NVIDIA fixed critical Triton Inference Server vulnerabilities. Patch your Triton Inference Server vulnerabilities now to stop denial of service attacks.
Related Posts:
OnePlus Session Takeover Vulnerability Exposes Android Data
Apache Artemis Vulnerabilities Demand Immediate Action
Arista Patches Critical Arista EOS Vulnerabilities
The post NVIDIA Patches Triton Inference Server Vulnerabilities appeared first on Daily CyberSecurity.
NVIDIA fixed critical Triton Inference Server vulnerabilities. Patch your Triton Inference Server vulnerabilities now to stop denial of service attacks.
MongoDB fixed 24 MongoDB Server vulnerabilities, including a critical auth bypass (CVE-2026-82067) and unauthenticated denial of service flaws. Patch now.
Related Posts:
OnePlus Session Takeover Vulnerability Exposes Android Data
NVIDIA Patches Triton Inference Server Vulnerabilities
Apache Artemis Vulnerabilities Demand Immediate Action
The post MongoDB Patches 24 Server Vulnerabilities, One Critical appeared first on Daily CyberSecurity.
MongoDB fixed 24 MongoDB Server vulnerabilities, including a critical auth bypass (CVE-2026-82067) and unauthenticated denial of service flaws. Patch now.
The Outsider Phishing Kit persists despite the Operation Ghost Hook takedown. Discover how the ChenLun Outsider PhaaS kit bypasses MFA via AiTM attacks.
Related Posts:
Phantom Deal Scam Targets Executives With Fake NDAs
Microsoft Teams IT Support Impersonation Leads to Domain Takeover
Chinese Actor Gambling Goblin Hijacks Brazilian Gov Sites
The post Outsider Phishing Kit Survives Operation Ghost Hook Takedown appeared first on Daily CyberSecurity.
The Outsider Phishing Kit persists despite the Operation Ghost Hook takedown. Discover how the ChenLun Outsider PhaaS kit bypasses MFA via AiTM attacks.
The Gentlemen ransomware, run by GOLD SHERWOOD, encrypts networks in under 24 hours. See the affiliate playbook and how to defend against it.
Related Posts:
PHP Web Server Rootkit Targets F5 BIG-IP Devices
StreamRat Banking Trojan Targets Spanish Android Users
Silver Fox Fake Software Installers Disable Windows Defender
The post The Gentlemen Ransomware Deploys in Under 24 Hours appeared first on Daily CyberSecurity.
A public announcement exists for the Cisco Secure Email vulnerability pair in S/MIME decryption, plus a Cisco phone SIP denial-of-service flaw.
Related Posts:
CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE
Apache Allura Security Vulnerabilities Patched in v1.21.0
CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation
The post Cisco Secure Email S/MIME Flaws Publicly Disclosed appeared first on Daily CyberSecurity.
AnonyMousKIT is an AI-powered PhaaS platform that phones iPhone theft victims as fake Apple Support to steal passcodes and beat Activation Lock.
Related Posts:
Dark Caracal Deploys New GoCaracal Malware Framework
Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT
BREEZE COMET Threat Actor Attacks Brazilian Banks
The post AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones appeared first on Daily CyberSecurity.
WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns.
Related Posts:
SynkLoader Malware Deploys Multi-Language Attack Tools
macOS ClickFix Malware Exploits Polygon C2
Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR
The post WeedHack Malware Still Hits Minecraft Gamers via Fake Sites appeared first on Daily CyberSecurity.
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
Related Posts:
GitLab Updates Fix Arbitrary Command Execution Vulnerability
FreeBSD Patches Eight Kernel Vulnerabilities
UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products
The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.
According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity
The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.
According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.
The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.
How Sexual Exploitation Actors Access Accounts
The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.
Password and PIN Targeting
In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.
When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.
Social Media Customer Service Impersonation
Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.
The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.
Phishing Emails
The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.
These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.
Stolen Content Can Lead to Further Attacks
Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.
The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.
FBI Shares Steps to Protect Accounts
The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.
It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.
Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.
Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.
People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.
Cloudflare says 805 DDoS attacks topped 1 Tbps in Q2 2026 as high-bandwidth attacks surged, raising new concerns for network defenses.
The post Cloudflare Report Shows Massive Spike in High-Volume DDoS Attacks: Here Is What the Data Shows appeared first on TechRepublic.
U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network.
The post US, South Korea Warn of Growing Gunra Ransomware Threat appeared first on TechRepublic.
Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met.
The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant d
Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met.
The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.
Gunra Ransomware Shifts to Affiliate Model
By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on dark web forums.
The program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers.
Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting.
Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific.
Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services.
VPN Vulnerabilities Used for Initial Access
According to the advisory, Gunra actors primarily gained initial access by exploiting known vulnerabilities in internet-facing devices, including firewall and VPN gateways. The FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions.
The Republic of Korea’s National Police Agency also observed Gunra actors exploiting credential exposure and SSH access control weaknesses in internet-facing VPN gateways to obtain unauthorized remote access.
After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.
Data Theft Precedes Encryption
The double-extortion ransomware operation involves stealing sensitive information before encrypting systems. The FBI observed Gunra actors collecting business-critical documents, databases, personally identifiable information, and internal email communications.
In at least one case, the actors used a malicious executable called main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes.
For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the .ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.
Agencies Urge Patching and Network Segmentation
The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. They also advise implementing and testing offline, immutable backups stored in physically separate and segmented locations.
Network segmentation is another key recommendation, intended to restrict lateral movement and limit the spread of ransomware between systems.
The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework.
The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic.
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns.
Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal groups.
A crypter’s job is simple to describe and hard to build well: scramble a
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns.
Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal groups.
A crypter’s job is simple to describe and hard to build well: scramble a malicious payload so antivirus tools can’t detect it, then unwrap it at just the right moment on the victim’s machine. Cruciferra does that job with a level of polish researchers don’t see often. It’s written in Mono and packs in indirect system calls, API unhooking, and a custom flavor of Process Ghosting designed to leave almost nothing behind for a forensic investigator to find.
“Cruciferra is written in Mono and features numerous techniques designed to evade detection, analysis, and incident response efforts. These include using indirect system calls, API and Import Address Table (IAT) unhooking, Bring-Your-Own-Vulnerable-Driver (BYOVD)-based EDR tampering, privilege escalation, persistence mechanisms, and a customized implementation of Process Ghosting used to execute payloads while minimizing forensic artifacts.” reads the report. “The crypter also includes a notable emphasis on payload protection. Cruciferra supports a large collection of custom encryption routines, many of which appear to be dynamically assembled from components of established cryptographic algorithms. This approach creates significant variation between samples, complicating static analysis and signature-based defenses. “
The pricing alone tells you this is a serious commercial operation, not a hobbyist’s side project. Sellers have advertised it on underground forums since fall 2025 for between $450 and $2,000 a month, marketed bluntly as one of the most effective crypters available. That price bought access to protection for a long list of commodity malware, including Agent Tesla, AsyncRAT, Remcos RAT, Snake Keylogger, XWorm, and several others.
What makes Cruciferra genuinely hard to fingerprint is that it doesn’t use one fixed encryption method. Each batch of samples gets its own encryption routine, built by mixing and matching pieces from well-known hashing, random number generation, and cipher algorithms, which means two Cruciferra samples can look completely unrelated at the code level. Researchers suspect this variation gets generated automatically rather than handpicked by a human, since the sheer number of combinations would be tedious to produce by hand.
One campaign traced to Cruciferra belongs to TA4922, a Chinese-speaking group with some overlap with another well-known operation called Silver Fox. TA4922 sent victims to fake landing pages hosting ZIP files disguised as tax documents, with four separate waves identified between April and early June 2026.
Cruciferra shows up in other unrelated campaigns too, which is really the point. One wave impersonated the US Social Security Administration to deliver XWorm and AdaptixC2 back in May, while another used complaints about bed bugs to target hotels and travel companies with zgRAT malware in late June. Different lures, different final payloads, same wrapper doing the hiding.
“Tax and government-related themes are frequent favorites of cybercriminals, and the U.S. Social Security Administration (SSA) is often abused in malware campaigns, including from actors using Cruciferra.” continues the report. “For example, in May, Proofpoint researchers observed emails impersonating the SSA regarding tax documents. (Curiously, the emails referred to items that needed to be completed by January 2026; it’s possible the actor repurposed an old lure, or mistakenly included the wrong date.)”
However it gets deployed, Cruciferra always loads through DLL side-loading and leans on the same set of evasion tricks. It hides its console window, strips visibility from Windows API calls, and abuses a vulnerable driver called GoFlyDrv.sys to kill off security processes running on the machine, a technique known in the industry as bring-your-own-vulnerable-driver. If it isn’t already running with administrator rights, it quietly bypasses Windows’ UAC prompt using a known COM elevation trick, then plants itself in the registry’s Run key under the unassuming name “putty” so it survives a reboot.
The final payload never actually touches disk as a real file. Cruciferra uses a variant of Process Ghosting, running code from a temporary file that gets deleted before the process even starts, which leaves security software with nothing to scan because there’s technically no file there.
