Visualização de leitura

Pegasus and NoviSpy Used Against Serbian Protesters

Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections.

A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, tracing it to an iMessage zero-click exploit and identifying high-confidence indicators of compromise between December 2025 and January 2026, with the possibility of additional infections not ruled out.

“In collaboration with the SHARE Foundation, the Citizen Lab analyzed forensic artefacts from the iPhone of a member of Serbia’s student protest movement after they received an Apple Threat Notification warning of targeting with mercenary spyware.” reads the report published by Citizen Lab. “Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware. “

The attack required no action from the victim, which makes zero-click attacks especially dangerous. Citizen Lab said the Pegasus infection could stay hidden while giving the attacker full access to the phone, including messages, photos, notes, microphone, and camera. Apple later fixed this specific exploit through security updates in iOS 18.4.1.

“We believe that the zero-click exploit used in this attack targeted Apple iMessage, and has subsequently been patched by Apple as of iOS 18.4.1.” continues the report. “A zero-click infection with Pegasus spyware would not have been visible to the target, and would give the Pegasus attacker total access to the device. Pegasus allows an attacker to do anything that a user can do, ranging from accessing private data like notes, pictures and even encrypted messages. Pegasus also has the ability to covertly enable the phone’s microphone and camera.”

This one confirmed infection sits inside something considerably bigger. The SHARE Foundation has documented at least 14 individuals targeted with advanced spyware since early 2026, spanning student movement members, civil society activists, an opposition member of parliament, and a local councilor, which the organization is calling the largest documented surveillance wave in Serbia’s history. Twelve people approached SHARE’s digital forensics team in August after receiving Apple’s own threat notifications, warnings the company sends when it detects likely state-sponsored spyware targeting; eleven of those devices remain presumed infected pending further forensic confirmation.

The timing lines up uncomfortably well with Serbia’s political calendar. This surveillance wave coincides with local elections held on March 29, 2026, and stretches toward planned early parliamentary elections in October, following months of student-led anti-government and anti-corruption protests.

“These notifications and forensic confirmation highlight the aggressive mercenary spyware targeting of the peaceful pro-democracy movement with mercenary spyware ahead of key 2026 election cycles.” continues the report.

Targeting activists and opposition figures specifically in the run-up to elections isn’t subtle, and it fits a pattern Serbia has shown before.

Serbia has a history of using commercial spyware. Citizen Lab previously documented Pegasus targeting civil society and the use of Cellebrite tools to install the locally developed NoviSpy on activists’ phones. In this case, SHARE Foundation and Amnesty Tech found a new version of NoviSpy on a student activist’s Android phone after Serbian authorities seized it during police questioning.

Amnesty International’s Security Lab head, Donncha Ó Cearbhaill, connected the dots plainly between state custody and spyware installation.

“The forensic findings by SHARE prove that Serbian students continue to be targeted with invasive Android spyware tools, installed while detained by Serbian authorities” he said.

If you’ve received an Apple Threat Notification, whether in Serbia or anywhere else, the Citizen Lab’s guidance is unambiguous: treat it as a presumed infection and get expert help immediately rather than waiting to see if anything seems wrong. Individuals in Serbia should contact the SHARE Foundation directly, and anyone elsewhere can reach Access Now’s Digital Security Helpline, which supports journalists, human rights defenders, and other high-risk civil society targets worldwide. Anyone who suspects they might be a target based on their work or public role should also turn on Lockdown Mode, Apple’s built-in feature that significantly narrows what a zero-click exploit can actually reach, and keep every device updated, since the patch that closed this specific hole has already existed for well over a year for anyone who installed it.

“We believe that the zero-click used in this attack has been rendered ineffective by a patch from Apple in recent iOS versions. We urge everyone, especially those facing increased risks because of who they are or the work they do, to keep all devices updated.” concludes the report. “Click HERE for instructions on how to keep your iPhone up to date.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Pegasus)

Pegasus, New NoviSpy Variant Found on Serbian Students and Opposition Figures

Pegasus, Pegasus Spyware, Serbia, Serbia Protests, Smartphone screen forming an eye shape against an abstract protest crowd, illustrating spyware targeting of Serbian student activists.

At least 14 people connected to Serbia's student protest movement and opposition politics have been targeted with mercenary spyware since early 2026, the Belgrade-based digital rights organization SHARE Foundation said, in what it called the largest documented wave of such targeting in the country.

The group said the cohort includes student movement members, civil society activists, a member of parliament and a local councilor. Forensic analysis was independently confirmed by the Citizen Lab at the University of Toronto and by Amnesty International's Security Lab.

Citizen Lab, in its own findings, said it verified an infection with NSO Group's Pegasus on the iPhone of a student activist who asked not to be named. High-confidence infection indicators span December 2025 through January 2026, delivered by a zero-click iMessage exploit that required no interaction from the target. Apple has since patched the underlying flaw; the fix shipped in iOS 18.4.1. Pegasus grants an operator access to notes, photographs and messages decrypted on the device, and can silently activate the microphone and camera.

Amnesty's Security Lab confirmed a new variant of NoviSpy, an Android implant first identified in Serbia in 2024, on two additional devices. SHARE said the rebuilt version was designed to evade the detection methods that exposed its predecessor.

Also read: Investigative Journalists in Serbia Hit by Advanced Spyware Attack

The circumstances of two infections are what elevate the findings beyond routine spyware reporting. SHARE said one NoviSpy infection appeared after police seized a student's phone during questioning, and another after private messages from that device were published by a pro-government media outlet. Donncha Ó Cearbhaill, who heads Amnesty's Security Lab, said the evidence suggests "infections are being carried out during detention by Serbian authorities."

Suspicion centers on Serbia's Security Information Agency, or BIA. Amnesty's December 2024 report "A Digital Prison" found earlier NoviSpy samples configured to send collected data to IP addresses associated with BIA servers, and documented the agency's parallel use of Cellebrite extraction tools on journalists and activists. In March 2025, Amnesty reported that two journalists at the Balkan Investigative Reporting Network were targeted with Pegasus.

The current cases surfaced through Apple's threat notification wave of Aug. 13, which reached users in 110 countries. The timing is politically loaded. The targeting overlaps with protests that followed the November 2024 collapse of a railway station canopy in Novi Sad, spans local elections held March 29 in 10 municipalities, and precedes October parliamentary elections widely read as a test of the ruling Serbian Progressive Party.

