June 16, 2025

Anubis Ransomware Now Wipes Files Beyond Recovery

A new, far more destructive chapter has begun for the Anubis ransomware operation. Previously known for encrypting data and extorting victims, the cybercriminals behind Anubis have now introduced a wiper feature. One that makes data recovery virtually impossible, even if the ransom is paid. This strategic shift marks a dangerous evolution in the ransomware-as-a-service (RaaS) ecosystem and signals a chilling

Anubis Ransomware
June 14, 2025

Predator Spyware Bounces Back and Finds New Market

When U.S. and EU sanctions hit Intellexa, the company behind the Predator spyware platform, many observers predicted the mercenary‑surveillance market would retreat. Instead, freshly released telemetry from Recorded Future’s Insikt Group shows Predator morphing rather than melting away. Their latest report maps brand‑new command‑and‑control (C2) servers in Mozambique, the first public evidence of a customer there,  plus infrastructure tied to

predator spyware
June 12, 2025

DNS Security: Your First Line of Defense in 2025

Every connection to your website begins with a simple question: “Where do I find this domain?” That question is answered by the Domain Name System (DNS), a decades‑old protocol that was never designed to fend off modern attackers. If an adversary can tamper with (or completely overwhelm) your DNS, they can redirect visitors, steal data, or knock your brand offline

DNS Security
June 11, 2025

Operation Secure by Interpol Seizes Malicious 20,000 IPs

From January to April 2025, INTERPOL coordinated “Operation Secure,” a concerted strike on the technical backbone that fuels the global trade in stolen credentials. Working with cyber‑crime units from 26 Asia‑Pacific countries and telemetry from Group‑IB, Kaspersky and Trend Micro, investigators mapped more than 20,000 IP addresses and domains that funnelled loot from 69 different infostealer strains. By April’s end,

Operation Secure
June 10, 2025

Crypto Phishing Campaign Adds Fake Wallet Apps on Google Play

A new cyber threat is making waves in the crypto world. This time, it’s coming straight from the Google Play Store. Security researchers have uncovered a crypto phishing campaign involving dozens of fake crypto wallet apps that are targeting unsuspecting users. These lookalike apps mimic real crypto platforms and trick users into handing over their 12-word recovery phrases, giving attackers

New Crypto Phishing Campaign
June 9, 2025

BADBOX 2.0: How Your TV Could Be a Botnet Node

Imagine buying a brand-new smart TV or streaming box, still sealed in its packaging. Only to find out later that it was already compromised by hackers before it ever reached your hands. That’s the chilling reality behind BADBOX 2.0, a global botnet campaign that has turned over a million consumer devices into unwitting cyber weapons. The FBI is sounding the

badbox 2.0
June 7, 2025

ViLE Members Sentenced for Breaching DEA Portal and Doxxing

In a chilling reminder of how digital tools can be weaponized for harassment and extortion, two members of the cybercrime group "ViLE" have been sentenced to federal prison after breaching a U.S. law enforcement portal and using stolen data to terrorize victims. Sagar Steven Singh, a 21-year-old from Rhode Island who operated under the alias “Weep,” and Nicholas Ceraolo, a

ViLE members sentenced
June 6, 2025

Play Ransomware Breaches 900 Victims Worldwide, FBI Confirms

The FBI, Cybersecurity and Infrastructure Security Agency (CISA), and Australian Cyber Security Centre (ACSC) have issued a joint advisory revealing that the Play ransomware group (also known as Playcrypt) has compromised over 900 organizations globally as of May 2025. This marks a sharp increase from the 300 known victims in October 2023, underscoring the escalating threat posed by the group.

Play Ransomware
June 5, 2025

Chaos RAT Malware Targets Windows and Linux

.ProvideA new wave of cyberattacks is leveraging an evolved version of Chaos RAT malware, an open-source remote access trojan that now poses a significant threat to both Windows and Linux systems. By disguising itself as a legitimate network utility, this malware is quietly infiltrating machines and granting attackers extensive control over compromised devices. What Is Chaos RAT Malware? Chaos RAT

Chaos RAT Malware
June 4, 2025

Conti, Trickbot Ransomware Leader Exposed by German Police

In a landmark development in the global fight against cybercrime, Germany’s Federal Criminal Police Office (Bundeskriminalamt, or BKA) has publicly identified the elusive leader of the notorious Trickbot and Conti ransomware groups. The man behind the alias "Stern" has been unmasked as 36-year-old Russian national Vitaly Nikolaevich Kovalev. This marks a critical breakthrough in international law enforcement efforts against organized

Conti Trickbot Ransomware Leader Exposed