Tactical reality behind the India-Pakistan hacktivist surge
In May 2025, a wave of hacktivist activity targeting Indian digital infrastructure sparked widespread alarm in media and social networks, with numerous groups claiming significant breaches of government,...
From PDF invoice to geo-fenced RAT delivery campaign
A recent campaign targeting Southern European organizations demonstrates advanced evasion techniques combining social engineering, trusted platforms, and geolocation filtering. The attack chain unfolds through four precision stages: 1....
Emerging DOGE Big Balls ransomware campaign leverages multi-stage tooling and BYOVD exploits
A recent analysis of newly discovered payloads linked to the DOGE Big Balls ransomware operation reveals a complex infection chain combining open-source tools, kernel-level exploits, and psychological warfare....
Stealthy Linux backdoor leveraging residential proxies and NHAS reverse SSH
A recently discovered Linux backdoor (SHA256: ea41b2bf1064efcb6196bb79b40c5158fc339a36a3d3ddee68c822d797895b4e) employs advanced evasion techniques to bypass detection while establishing persistent access via SOCKS5 proxies and in-memory payload execution. This analysis breaks...
US indicts Black Kingdom ransomware operator: technical analysis of ProxyLogon exploitation and law enforcement response
The U.S. Department of Justice unsealed charges against Yemeni national Rami Khaled Ahmed (36) for deploying Black Kingdom ransomware via ProxyLogon exploits (CVE-2021-26855) against 1,500+ systems, including U.S....
Hijacking Trust: how Gmail and Google APIs are being weaponized for stealthy C2 channels
In the ever-evolving landscape of cybersecurity, attackers are increasingly exploiting trusted services to establish covert command-and-control (C2) channels. By leveraging platforms like Gmail and Google Drive, threat actors...
Kintetsu World Express ransomware attack: technical overview and response
Kintetsu World Express (KWE), a major Japanese global logistics provider, has confirmed a significant ransomware attack that began impacting its operations in late April 2025. The incident has...
JFL Hospital targeted in ransomware attack amid wave of cyber incidents in US Virgin Islands
Governor Juan F. Luis Hospital & Medical Center (JFL) in the US Virgin Islands has become the latest government entity to suffer a cybersecurity breach, confirming a ransomware...