Ana Toskic Cvetinovic, a legal expert cited in the reporting, noted that deploying intrusive software without judicial authorization is unlawful under Serbian law. SHARE published an analysis of the domestic legal framework in January arguing the same. Criminal complaints filed over the 2024 cases remain pending before Serbian courts, with no resolution.

Also read: 7 New Pegasus Infections Found on Media and Activists’ Devices in the EU

NSO has been on the U.S. Commerce Department's Entity List since 2021.

Serbia is an accession candidate, the European Parliament has previously questioned the Commission over unlawful spyware use in the country, and the Commission published its 2026 enlargement country report in July. Amnesty's submission for that package raised surveillance directly.

Both groups urged at-risk users to enable Lockdown Mode on iOS or Advanced Protection on Android.

Threat landscape for industrial automation systems. Q2 2026

All threats

In Q2 2026, the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15%, its lowest level since 2022.

Percentage of ICS computers on which malicious objects were blocked, Q3 2023–Q2 2026

Percentage of ICS computers on which malicious objects were blocked, Q3 2023–Q2 2026

Regionally, the percentages ranged from 8.1% in Northern Europe to 27.9% in Africa.

Regions ranked by percentage of attacked ICS computers

Regions ranked by percentage of attacked ICS computers

The figures increased in five regions over the quarter, most notably in East Asia (by 2.0 pp) and Africa (by 0.5 pp).

East Asia saw increases in percentages for all threats except miners. The region ranked first in terms of growth for malicious scripts and phishing pages, spyware, and viruses. East Asia also led in terms of growth in threats from the internet. The percentage of ICS computers on which email threats were blocked also increased.

Selected industries

The biometrics sector (26.44%) has traditionally led the rankings of industries and OT infrastructures surveyed in this report in terms of the percentage of ICS computers on which malicious objects were blocked. Biometric systems are characterized by the availability of internet access, extensive email use for data exchange and approvals (e.g. access granting), and, in many cases, minimal cybersecurity controls within the organizations that use them.

Industries ranked by percentage of ICS computers on which malicious objects were blocked

Industries ranked by percentage of ICS computers on which malicious objects were blocked

The biometrics sector ranked first among industries in terms of the following threat categories: malicious scripts and phishing pages, malicious documents, spyware, ransomware, and worms. The sector is also leading among industries in terms of email threats. At the same time, unlike other industries, the percentage of affected ICS computers for email threats in biometrics exceeds that for internet threats.

In all selected industries, the global average follows a downward trend.

Threat categories

In Q2 2026, Kaspersky security solutions blocked malware from 10,904 different malware families of various categories on industrial automation systems.

Over the quarter, the percentage of ICS computers on which malicious objects of the following categories were blocked increased: denylisted internet resources, malicious documents, worms, ransomware, and malware for AutoCAD.

Percentage of ICS computers on which the activity of malicious objects from various categories was blocked

Percentage of ICS computers on which the activity of malicious objects from various categories was blocked

Malicious scripts and phishing pages (JS and HTML)

Malicious scripts and phishing pages remained in first place in the threat category rankings based on the percentage of ICS computers on which the respective threats were blocked. In Q2 2026, the global average dropped to 5.42%.

Over the quarter, the figure for this category only increased in East Asia, rising by 0.93 pp to 4.86%. This is the second-highest figure in the region in the last three years.

In East Asia, the percentage of ICS computers affected by malicious scripts and phishing pages increased in all the industries surveyed, except construction. The highest figures were recorded for biometrics (9.01%) and building automation (6.49%).

Denylisted internet resources

In Q2 2026, denylisted internet resources rose in the threat category rankings from third to second place, displacing spyware. Globally, the percentage of ICS computers on which denylisted internet resources were blocked has been increasing for two quarters in row and reached 4.31%.

The figures increased in all regions over the quarter, most notably in Russia (by 1.33 pp). Moreover, Russia ranked first (5.17%) among the regions in terms of denylisted internet resources. Since 2022, the region has topped these rankings twice before, both times in Q2: in 2022 and 2024.

Among the selected industries in Russia, the highest figures for the denylisted internet resources were in the electric power (6.61%) and engineering and ICS integration (5.62%) industries.

Malicious documents (MSOffice + PDF)

Malicious documents ranked fourth in the threat category rankings by the percentage of ICS computers on which they were blocked. The percentage for this category decreased over the previous three quarters, reaching its lowest level in three years. However, in Q2 2026, it increased to 1.77%.

Over the quarter, the figures for malicious documents increased in seven regions, most notably in South America (by 1.35 pp) and Southern Europe (by 0.48 pp). These two regions are among the top three in terms of malicious documents, malicious scripts and phishing pages, as well as threats from email clients.

South America ranked second in the rankings of regions in terms of malicious documents. In Q2 2026, the percentage of ICS computers in the region on which this threat was blocked was 3.56%, which was the fourth highest in three years.

Among the selected industries in South America, the highest percentage of ICS computers on which malicious documents were blocked was in biometrics (6.67%).

Southern Europe ranked first in the rankings of regions in terms of malicious documents. In the previous quarter, the percentage of ICS computers in the region on which this threat was blocked was the lowest in three years, but in Q2 2026 it increased to 3.63%.

Among the selected industries in Southern Europe, the highest percentage of ICS computers on which malicious documents were blocked was once again in biometrics (11.48%).

Spyware

Spyware ranked third in the threat category rankings based on the percentage of ICS computers on which it was blocked. The percentage for this category (3.30%) is the lowest since 2022.

Over the quarter, the figures increased in three regions, most notably in East Asia (by 0.53 pp) and Southeast Asia (by 0.42 pp).

East Asia ranked third based on the figures for spyware (4.77%), behind Africa and Southeast Asia. This is the region’s highest rate since Q2 2025. Among the countries and territories in the region, the highest percentage of ICS computers on which spyware was blocked was in mainland China (6.61%). Among the selected industries in East Asia, the highest figures for spyware were in the electric power (11.75%) and manufacturing (5.87%) industries. In all the industries surveyed, the figures are higher than the regional average.

Southeast Asia ranked second after Africa in the ranking of regions in terms of spyware, with 5.32%. Among the selected industries in Southeast Asia, the highest figures for spyware were in biometrics (8.93%) and manufacturing (7.32%). The figures increased in all industries over the quarter.

