threat actor

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A new threat actor, operating under the name "Ransom Busters," is contacting ransomware victims directly, claiming to have infiltrated ransomware groups' servers and offering to delete stolen data for a fee between $20,000 and $60,000. Security researchers believe this is likely a ransomware affiliate attempting to extort victims further, rather than a legitimate recovery service, and warn that payments offer no guarantee of data deletion.

Cavern C2 Framework Evolves With DNS and Google Apps Script
Researchers have identified new components in the Cavern command-and-control framework, which is being used by Iranian nation-state actors. The framework now leverages DNS and Google Apps Script to disguise its malicious traffic as legitimate activity. This evolution aims to enhance its stealth capabilities in ongoing attacks targeting entities in Israel.

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Researchers have linked the threat actor known as TeamPCP to cybercriminal activities dating back to 2020, predating their known supply chain attacks. The group has a history of exploiting vulnerabilities in internet-facing infrastructure, including Redis servers and AI platforms, for various malicious purposes like cryptocurrency mining and botnet creation. Their operations have evolved to include sophisticated supply chain compromises, weaponizing open-source libraries and leveraging cloud infrastructure for widespread attacks.

Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese threat actor has been observed using AI, specifically DeepSeek's Hermes Agent, to automate and scale their cyberattacks. The actor combined AI-driven reconnaissance and vulnerability exploitation with manual techniques, targeting internet-exposed infrastructure in Asia. While the observed campaign had limited impact, it demonstrates a growing trend of AI-augmented offensive capabilities becoming more accessible and effective.

Fake 7-Zip Installers Hijack Devices for Proxy Network
A threat group known as Lurking Lizard has established a large-scale residential proxy network using over 230 fake domains. This operation, active since at least August 2022, leverages compromised devices, including those infected via fake 7-Zip installers, to route traffic for malicious purposes.

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese threat actor, UAT-7810, is reportedly enhancing its custom malware to broaden its Operational Relay Box (ORB) network. This expansion involves compromising internet-facing networking devices, according to Cisco Talos.

UAT-7810 continues building ORB networks using new malware
The threat actor UAT-7810 is reportedly developing new custom malware. This malware is being utilized to establish ORB networks, indicating an evolution in their tools and ongoing malicious operations.

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
A new phishing campaign has been identified, attributed to a previously unknown APT group named Armored Likho. This group targets government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. They employ a diverse toolkit, including a new Python-based infostealer called BusySnake Stealer, and utilize AI-generated payloads to evade detection and complicate attribution.

Gamaredon Group Evolves Tactics With New Tools and Alliances
ESET Research has identified new tactics employed by the Gamaredon group, including the use of tunnels, dead drops, and worker processes. The threat actor is increasingly leveraging legitimate online services to conceal its command-and-control infrastructure and to exfiltrate stolen data.

Cloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts
A new credential theft framework dubbed PCPJack has been identified, capable of spreading across exposed cloud infrastructure. The tool not only harvests sensitive data from various cloud services but also actively removes artifacts associated with the threat actor group TeamPCP. PCPJack targets services like Docker, Kubernetes, and MongoDB, exfiltrating stolen information and seeking to infect additional systems.