“Process Ghosting is when malware creates a temporary file, marks it for pending deletion via NtSetInformationFile, writes the malicious payload into it, then creates an image section (NtCreateSection with SEC_IMAGE) from that file. Once the file handle is closed, the operating system deletes the file from disk while the section persists in memory.” states the report.”A legitimate process is then created in a suspended state, the ghost section is mapped into it via NtMapViewOfSection, the thread context is redirected to the payload’s entry point, and the thread is resumed. The result is a running process backed by a PE image that never existed on disk in a scannable state.”
On top of that, it patches memory-query hooks and tries to interfere with a Windows routine that manages hot patches, covering its own tracks and disabling integrity checks along the way.
None of the individual tricks here are brand new on their own. What stands out is how many of them Cruciferra stacks together in one modular package, built to protect whatever malware a customer wants to hide that week. Calling something “the most lethal crypter” in a forum ad is usually just sales talk, but this is one of the rare cases where the product notes actually undersell it.
“While crypters have long been used to evade detection and increase malware delivery and execution success rates, Cruciferra distinguishes itself through its extensive and unique defense-evasion capabilities, modular design, and highly customized and varied approach to payload protection.” concludes the report. “During our investigations, we observed Cruciferra delivering numerous malware families, including various remote access trojans and infostealers, highlighting its role as an enabling technology within the cybercrime ecosystem. Proofpoint will continue to monitor the development and adoption of Cruciferra and provide updates as new capabilities and campaigns are identified. “
In this episode of the podcast, host Paul Roberts interviews Nishawn Smagh of the firm GreyNoise Intelligence about the findings of their State of the Edge report, an analysis of GreyNoise data on risks stemming from compromised edge devices such as broadband routers, VPN gateways, smart home devices and more. Shawn and Paul talk about how attackers are turning edge devices into their favorite entry point, and strategies for organizations to counter the growing risk of compromised edge devices.
In this episode of the podcast, host Paul Roberts interviews Nishawn Smagh of the firm GreyNoise Intelligence about the findings of their State of the Edge report, an analysis of GreyNoise data on risks stemming from compromised edge devices such as broadband routers, VPN gateways, smart home devices and more. Shawn and Paul talk about how attackers are turning edge devices into their favorite entry point, and strategies for organizations to counter the growing risk of compromised edge devices.
New Jalisco and OmegaLord phishing kits target Microsoft 365 accounts by abusing device code flows, OAuth tokens, and MFA prompts to maintain access.
The post Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts appeared first on TechRepublic.
The Nihon Kotsu cyberattack has disrupted operations at Japan's largest taxi operator after the company confirmed that its internal systems were compromised by a malware-related security incident. The cyberattack on Nihon Kotsu forced the company to shut down parts of its IT infrastructure, leaving key Japan taxi service operations, including its taxi dispatch system, unavailable.
According to the company, the incident occurred early on Saturday, July 11, 2026. After detecting unauthorized a
The Nihon Kotsu cyberattack has disrupted operations at Japan's largest taxi operator after the company confirmed that its internal systems were compromised by a malware-related security incident. The cyberattack on Nihon Kotsu forced the company to shut down parts of its IT infrastructure, leaving key Japan taxi service operations, including its taxi dispatch system, unavailable.According to the company, the incident occurred early on Saturday, July 11, 2026. After detecting unauthorized access, Nihon Kotsu immediately shut down affected systems to contain the attack and prevent additional damage. The taxi dispatch service operated via telephone, the hire car web ordering and reservation management system, and several internal systems remain temporarily offline.
Nihon Kotsu Shuts Down Systems
Nihon Kotsu, Japan's largest taxi and chauffeur operator by group revenue, generates approximately ¥155 billion (around $1 billion) annually. The company employs 18,228 people and operates a fleet of 8,558 taxis alongside more than 2,000 chauffeur vehicles, making the disruption significant for the country's Japan taxi service sector.In a statement, the company said, "We have confirmed that our internal systems were subjected to unauthorized external access (malware infection)." It also apologized for the incident, stating, "We sincerely apologize for the great inconvenience and concern this has caused to our customers, business partners, and all other parties involved."
Japan Taxi Service Affected as Dispatch Operations Remain Offline
The company explained that emergency measures were implemented immediately after the breach was detected. "Upon detecting the unauthorized access, we immediately took emergency measures, including shutting down systems, to prevent further damage," the statement said. It added that the disruption has affected web-based hire car reservations, telephone taxi dispatch services, and certain internal systems.As the cyberattack on Nihon Kotsu continues to be investigated, customers requiring taxis have been advised to use the GO taxi application, nearby taxi stands, or hail a cab directly from the street. Users of the GO app can still request a Nihon Kotsu vehicle by selecting the company within the application.The company said it is working with external cybersecurity specialists to determine the cause of the incident, analyze system logs, and assess the overall impact. According to the statement, the internal network has been isolated, and "further spread of the damage has been contained."