Ransomware

The percentage of ICS computers on which ransomware was blocked decreased in the previous three quarters but increased to 0.16% in Q2 2026.

During the quarter, the percentage increased in all regions, except Western and Southern Europe and North America (Canada). Africa led the ranking in terms of growth for this metric.

In Q2 2026, Africa ranked first among the regions in terms of the percentage of ICS computers on which ransomware was blocked (0.29%). The only time the figure in the region was higher in the past three years was Q2 2025 (0.31%).

Among the selected industries in Africa, the highest figures for ransomware were in the electric power industry (0.72%) and biometrics (0.52%). Over the quarter, the figures increased in all industries, except manufacturing and construction. The biggest increase was recorded in the electric power industry.

In Russia, the percentage of ICS computers on which ransomware was blocked in biometric systems has increased for three consecutive quarters, reaching 1.22%. This is the highest level of ransomware across all industries in all regions.

Miners

In Q2 2026, the percentage of ICS computers on which miners were blocked was the lowest since 2021, for both miners in the form of executable files for Windows (0.48%) and web miners running in browsers (0.14%).

The figures for both categories decreased in all regions, except for Africa where figures for miners in the form of executable files for Windows increased slightly.

On average, the oil and gas industry led the rankings among the selected industries both in terms of miners in the form of executable files for the Windows OS (0.66%) and in terms of web miners (0.34%).

Worms

In Q2 2026, the percentage of ICS computers on which worms were blocked increased to 1.43%.

In Q2 2026, the Middle East (2.11%) was second (after Africa) in the rankings of regions in terms of worms, displacing Central Asia and the South Caucasus.

Among the selected industries in the Middle East, the highest percentage of ICS computers on which worms were blocked was in building automation (2.90%). Over the quarter, the figures increased in all industries.

Australia and New Zealand ranked 12th among the regions in terms of the percentage of ICS computers on which worms were blocked (0.41%). Over the past three years, the figure in this region was only higher in Q2 2024 (0.42%). The figures increased in all the surveyed industries in the region, most notably in manufacturing and electric power. As a result, for these industries they exceeded the regional average by 2.9 and 2.3 times, respectively.

Viruses

In Q2 2026, the percentage of ICS computers on which viruses were blocked decreased to 1.29%.

The top three regions for this metric remain unchanged: Southeast Asia (6.03%), Africa (4.22%), and East Asia (3.14%). These same regions lead the rankings in terms of malware for AutoCAD.

The figures increased in three regions: East Asia, Australia and New Zealand, and Africa, where it has been growing for four consecutive quarters and reached its highest value since 2022.

Among the selected industries in Africa, the highest percentage of ICS computers on which viruses were blocked was in construction (5.47%).

East Asia ranked third among the regions in terms of viruses, reaching the highest level in the region for the past three years. Among the countries and administrative regions of East Asia, mainland China is the clear leader in terms of viruses (5.07%).

Among the selected industries in East Asia, the highest percentage of ICS computers on which viruses were blocked was in construction (5.93%).

In Australia and New Zealand, the increase in the percentage of ICS computers on which viruses were blocked was primarily due to a 4.3-fold increase in the figure for the electric power industry: from 0.29% to 1.24%. For a region where the percentage of attacked ICS computers for all threats is 0.12%, this is a very high value.

Malware for AutoCAD

In Q2 2026, the percentage of ICS computers on which malware for AutoCAD was blocked increased to 0.31%.

The most notable increase over the quarter was observed in Africa. After more than doubling in the previous quarter, the figure for the region continued to rise (although not so dramatically), reaching 1.02%.

Among the selected industries across all regions, the highest percentage of ICS computers on which malware for AutoCAD was blocked was in construction in East Asia (6.38%) and in Southeast Asia (4.05%).

Main threat sources

In Q2 2026, of all the threat sources, the percentage increased only for email.

Percentage of ICS computers on which malicious objects from various sources were blocked

Percentage of ICS computers on which malicious objects from various sources were blocked

Internet

The percentage of ICS computers on which threats from the internet were blocked decreased to 7.61%, reaching its lowest level since 2021.

Over the quarter, the percentage increased in three regions: East Asia by 0.8 pp (to 6.3%), South Asia by 0.3 pp (to 10.4%), and Russia by 0.3 pp (to 6.4%).

Among the selected industries across all regions, the highest percentage of ICS computers on which threats from the internet were blocked was in biometrics (13.03%) and engineering and ICS integration (12.16%) in South Asia.

Email

The percentage of ICS computers on which email threats were blocked increased to 2.84%.

In Q2 2026, the percentage of ICS computers on which email threats were blocked increased in South America by 1.0 pp (to 5.2%) and in Africa by 0.7 pp (to 4.3%).

Among the selected industries across all regions, the highest percentage of ICS computers on which email threats were blocked was in biometrics (19.14%) and building automation (12.49%) in Southern Europe.

Removable media

The percentage of ICS computers on which threats from removable media were blocked continued to decrease, reaching 0.24%, the lowest value for the period under review.

Among the selected industries across all regions, the highest percentage of ICS computers on which threats from removable media were blocked was in the electric power industry in East Asia (1.34%) and biometrics in Africa (1.29%).

Network folders

The percentage of ICS computers on which threats from network folders were blocked continued to decrease. In Q2 2026, it was the lowest for the period under review, at 0.023%.

The only region to see an increase in the percentage of ICS computers on which threats from network folders were blocked during the quarter was Africa. This was mainly due to an increase in the building automation figure to 0.05%.

Among the selected industries across all regions, the highest percentage of ICS computers on which threats from network folders were blocked was in biometrics (0.23%), building automation (0.17%), and engineering and ICS integration (0.13%) in East Asia.

For more information on industrial threats see the full version of the report.

Spyware for Babies

The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.

Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech and language development, motor skills and more, while extending its presence in children’s bedrooms into early adolescence.

Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss

Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help.

The post Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss appeared first on TechRepublic.

FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight

Federal court records show how far the FBI’s Pegasus review progressed — and why new US spyware reporting will still leave major gaps in government hacking transparency.

The post FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight appeared first on TechRepublic.

US Courts To Begin Publishing Spyware Records From 2029

U.S. courts will begin separately tracking spyware-based interceptions, giving the public new data on government hacking while leaving key gaps.

