Tag Cobalt Strike

APT Hackers Exploit Industrial Control Systems Using ShadowPad Backdoor

Recent reports have surfaced detailing a targeted cyberattack campaign aimed at unpatched Microsoft Exchange Servers, utilizing these vulnerabilities as a foothold to deploy the sophisticated ShadowPad malware. Key targets include entities in Afghanistan, Malaysia, and Pakistan, particularly focusing on organizations within the telecommunications, manufacturing, and transportation sectors. The activity was…

Read MoreAPT Hackers Exploit Industrial Control Systems Using ShadowPad Backdoor

Cisco Acknowledges Breach by Yanluowang Ransomware Group

Cisco Confirms Cyberattack Linked to Yanluowang Ransomware Gang On May 24, 2022, Cisco Systems, a leading networking equipment provider, confirmed it fell victim to a cyberattack that exploited vulnerabilities in its digital infrastructure. The breach occurred after an attacker compromised a Cisco employee’s personal Google account, which contained synchronized passwords…

Read MoreCisco Acknowledges Breach by Yanluowang Ransomware Group

Infrastructure Utilized in Cisco Hack Also Aimed at Workforce Management Solutions

In early 2022, an attack infrastructure targeting Cisco was also utilized in an attempted breach of an unnamed workforce management solutions holding company. This attempted intrusion occurred just one month prior to the Cisco incident, highlighting a strategy employed by cybercriminals to exploit vulnerabilities in various sectors. According to cybersecurity…

Read MoreInfrastructure Utilized in Cisco Hack Also Aimed at Workforce Management Solutions

Conti Group Members Launch Financially Driven Attacks on Ukraine

Recent investigations have uncovered the involvement of former Conti cybercrime group members in multiple campaigns targeting Ukraine from April through August 2022. According to Google’s Threat Analysis Group (TAG), these cyber operations reflect a strategic continuation of prior attacks against the Eastern European nation amidst the ongoing Russo-Ukrainian conflict. The…

Read MoreConti Group Members Launch Financially Driven Attacks on Ukraine

Chinese ‘Mustang Panda’ Hackers Are Actively Targeting Governments Globally

A sophisticated threat actor known as Mustang Panda has been implicated in a wave of spear-phishing attacks directed at key sectors including government, education, and research from May to October 2022. According to a recent report by cybersecurity firm Trend Micro, the targeted regions include countries in the Asia Pacific,…

Read MoreChinese ‘Mustang Panda’ Hackers Are Actively Targeting Governments Globally

IcedID Malware Targets Again: Active Directory Domain Breached in Less Than 24 Hours

Malware Attack Utilizing IcedID Compromises Active Directory Domain A recent incident involving IcedID malware has raised significant alarms within the cybersecurity community, highlighting the persistent threat posed by sophisticated attacks. Within just 24 hours of gaining initial access, the threat actor successfully compromised the Active Directory domain of an unidentified…

Read MoreIcedID Malware Targets Again: Active Directory Domain Breached in Less Than 24 Hours

Exploitation of PHP-CGI RCE Vulnerability Targets Japan’s Technology, Telecommunications, and E-Commerce Industries

In a disturbing development for cybersecurity, a campaign attributed to unidentified threat actors has emerged, focusing primarily on organizations in Japan since January 2025. This malicious initiative exploits a vulnerability known as CVE-2024-4577, a remote code execution (RCE) flaw in the PHP-CGI implementation on Windows systems, as reported by Cisco…

Read MoreExploitation of PHP-CGI RCE Vulnerability Targets Japan’s Technology, Telecommunications, and E-Commerce Industries

⚡ THN Weekly Recap: Fresh Assaults, Timeless Tactics, Greater Consequences

In an era where cyber threats are not merely evolving but rapidly mutating, the cybersecurity landscape continues to challenge defenses across various sectors, from global financial frameworks to vital infrastructure. With the advent of sophisticated cybercrime, ranging from state-sponsored espionage to ransomware attacks leveraging artificial intelligence, pressing questions arise about…

Read More⚡ THN Weekly Recap: Fresh Assaults, Timeless Tactics, Greater Consequences

New Report Uncovers NikoWiper Malware Targeting Ukraine’s Energy Sector

In a significant development in cybersecurity, the Russian-affiliated group known as Sandworm has deployed a new variant of wiper malware called NikoWiper in an attack against a Ukrainian energy sector company in October 2022. This incident underscores the ongoing cyber threats linked to geopolitical tensions in the region. ESET, a…

Read MoreNew Report Uncovers NikoWiper Malware Targeting Ukraine’s Energy Sector