Hijacker, ARKTunnel and the cross-platform Insomnia RAT between July 2025 and April 2026. Oasis Security reported that 230 of 243 unauthenticated LocalAI instances were exploitable, with root command execution confirmed on 23 servers, theft of 127 AWS credential records, and exfiltration from a Thai military workstation. The roundup also covers Irregular's research on agentic self-modification, an AEPD-notified breach executed with an AI agent, CISA's warning that ransomware gangs exploit VMware vCenter CVE-2026-59310, and Oracle's September 2026 CPU fixing over 800 flaws.

The Hacker News · 20h agoThreat actor in the wildCVE-2026-59310