credential theft

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
A sophisticated threat actor known as Storm-2945, a sub-cluster of Midnight Blizzard, is targeting travelers worldwide through captive portal networks. The group manipulates network traffic to deliver malware, including a Go-based RAT called CornFlake, and conducts phishing attacks to steal credentials and register devices with Microsoft Entra ID. This campaign, dubbed CaptiveCrunch, leverages AI and mimics legitimate system updates to trick victims into downloading malicious software.

North Korean hackers use fake coding interviews to steal developer credentials
Elastic Security Labs has identified a new campaign by North Korean threat actors, dubbed 'Contagious Interview,' targeting software developers. The attackers use fake job postings and coding challenges, embedding malware within SVG files using steganography. Successful execution of these projects leads to the deployment of a multi-stage payload designed to steal credentials, cryptocurrency, and provide remote access.

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches
Several organizations experienced significant security incidents this week. The Texas Parks and Wildlife Department suffered a data breach affecting over 3 million customers due to a vendor compromise, exposing personal information but not financial or social security data. Additionally, a supply chain attack on WordPress plugin vendor ShapedPlugin delivered malicious updates, leading to credential theft and website modifications. AI-powered threats are also on the rise, with a new phishing service called EvilTokens exploiting device-code authentication to steal Microsoft 365 tokens.

Cybercriminals Are Targeting the FIFA World Cup 2026
Cybercriminals are leveraging the upcoming FIFA World Cup 2026 to conduct various malicious activities. These attacks include phishing campaigns, the distribution of fake tickets, malware deployment, impersonation tactics, and attempts to steal user credentials.

Cloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts
A new credential theft framework dubbed PCPJack has been identified, capable of spreading across exposed cloud infrastructure. The tool not only harvests sensitive data from various cloud services but also actively removes artifacts associated with the threat actor group TeamPCP. PCPJack targets services like Docker, Kubernetes, and MongoDB, exfiltrating stolen information and seeking to infect additional systems.