The post US Courts To Begin Publishing Spyware Records From 2029 appeared first on TechRepublic.

Apple warned hundreds of users of mercenary spyware attacks

Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance.

Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already issued in more than 150 countries since the programme began in 2021.

“Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks, likely because of who they are or what they do. Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices.” reads the alert. “Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks.”

That alone should reset the usual mental model. This isn’t about a suspicious app, a recycled phishing email, or the kind of opportunistic malware that lands wherever it can. Apple’s alerts concern highly targeted attacks against particular people, often because of their role, their work, or the people they know.

The people most likely to receive these notifications include journalists, activists, politicians, diplomats, lawyers, and others whose devices may hold valuable conversations, contacts, documents, or location data. That does not mean every recipient has been fully compromised, but it does mean Apple has observed enough to treat the risk as credible.

Apple has also changed how it delivers those alerts. A recipient may see a push notification directly on the iPhone lock screen and in Settings, receive an email from threat-notifications@email.apple.com, and find a warning banner after signing in to their Apple Account. The company says genuine notices will never ask users to click a link, open a file, install a profile, or provide a password or verification code by email or phone.

“Apple relies solely on internal threat-intelligence information and investigations to detect such attacks. Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.” continues the report. “We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future.”

That lack of detail can frustrate recipients. They want to know who targeted them, how the device was approached, and whether the attacker got in. Apple can’t safely answer most of those questions in public, because publishing the detection logic would give spyware vendors a free quality-assurance report. Nobody needs to make Pegasus-style operators more efficient.

If you receive the warning, don’t panic and don’t start improvising. First, verify it by signing in directly at account.apple.com: a genuine Apple threat notification appears at the top of the page. Then preserve the device, avoid unnecessary resets or changes until you have spoken to someone qualified, and seek expert help, such as the Digital Security Helpline run by Access Now.

Apple recommends enabling Lockdown Mode, its high-security setting designed to reduce the attack surface available to sophisticated spyware. It also advises keeping devices updated, using a strong passcode with Touch ID or Face ID, turning on two-factor authentication, enabling Stolen Device Protection, using strong and unique passwords or passkeys, installing apps only through the App Store, and treating unexpected links or attachments as hostile until proven otherwise.

“Since 2021, we have sent Apple threat notifications multiple times a year as we have detected these attacks, and to date we have notified users in over 150 countries in total. The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today.” states the alert. “As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.”

The wider value of these alerts goes beyond the device in front of the recipient. Citizen Lab researcher John Scott-Railton told TechCrunch that notifications can reveal that an entire community is being targeted, because people who receive them often seek help and their cases lead investigators to others.

Most people will never receive one of these warnings. Apple says that plainly, and it is worth repeating because not every cybersecurity story needs to become a universal panic. But if your phone shows an Apple notice saying it detected a targeted mercenary spyware attack, assume it matters until an expert tells you otherwise.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Apple)

Apple now uses iPhone alerts for targets of mercenary spyware

Apple has expanded its threat-notification system for targets of mercenary spyware.

Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user’s Apple Account page.

In the explanation, Apple states:

“Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.”

Apple Threat Notification

“Apple Threat Notification
Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device.”

Apple says its threat notifications are intended for people individually targeted by mercenary spyware attacks, which are highly sophisticated campaigns usually associated with commercial surveillance vendors and their government customers. Apple says it has notified targets in over 150 countries since the launch of the program in 2021, while the latest round of notifications reached people in 110 countries.

Mercenary spyware campaigns are usually not aimed at the average iPhone owner—at least at first. The initial targets are often people selected for who they are, what they know, or the work they do. But it would be a mistake to view this as someone else’s problem.

Attack techniques developed for narrowly targeted operations have a habit of spreading. Exploits can be reused, sold onward, reverse engineered, copied by other surveillance vendors, or adapted by criminal groups. A vulnerability initially valuable because it compromises a small number of carefully chosen devices may become much more dangerous once public disclosure, patch analysis, or exploit sharing makes them available for more widespread campaigns.

How to stay safe

Apple advises users to:

  • Update your devices to the latest software, which includes the latest security fixes.
  • Protect your devices with a passcode, Touch ID, or Face ID.
  • Use two-factor authentication and a strong password for your Apple Account.
  • Turn on Stolen Device Protection.
  • Install apps from the App Store.
  • Use strong and unique passwords, and passkeys where available.
  • Don’t open links or attachments from unknown senders.

We’d like to add:

  • Potential targets of mercenary spyware should consider applying Apple’s Lockdown Mode.
  • Check if an Apple Threat Notification is real. Scammers will undoubtedly try and mimic them. You can verify a notification by signing in to your Apple account. A genuine Threat Notification will always be clearly listed there.
  • If you receive an Apple Threat Notification, Apple recommends seeking expert help, such as the Digital Security Helpline from Access Now.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Armored Likho expands its cyber-espionage toolkit

In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage.

We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal.

During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data to gain ongoing access to the victim’s account. With this stolen data, attackers can leverage the Telegram API to automatically pull chat logs, media files, and other information from the account.

The second component, Still Audio, is an implant for covert audio surveillance. It analyzes the incoming audio stream, automatically detects speech, records conversations, and sends the recordings to a command-and-control server.

In this article, we’ll look at the initial infection method, how the new Still Toolkit components are built, and the technical details of how they operate.

Kaspersky products detect this threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic.

Background

Armored Likho’s malicious activity has been documented several times before: in November 2024, and in February and July 2026. The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure. At the same time, our research uncovered a number of new tools that point to the attackers expanding their capabilities.

Initial infection

The infection chain starts with an app that mimics a donation service. As of this writing, the app distribution method remains unknown. During our research, however, we obtained several samples posing as apps from different Russian foundations.

In reality, the app is a dropper. Its developers wrote it in Rust on top of the popular Tauri framework, and it has a graphical interface designed to deceive the user. After launch, it displays a login form that asks for a password, presumably one the attackers supplied.

The login form

The login form

After the user enters a valid password, they see a catalog of donatable items. The app pulls item and category information from orderapiserver[.]info through the public/categories and public/products endpoints. A clickable catalog makes the app look legitimate. While the user browses the items, the dropper quietly decrypts and launches the payload for the next stage in the background.

Our analysis shows that the mechanism for decrypting the payload and launching subsequent stages hasn’t changed since the February campaign. However, we found a new cyber-espionage toolkit – the Still Toolkit – made up of two components: Still Sync and Still Audio.

