Tag Cybercrime

Scattered Spider Compromises VMware ESXi to Launch Ransomware Against Critical U.S. Infrastructure

July 28, 2025
Cyber Attack / Ransomware

The infamous cybercrime group Scattered Spider is targeting VMware ESXi hypervisors in a series of attacks against the retail, airline, and transportation sectors in North America. According to an in-depth analysis by Google’s Mandiant team, “The group’s core tactics remain unchanged and do not depend on software exploits. Instead, they employ a strategic playbook that primarily involves phone calls to IT help desks.” The actors are described as aggressive and innovative, particularly adept at using social engineering to bypass even robust security systems. Their operations are precision-driven campaigns focused on the most critical systems and data of their victims. Also known as 0ktapus, Muddled Libra, Octo Tempest, and UNC3944, these threat actors have a track record of executing sophisticated social engineering tactics to gain initial access to target environments, subsequently employing a “living-off-the-land” (LotL) strategy by leveraging trusted administrative tools.

Scattered Spider Breaches VMware ESXi to Launch Ransomware Attacks on Critical U.S. Infrastructure July 28, 2025 In a concerning escalation of cyber threats, the cybercriminal group known as Scattered Spider has been orchestrating targeted attacks on VMware ESXi hypervisors, primarily affecting sectors such as retail, airlines, and transportation across North…

Read More

Scattered Spider Compromises VMware ESXi to Launch Ransomware Against Critical U.S. Infrastructure

July 28, 2025
Cyber Attack / Ransomware

The infamous cybercrime group Scattered Spider is targeting VMware ESXi hypervisors in a series of attacks against the retail, airline, and transportation sectors in North America. According to an in-depth analysis by Google’s Mandiant team, “The group’s core tactics remain unchanged and do not depend on software exploits. Instead, they employ a strategic playbook that primarily involves phone calls to IT help desks.” The actors are described as aggressive and innovative, particularly adept at using social engineering to bypass even robust security systems. Their operations are precision-driven campaigns focused on the most critical systems and data of their victims. Also known as 0ktapus, Muddled Libra, Octo Tempest, and UNC3944, these threat actors have a track record of executing sophisticated social engineering tactics to gain initial access to target environments, subsequently employing a “living-off-the-land” (LotL) strategy by leveraging trusted administrative tools.

Rising Threats: Ransomware Victims, Data Breaches, and Info Stealers

Surge in Cybercrime: Alarming Trends in Ransomware and Infostealer Attacks Recent research highlights a significant escalation in cybercrime activity throughout 2025, characterized by substantial increases across various types of threats. Notably, there has been a staggering 800% rise in credential theft attributed to information-stealing malware, defining identity theft as a…

Read MoreRising Threats: Ransomware Victims, Data Breaches, and Info Stealers

Google and Cisco Report CRM Software Breaches Caused by Vishing Attacks

Cybercrime, Fraud Management & Cybercrime Voice Phishing Attacks Target Salesforce Users: A Persistent ShinyHunters Strategy Mathew J. Schwartz (euroinfosec) • August 6, 2025 Be cautious of voice phishing calls from the ShinyHunters cybercrime group. (Image: Shutterstock) In an alarming trend, technology giants Google and Cisco disclosed separate incidents of data…

Read MoreGoogle and Cisco Report CRM Software Breaches Caused by Vishing Attacks

Surge in Chaos Ransomware Linked to BlackSuit Group Departure

Fraud Management & Cybercrime, Ransomware Operation Checkmate Disrupts Major Russian-Speaking Ransomware Group Mathew J. Schwartz (euroinfosec) • July 28, 2025 The BlackSuit dark web leak site as of July 24, 2025. In a significant international effort, Operation Checkmate has dismantled BlackSuit, a ransomware group responsible for leveraging ransom demands that…

Read MoreSurge in Chaos Ransomware Linked to BlackSuit Group Departure

China-Supported Hackers Ramp Up Attacks on Taiwan’s Chip Manufacturing Sector

Anti-Phishing, DMARC, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime State-Sponsored Groups Target Semiconductor Sector with Spear-Phishing Attacks Prajeet Nair (@prajeetspeaks) • July 17, 2025 Chinese state-aligned hackers have escalated their espionage tactics against Taiwan’s semiconductor ecosystem through concentrated spear-phishing efforts. (Image: Shutterstock) Chinese state-aligned hackers are intensifying their espionage…

Read MoreChina-Supported Hackers Ramp Up Attacks on Taiwan’s Chip Manufacturing Sector

Hackers Exploit Backdoor to Access Data from SonicWall Appliance

Cybercrime, Fraud Management & Cybercrime, Governance & Risk Management Hacking Group UNC6148 Exploits OVERSTEP Rootkit to Steal Credentials, According to Google Akshaya Asokan (asokan_akshaya) • July 16, 2025 A cybercrime group leveraged a backdoor in a fully patched SonicWall appliance to exfiltrate credentials and may have sold this information to…

Read MoreHackers Exploit Backdoor to Access Data from SonicWall Appliance