Debunking OrbitShade: AI-Driven misinformation in Cyber Threat Intelligence
The recent public report dated April 29, 2025, alleging the existence of a state-sponsored malware named OrbitShade targeting satellite infrastructure appears to be a fabricated narrative likely generated...
Ransomware attack in MathWorks outage that paralyzed MATLAB
When the world’s engineers, scientists, and students logged in to MATLAB on May 18, 2025, many were met with silence—a digital void where powerful tools once lived. What...
Anatomy of the Winos 4.0 campaign
The Winos 4.0 campaign, as dissected by Rapid7, exemplifies the evolving sophistication of contemporary malware operations targeting Chinese-speaking environments. This campaign leverages a multi-layered loader architecture, dubbed the...
Dero miner container infection campaign
The recent campaign uncovered by Kaspersky, involving the Dero cryptocurrency miner spreading through containerized Linux environments by exploiting exposed Docker APIs, represents a sophisticated and highly automated threat...
Unmasking FrigidStealer: advanced macOS malware analysis and detection
FrigidStealer represents a sophisticated evolution in macOS-targeted malware, combining social engineering with technical evasion tactics to compromise sensitive data. First observed in January 2025, this information stealer masquerades...
Trojanized KeePass campaign: novel loader and credential theft in ransomware operations
A recent investigation by WithSecure’s Threat Intelligence team has uncovered a sophisticated malware campaign leveraging a trojanized version of the open-source password manager KeePass. This operation, active for...
JPEG image FUD ransomware: a way to evades antivirus solutions
In a concerning development for cybersecurity professionals, threat actors have begun leveraging a novel Fully UnDetectable (FUD) ransomware attack technique that utilizes seemingly benign JPEG image files as...
New malware LOSTKEYS uncovered in COLDRIVER campaign targeting Western governments and NGOs
The Google Threat Intelligence Group (GTIG) has recently uncovered a sophisticated new malware strain, dubbed LOSTKEYS, deployed by the Russian state-sponsored threat actor COLDRIVER (also known as UNC4057,...