Still Sync

Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API.

Architecturally, Sync is an asynchronous application based on the Tokio library. It talks to the server over gRPC and serializes messages with FlatBuffers. It supports both HTTP and HTTPS as transport protocols; the URL of the command-and-control server determines which one it uses.

How it works

When Sync launches, the attackers set several environment variables. Before starting any malicious activity, the implant pulls configuration parameters from these:

  • STILL_SYNC_ADDR: the address of the command-and-control server. By default, this is https://tg4service[.]com:443.
  • STILL_SEND_PATH: the path to the tdata
  • STILL_TELEGRAM_PASSCODE: the password for decrypting the tdata folder, if Telegram data encryption is enabled on the victim’s device.

Sync also supports several command-line arguments:

  • --console: runs as a console application. If this parameter is absent, the implant creates a TReload service to keep running in the background.
  • --version: prints version information and exits.
  • --firefly: launches a trace thread that monitors the program’s operation. It writes error messages to a hidden file, bin, located in the same folder as the main executable.
  • --db: turns on debug mode with detailed logging.
Example Still Sync logs

Example Still Sync logs

Once it launches, the malware begins registering the device with the C2 server. To do this, Sync collects the following information about the victim’s system:

  • Motherboard serial number
  • CPU ID
  • System UUID
  • BIOS serial number
  • Computer domain name

The malware combines the collected data into a single string with a colon as the separator. It then hashes that string with SHA-256 and stores the resulting hash under the key sysmarker. Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm.

Sync then serializes a package containing all the collected information and the agent version, and sends it in a POST request to /still.rpc.Sync/RegisterMachine. The response contains a machine_id value, which Sync uses to identify itself in subsequent requests.

Once registration succeeds, Sync sends a POST request with the machine_id parameter to /still.rpc.Sync/GetMachineSettings. The server responds with the following settings:

  • enabled: triggers malicious activity on the infected device.
  • scan_portable: turns on extended scanning when searching for the tdata We’ll cover this feature in more detail below.
  • fetch_telegram: if this parameter is on, Sync attempts to log in to Telegram and extract data. We’ll cover this feature in more detail below.
  • download_channels: if this parameter is off, Sync skips channel dialogs when exfiltrating Telegram data.

These parameters have no default values, so Sync doesn’t perform any malicious actions until the registration and settings-retrieval processes both complete successfully.

Telegram data collection

Before stealing a Telegram session, Sync searches for the tdata folder, unless the STILL_SEND_PATH variable is already set. The list of search paths includes both standard and nonstandard directories, if the scan_portable option is turned on:

  • C:\Users\<username>\AppData\Roaming\Telegram Desktop\: the standard Telegram Desktop installation directory.
  • C:\Users\<username>\AppData\Local\Packages\<package_folder>\LocalCache\Roaming\: the installation directory for the Microsoft Store version. Sync identifies the package folder by a name that contains the string TelegramMessenge.
  • C:\: used for the extended search (if the scan_portable option is on).

Sync then sends a POST request with a list of files from the tdata folder to the /still.rpc.Sync/CheckFiles endpoint. The server responds with the following values:

  • snapshot_id: an identifier the server assigns to the current data snapshot.
  • present: a list of file paths that are already present on the server.

This lets the C2 server avoid re-receiving files it already has. In addition, if Sync can’t access files on disk through standard methods, it falls back on three mechanisms that abuse the SeBackupPrivilege privilege:

  • Opening files with the CreateFileW function using the FILE_FLAG_BACKUP_SEMANTICS parameter
  • Creating a backup copy through the Shadow Copy service and reading files from there
  • If the previous methods all fail, attempting to copy the file using the Robocopy utility in backup mode

Beyond stealing Telegram session data, Sync can carry out full-scale collection of user information from the messaging app. When the fetch_telegram option is on, it launches a separate thread that authenticates to the chat app using the previously obtained tdata. Once authentication succeeds, Sync gains access to the account data and sends the following collected information to the server:

  • User details, such as username, phone number, first and last name
  • Information about private chats, groups, or channels, such as chat name and ID, the member list, and so on
  • Dialogs from private chats, groups, and channels (if the download_channels option is on)
  • Media files under 250MB: photos, documents, stickers, and contacts

Still Audio

Still Audio is an audio surveillance implant written in Rust. Its main job is to analyze the incoming audio stream and start recording voice when certain conditions are met – we’ll cover those in the next section. Architecturally, Still Audio largely mirrors Sync and uses the same mechanisms for communicating with the C2 server.

On launch, Still Audio performs a sequence of actions:

  • It extracts libmp3lame.dll, a file stored inside the executable. This is a library used to encode audio data.
  • If the --console command-line argument is absent, the implant creates a service named auxhost, connects to it, and continues running in the background.
  • While running in the background, it creates a file, logfile.log, to write logs to.

Next, Still Audio retrieves the C2 server address. As with Sync, it stores the URL in an environment variable – in this case, STILL_AUDIO_SYNC_ADDR. If that variable isn’t set, it falls back to STILL_SYNC_ADDR, which shows the two modules are compatible with each other. If neither variable is set, it uses the default URL, https://srwinservice[.]com.

Still Audio also uses the Dead Drop Resolver technique as a fallback mechanism for obtaining the C2 address. If the current server stays unreachable for three days, the tool tries to pull the current C2 URL from a GitHub repository. In the sample under analysis, we found the following URL for the page containing C2 information: hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json

Encrypted C2 address inside the GitHub repository

Encrypted C2 address inside the GitHub repository

The repository, a fork of a popular project, contains the server URL Base64-encoded and encrypted with the Blowfish algorithm in ECB mode, using the key 5c8e153228edd3c6cbf75684 (lowercase string). Older AquilaRAT samples use this exact same algorithm and key.

Once it obtains the current C2 address, the Audio module starts a registration process similar to Sync’s, but through a different endpoint:

/still.rpc.Audio/RegisterAudioMachine. Also, unlike Sync, Audio sends a list of available audio input devices along with the system information.