Investigation into the Nihon Kotsu Cyberattack Continues
Investigators are also examining whether any personal or corporate data was exposed during the Nihon Kotsu cyberattack. The company stated that no information leak has been confirmed at this stage. However, it noted that a detailed investigation is ongoing with specialized agencies to determine whether any data was compromised. If customer or partner information is found to have been exposed, Nihon Kotsu said it will make a public announcement and individually notify affected parties in accordance with applicable laws.The company said restoring systems securely remains its highest priority. It also pledged to provide updates on both the investigation and recovery process as more information becomes available. In the meantime, Nihon Kotsu urged customers to remain cautious of fraudulent emails or messages claiming to originate from the company and advised them not to open suspicious attachments or click unknown links.
The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.
According to statements releas
The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.
According to statements released by the EU and UK on Monday, the FSB's Center 16 was responsible for attempted cyber sabotage against Poland's heating and power infrastructure, as well as cyber intrusions targeting water treatment facilities. The allies also accused the agency of conducting broader cyber operations against governments and critical infrastructure across Europe.
Russia Cyberattack Linked to FSB's Center 16 Operations
The European Union said Center 16, the signals intelligence arm of the FSB, has conducted malicious cyber activities affecting multiple member states and international partners. According to the bloc, these operations have included infiltration of government networks, cyber espionage, and sabotage targeting critical infrastructure in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.
The EU also stated that Center 16 controls several cyber threat groups, including TURLA, and has been involved in cyber operations against strategic government entities in France since 2010 and the country's defense industry in 2025. In Germany, it allegedly targeted government institutions, while in Poland it carried out disruptive operations against combined heating and power plants.
British authorities described last December's attempted attack on Poland's energy grid as "reckless," saying it was another example of Russia's attempts to create disruption across Europe.
However, Poland's national cybersecurity agency, CERT Polska, later disputed that assessment after tracing the attack infrastructure and connecting it to a cluster associated with the FSB.
Separately, Poland's domestic intelligence service warned in May that cyber intrusions targeting the country's water treatment facilities posed a direct risk to the continuity of water supply.
EU and UK Expand Cyber Sanctions
In response, the European Union imposed restrictive measures on nine individuals and four entities linked to Russia's cyber ecosystem. The sanctions target intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies accused of supporting or facilitating malicious cyber operations.
The wider sanctions package announced by European partners targets more than 30 individuals and organizations, including operators behind the Lumma Stealer malware, companies accused of recruiting hackers from Russian universities, and individuals associated with the pro-Kremlin Rybar military blog.
EU foreign policy chief Kaja Kallas said Russia continues to rely on intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious cyber operations against Europe and its partners.
She added that the bloc strongly condemns the misuse of this cyber ecosystem, which has targeted public services and critical infrastructure, resulting in operational disruptions and financial losses.
France Details FSB Activities
France also announced additional sanctions and said it would summon the Russian ambassador over what it described as persistent malicious cyber activities conducted for espionage purposes.
A technical report from France's Cyber Crisis Coordination Center (C4) identified 11 interception centers operated by Center 16 across Russia, including Unit 61240, which it said specifically focused on France.
French authorities alleged that the unit targeted government ministry systems in 2014, compromised the French Embassy network in Moscow in 2018, and stole significant volumes of data from a research institute working with the French defense industry in February 2025.
France also stated that one newly sanctioned group had claimed responsibility for destabilization efforts targeting the 2024 Paris Olympic and Paralympic Games.
Allied Advisory Warns of Ongoing Threats
Alongside the sanctions, the United States and intelligence agencies from a dozen allied countries published a joint cybersecurity advisory warning that Russian operators linked to Center 16 have been scanning internet-connected devices protected by weak or default credentials.
The United Kingdom separately sanctioned individuals connected to Lumma Stealer, describing it as one of the world's most widely used information-stealing malware families. British officials said credentials stolen through the malware have been used to support Russian espionage operations globally. According to the UK's National Crime Agency, more than 2,100 victims in the country were infected by Lumma Stealer during the past six months.
British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services, while emphasizing that the coordinated measures send a clear message against the use of proxy cyber groups.
The Kremlin has repeatedly denied conducting offensive cyber operations. Russian President Vladimir Putin has dismissed European allegations of sabotage and cyberattacks as baseless, saying they are intended to justify aggressive policies against Russia.
RedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription
Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent roots in the Oblivion malware family.
It comes with documentation, tutorial videos, a referral discount program, and a bot that builds custom malicious apps on demand. No malware-writing skill required.
“Far from being
RedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription
Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent roots in the Oblivion malware family.
It comes with documentation, tutorial videos, a referral discount program, and a bot that builds custom malicious apps on demand. No malware-writing skill required.
“Far from being just another basic piece of malware sold online, RedWing is a fully developed, commercial-grade MaaS product with seller documentation, videos, and a bot-driven subscription model that provides a low entry barrier for novice attackers.” reads the report published by Zimperium. “As a proof of this, the APK customization/obfuscation/creation can be fully implemented through telegram.”
Infection starts with a phishing link that opens a fake app store page. The dropper builder can mimic Google Play, the Samsung Galaxy Store, or Huawei’s AppGallery with fake ratings, reviews, and download counts.
“the C2 panel features a sophisticated ‘Onboarding Constructor‘. Within the ‘Stealer’ configuration module, operators can deploy a deceptive ‘WebView + Cards’ interface. This mechanism loads a benign-looking webpage in the background to establish legitimacy, while sequentially overlaying customized permission prompts (cards) from the bottom of the screen.” continues the report. “Through tailored social engineering lures, the malware coerces the user into granting critical system access, specifically targeting three core permissions: disabling Battery Optimization (to ensure uninterrupted background execution), setting the application as the Default SMS handler (crucial for intercepting 2FA codes), and access to Notifications.”
Once installed, the app walks the victim through permission screens one at a time, disable battery optimization, set the app as the default SMS handler, enable notifications, framed as routine setup steps.
With those permissions in place, RedWing has deep system access. It deploys fake login screens over real banking and crypto apps to steal credentials, reads incoming texts to capture one-time codes, and uses Android’s Accessibility Service to lift PINs, card numbers, and CVV values directly off the screen as they appear.
The malicious code also silently enables call forwarding using a hidden carrier code, 21, redirecting all incoming calls to an attacker-controlled number, which knocks out phone-based two-factor authentication and bank fraud-prevention calls in one move.
The researchers pointed out that the surveillance capabilities go further. RedWing can remotely activate a victim’s camera and microphone, recording audio through commands sent from the attacker’s server with configurable recording duration.
“The malware is capable of remotely activating the cameras and the microphone of an infected device (Fig. 12). This functionality is executed via specific commands. For instance, the <take_photo> command allows the attacker to remotely capture images using the device’s camera. Similarly, the <start_recording> command leverages the MediaRecorder API to capture ambient audio.” continues the report.“This audio recording process is managed entirely from the remote server, which allows the attacker to configure the exact duration of the recording, among other parameters.”
On top of that, operators get live screen streaming via VNC, a real-time keylogger, access to all files on the device, contact lists, call logs, and location tracking.
The targeting architecture reveals something telling about how RedWing is built. The apps it monitors through Accessibility are baked into each compiled copy, which points to a fresh APK being generated server-side each time a buyer specifies their targets. The overlay targets, by contrast, can be updated from the control panel at any time without distributing a new app.
Zimperium identified 82 targeted institutions across multiple sectors, with a heavy focus on Russian financial firms, one sample used a fake RuStore page, though the list can shift at any time from the operator’s dashboard.
RedWing doesn’t need any Android vulnerability to work. It relies entirely on the user installing an app from outside an official store and approving its permission requests. The first line of defense is what happens at install time: don’t install apps from links sent by text or messaging apps, don’t grant Accessibility or default-SMS access to apps with no clear reason to need them, and treat any app that hides its icon after installation as a red flag. On managed devices, sideloading can be blocked centrally and suspicious permission requests flagged automatically.
RedWing can also transform infected Android devices into a botnet capable of launching coordinated DDoS attacks. Through its control panel, attackers can command multiple compromised phones at once to send traffic floods against a target website or server, disrupting its availability and adding another capability beyond spying and data theft.
Because operators can reskin the app and swap its targets from the control panel, the app name is a poor indicator, behavior is what to watch for.
“The rapid rise of Malware-as-a-Service (MaaS) operations like RedWing shows how easily attackers can weaponize legitimate Android components to achieve full device compromise. Unlike older banking trojans that rely solely on overlays, RedWing integrates custom droppers, live screen streaming, and abuse of the SMS handler role and Accessibility to exfiltrate data and impersonate legitimate apps in real time.” concludes the report. “This blend of social engineering and hijacking the incoming calls makes this deep-system control especially dangerous in BYOD and consumer-facing environments where app-store trust is assumed.”