The server responds with settings for the implant:

  • machine_id: a unique identifier for the current device.
  • vad_threshold: the threshold value for the VAD (Voice Activity Detection) algorithm. Expressed as a decimal fraction, it represents a proportion of the maximum sound level the input device can pick up. Sound above this threshold counts as voice activity. The default vad_threshold is 02.
  • max_silence_duration: the number of audio samples with a VAD value below the set threshold after which the implant considers the recording finished.
  • max_buffer_size: the maximum buffer size for recorded audio data.
  • active_device: the name of the input device selected for recording, from the list of available devices.

The eavesdropping process

Still Audio works with raw audio samples it captures directly from the input device. To detect voice activity, it implements an algorithm based on Root Mean Square (RMS), a lightweight signal-processing method that distinguishes speech from silence by measuring the audio signal’s average power over time. The implant doesn’t rely on any third-party libraries here; it implements all the calculations itself.

The implant compares the calculated RMS value against the vad_threshold parameter. If RMS meets or exceeds this threshold, recording starts. To avoid losing the beginning of the recording, Still Audio uses a pre-buffer, a size-limited buffer that stores samples from just before the current recording moment. A sequence of max_silence_duration samples (320 by default) with RMS values below the threshold signals the end of the recording. For example, with a standard headset running at a 44.1kHz sampling rate, recording stops after roughly 7ms of silence.

Interestingly, the Audio module makes no attempt to hide its use of the microphone: its name shows up in Windows settings. In the sample we examined, the file was saved to disk as IntAudio.exe, and it appeared in the list of apps using the microphone as “Intel Audio”:

The malicious module in the list of apps using the microphone

The malicious module in the list of apps using the microphone

Before sending recordings to the server, the implant uses the libmp3lame library to encode the raw audio samples. It sends the recording files via a POST request to /tgfrg, adding a Client-Id header containing the machine_id obtained during registration to identify the device.

Infrastructure

This campaign draws on a broad set of hosting providers and domains registered at different points in time, which suggests the attackers are trying to make their infrastructure harder to detect. We found no direct overlap in domains or IP addresses with the February campaign. Even so, the two infrastructures share some similarities:

  • They use the same hosting providers, with the ASNs 149440, 202448, and 215311.
  • Their domain names follow similar naming patterns that mimic Windows system services and update mechanisms.
Domain IP address Registration date ASN
orderapiserver[.]info 187.127.153[.]38 April 18, 2026 47583
tg4service[.]com 159.198.37[.]74 October 4, 2025 22612
srwinservice[.]com 213.252.244[.]123 March 19, 2026 61272
screenserv[.]com 23.26.237[.]250 February 13, 2026 149440
windowserv[.]net 23.27.24[.]30 February 10, 2026 149440
managementapiservice[.]com 188.212.124[.]178 May 1, 2026 202448
service8date[.]com 145.223.69[.]143 January 13, 2026 215311
updateservs[.]com 145.223.68[.]66 December 23, 2025 215311

Victims

In this campaign, we’ve determined that the attackers’ primary targets are users in Russia. Most victims are private individuals, though the corporate sector, government organizations, IT companies, and educational institutions are also affected.

Attribution

This campaign has been using both new tools and malware families documented in BI.ZONE’s February report. While some components turned up for the first time, they show significant code-level overlap with malicious tools seen in earlier Armored Likho campaigns. Based on these overlaps, along with additional technical artifacts, we’re highly confident the Armored Likho group is behind the campaign. The overlaps we identified include:

  • Identical dropper architecture in the February and current campaigns, which includes the use of the Tauri library to build the graphical interface, a similar user-input handler, a payload with the ICRYPTMP header, and the same multi-part encryption format.
  • The same encryption algorithm and key used in AquilaRAT from the previous campaign and in the Still Audio module from the current campaign, both implementing the Dead Drop Resolver technique.
  • Identical logic for generating the sysmarker value in older AquilaRAT samples and in the Still toolkit from the current campaign. The algorithms match down to the PowerShell commands used to collect system information.
  • Substantial infrastructure overlap, which includes the hosting providers and domain-naming patterns described in the Infrastructure section.

Takeaways

The campaign described in this post shows Armored Likho’s toolkit evolving, with the group steadily expanding its cyber-espionage capabilities. Beyond the components we already knew about, the attackers rolled out new modules that let them not only access Telegram data but also conduct audio surveillance on victims. Together, these capabilities significantly widen the range of information attackers can collect in a single compromise.

One point deserves particular attention: the new tools form a cohesive set, sharing similar architecture, C2 communication mechanisms, and common implementation elements. This points to the group building out its own tool ecosystem, designed for long-term use and further expansion.

The emergence of new, specialized modules shows the attackers aren’t just trying to preserve their existing capabilities – they’re working to make intelligence-gathering more effective by controlling multiple communication channels at once.

Indicators of compromise

Additional information about this threat, indicators of compromise included, is available to customers of Kaspersky Threat Intelligence Reporting. Contact intelreports@kaspersky.com for more details.

File hashes
Droppers
C1D1EE16B92E6A138FFA048855F75D7D
17674B250D8B422A50A86C9FF207186D
62801F6223E860A7CCA271522E303B2D

Still Sync
68F0365D2FA8C828D012D8859E52A773
4BD7C352AE277B0E38D07BEEDD4DD507
D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD

Still Audio
2CA8ADBAB98EBE305EACF272CF48F5A0
3AC41B097236A7723821848AE31EF141
439255736797BC88BD19F282449E0436

Domains
orderapiserver[.]info
tg4service[.]com
srwinservice[.]com
screenserv[.]com
windowserv[.]net
managementapiservice[.]com
service8date[.]com
updateservs[.]com

Malicious CCleaner Installer Patches Chrome Security Extension to Deploy Browser Spyware

A counterfeit installer for the widely used PC-cleaning utility CCleaner is being used to compromise Windows systems and deploy a malicious Chrome extension dubbed GhostDesk. CCleaner’s global popularity, with more than two billion downloads, gives attackers a credible pretext to target users searching for system-maintenance tools. The observed infection chain begins at ccleanerwind[.]top, a website […]

The post Malicious CCleaner Installer Patches Chrome Security Extension to Deploy Browser Spyware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Relatório Semestral de Ameaças da Gen: cibercriminosos se aproximam de sistemas nos quais as pessoas confiam

00A Gen (NASDAQ: GEN) publicou seu Relatório de Ameaças do primeiro semestre de 2026 para ajudar as pessoas a entender quais ciberameaças estão emergindo e quais riscos estão moldando a vida digital hoje. Um ponto em comum permeia todo o relatório: cibercriminosos estão se movendo para mais perto das partes confiáveis da vida digital. Eles não estão apenas enviando links maliciosos ou distribuindo malwares, mas também explorando o contexto, sessões, fluxos de trabalho, marcas, sistemas de atualização, plataformas de publicidade e autoridade delegada.

 A confiança se tornou a nova superfície de ataque

A descoberta central do Relatório de Ameaças é uma mudança em como os ataques funcionam. As ameaças mais eficazes na primeira metade de 2026 não dependeram de explorações técnicas ou engano óbvio, elas tiveram sucesso porque eram difíceis de distinguir da vida digital normal. Golpes chegaram através de uma plataforma de reserva de hotel, referenciando uma reserva real. Contas de WhatsApp foram comprometidas não através de uma violação de senha, mas ao enganar usuários para aprovarem o navegador de um cibercriminoso como um dispositivo vinculado. A fraude se moveu através de contas financeiras reais e verificadas porque as pessoas por trás daquelas contas tinham sido recrutadas através das redes sociais com ofertas de dinheiro rápido. E agentes de IA, operando com permissões que o usuário já tinha concedido, foram parados antes de executarem um shell reverso (técnica de invasão que dá o controle remoto do sistema ao cibercriminoso).

“Os ataques mais eficazes no primeiro semestre de 2026 não pareciam ataques”, afirma Vita Santrucek, Diretor de Tecnologia e Desenvolvimento na Gen. “Eles chegaram por meio de plataformas de reservas, conversas familiares em aplicativos de mensagens, canais de atualização de software e fluxos de trabalho de agentes de IA — todos ambientes nos quais as pessoas já confiam. À medida que os cibercriminosos se misturam às experiências digitais do dia a dia, a proteção precisa estar cada vez mais próxima dos momentos em que essa confiança é conquistada, explorada ou quebrada”.

 Entre golpes, violações de identidade e de privacidade, o padrão é o mesmo: o ataque se moveu para dentro de sistemas confiáveis antes que o perigo se tornasse visível.

Destaques do Relatório de Ameaças

 A telemetria da Gen do primeiro semestre de 2026 mostra a atividade de tendências nas principais áreas de ameaças ao longo dos últimos seis meses.

As principais descobertas incluem:

  • 114,2 milhões de ataques de golpes de e-shop bloqueados, aumento de 109% – destacando o risco crescente de lojas online falsas visando compradores.
  • Um aumento de 387% em golpes de personificação de governo – mostrando que criminosos estão crescentemente explorando a confiança em instituições públicas para roubar dinheiro e informações.
  • Um aumento de mais de 454% nos golpes de personificação de familiares, enquanto uma atividade separada, chamada “GhostPairing”, mostrou como o recurso de dispositivo vinculado do WhatsApp pode ser explorado para obter acesso persistente a uma conta e permitir que pessoas se passem por familiares.
  • 20,3 milhões de ataques de golpes de suporte técnico bloqueados – refletindo tentativas contínuas de enganar pessoas para darem a golpistas acesso remoto a seus dispositivos ou informações financeiras.
  • Mais de 304 milhões de impressões de anúncios de golpes identificadas através da União Europeia e do Reino Unido em menos de um mês, evidenciando o quão facilmente anúncios fraudulentos podem alcançar as pessoas.
  • Aproximadamente 1,9 bilhão de tentativas de rastreamento bloqueadas durante o primeiro semestre de 2026 – demonstrando a escala do rastreamento online que pode corroer a privacidade do consumidor.
  • Os alertas de notificação de violação de dados do Norton e do LifeLock com fontes de origem atribuídas aumentaram 628,1%, chegando a 3,3 milhões. No total, mais de 10 milhões de notificações de violação de dados foram enviadas, comprovando que as informações pessoais de um número cada vez maior de pessoas estão sendo expostas em vazamentos de dados.
  • Aumento de 734% nos alertas de atividade de contas bancárias — mais uma evidência da rápida exploração financeira que acontece após uma violação.
  • 1 milhão de ataques de web skimming bloqueados, aumento de 212% – mostrando como criminosos continuaram a visar fluxos de checkout onde usuários já esperam inserir detalhes de pagamento.
  • Mais de 15,7 milhões de registros violados contendo endereços de e-mail identificados, dando a cibercriminosos mais oportunidades para visar consumidores com phishing, golpes e tentativas de tomada de conta.

 As principais descobertas no Brasil incluem diversas categorias de golpes que registraram aumento no primeiro semestre de 2026, entre elas:

  • Golpes relacionados a apostas (+755%)
  • Golpes financeiros genéricos (+261%)
  • Golpes de suporte técnico (+93%)
  • Golpes de lojas online falsas (e-shop scams) (+62%)
  • Golpes de relacionamento (+24%)
  • Phishing (+20%)
  • A atividade de ransomware aumentou 43%
  • A atividade de exploits aumentou 31%
  • A atividade de droppers aumentou 23%
  • A atividade de infostealers: web skimming (+176%), ladrões de senhas (password stealers) (+16%) e ameaças do tipo banker (+10%).
  • O relatório também identificou uma tendência específica no Brasil: PDFs falsos de pagamento que imitavam marcas de comércio eletrônico e instituições bancárias foram utilizados para atingir o ecossistema de pagamentos via boleto.

O relatório também identifica a IA agêntica como uma fronteira de segurança emergente. À medida que os sistemas de IA ganham a capacidade de navegar, instalar softwares, acessar arquivos, conectar-se a serviços e agir em nome dos usuários, os cibercriminosos visam cada vez mais as permissões e a confiança em que esses sistemas se baseiam. A telemetria inicial do Sage, a plataforma de segurança agêntica da Gen por trás de recursos como o AI Agent Protection da Norton e Avast, revelou que os comportamentos de risco mais comuns de agentes de IA envolveram:

  1. Tentar executar comandos de sistema perigosos.
  2. Tentar abrir um canal de comando remoto, o que poderia permitir que um invasor controlasse o sistema.
  3. Baixar e executar códigos da internet.
  4. Ler arquivos de credenciais sem autorização.
  5. Tentar criar um acesso remoto persistente, como adicionar uma chave SSH confiável.
  6. Tentar anular as instruções do agente.

O Relatório completo de Ameaças do primeiro semestre de 2026 da Gen está disponível (em inglês) em: https://www.gendigital.com/blog/insights/reports/threat-report-h1-2026.

Cibersegurança: Como impedir que malware bancário roube dados financeiros do celular

Um tipo de software malicioso tem chamado a atenção de especialistas: o malware bancário. Trata-se de um programa criado para acessar e roubar dados de celulares e computadores e que dá aos criminosos o controle total do dispositivo infectado. Diferente de fraudes financeiras em que o golpista se passa por outra pessoa para pedir uma transferência, aqui o criminoso convence a vítima a instalar um software malicioso que dá acesso a aplicativos, contas bancárias, mensagens e informações pessoais, podendo, inclusive, realizar movimentações financeiras sem que a vítima perceba.

Malware bancário é um mecanismo usado para aplicar golpes digitais e acessar e roubar dados financeiros de celulares e computadores. Costuma chegar até o dispositivo das vítimas por meio de engenharia social, quando o criminoso engana a pessoa para que ela mesma realize alguma ação (como clicar em um link ou baixar um aplicativo de fonte desconhecida), acreditando que se trata de algo legítimo. Depois de instalado, o software funciona como um “espião” dentro do aparelho, transmitindo para o criminoso informações confidenciais como senhas, dados de contas e códigos de segurança.

Como criminosos aplicam golpes com o malware bancário?

Os golpes se iniciam em um contato direto, geralmente por WhatsApp. O criminoso se apresenta como um contato confiável, um representante de uma empresa conhecida, ou de um serviço que a vítima já usa ou tenha interesse. Durante a conversa, ele pede que a pessoa baixe ou atualize um aplicativo, ou até mesmo clique em um link. Em alguns casos, o golpista pode até fazer uma chamada de vídeo ou telefônica para parecer mais convincente, aumentar a sensação de segurança e acompanhar o processo em tempo real, gerando pressão e sentimento de urgência.

Depois disso, o programa malicioso é instalado no celular e o criminoso passa a interferir no funcionamento do aparelho sem que a pessoa perceba. É nesse momento em que ele aproveita para realizar ações em segundo plano, como movimentações financeiras sem autorização. Em poucos minutos, os golpistas podem realizar empréstimos, transferências e outras operações, gerando prejuízos significativos para a vítima.

Como saber se o celular foi infectado?

Alguns sinais podem indicar que há algo errado com o aparelho:

  • O celular trava ou fica lento com mais frequência;
  • A bateria acaba muito mais rápido que o normal;
  • A tela fica preta ou sem resposta por alguns momentos;
  • O dispositivo reinicia ou fecha aplicativos de forma repentina;
  • O celular esquenta de forma excessiva;
  • Mensagens são enviadas automaticamente pelo celular, sem que o usuário tenha realizado a ação;
  • Presença de aplicativos desconhecidos, com nomes genéricos ou incomuns, que a pessoa não se lembra de ter instalado;
  • Mudanças inesperadas nas configurações do celular ou nos aplicativos instalados;
  • Aplicativos solicitando permissões incomuns, como acesso a acessibilidade, mensagens ou controle do dispositivo

Além dos sinais visíveis, é importante ficar atento às permissões concedidas aos aplicativos. Alguns malwares bancários solicitam acesso aos recursos de acessibilidade do celular, uma funcionalidade criada para auxiliar usuários com necessidades específicas. Quando utilizada de forma indevida, essa permissão pode permitir que aplicativos maliciosos visualizem informações exibidas na tela e executem ações no aparelho. Por isso, desconfie sempre que um aplicativo solicitar esse tipo de acesso sem uma justificativa clara.

“Se você perceber comportamentos anormais ou sentir que perdeu o controle do seu aparelho, principalmente após clicar em links desconhecidos ou instalar aplicativos fora das lojas oficiais, o mais seguro é restaurar o dispositivo para as configurações de fábrica. Essa medida ajuda a remover aplicativos ocultos, eliminar permissões indevidas e reduzir o risco de o malware continuar ativo”, orienta Rodrigo Fernandes, Supervisor de Prevenção à Fraude da DM

Dicas para se proteger

A principal forma de prevenção é nunca seguir instruções de terceiros que envolvam a instalação de aplicativos ou o acesso ao seu dispositivo. “Não clique em links suspeitos enviados por mensagem e não baixe aplicativos fora das lojas oficiais, como App Store e Google Play. Desconfie de contatos inesperados, mesmo que pareçam conhecidos, ou feitos por números de empresas que não sejam oficialmente verificados. Além disso, não realize qualquer ação, instalação ou atualização de aplicativo seguindo instruções, nem clique em links enviados por pessoas que não são da sua confiança. E nunca conceda acesso ao seu aparelho durante uma ligação”, aponta Rodrigo Fernandes.

Caí no golpe. E agora?

Se a pessoa desconfia que caiu em um golpe, o mais importante é agir rápido. “Entre em contato com o seu banco ou com a sua instituição financeira pelos canais oficiais para informar o ocorrido e tentar bloquear movimentações. Em seguida, altere suas senhas, principalmente de aplicativos bancários e e-mail, para recuperar o controle dos acessos. Se houver suspeita de instalação de aplicativo malicioso, considere restaurar o dispositivo para as configurações de fábrica. Além disso, é recomendado registrar um boletim de ocorrência, que pode ajudar no acompanhamento do caso”, aconselha o especialista.

Camadas de segurança

Para auxiliar clientes a se prevenir contra os prejuízos causados pelos golpes, a DM conta com camadas de segurança que ajudam a proteger as transações, como:

  • Confirmação de compra: em caso de movimentações suspeitas, entramos em contato por ligação ou WhatsApp pra aprovar a transação;
  • Bloqueio temporário do cartão: o cliente pode bloquear o cartão rapidamente pelo DM App em caso de suspeita;
  • Bloqueio de pagamentos de madrugada: transações realizadas em horários ou padrões considerados fora do comum são bloqueadas;
  • Gestão de limite: o usuário pode ajustar o limite conforme o seu perfil de uso, o que ajuda a reduzir possíveis prejuízos.

Além das camadas de segurança presentes no aplicativo DM, os clientes contam com recursos adicionais de proteção, como o código de segurança dinâmico (CVC), que dificulta o uso indevido dos dados do cartão em compras online.

Hospitais cada vez mais conectados ampliam eficiência, mas também aumentam exposição a ataques cibernéticos

A transformação digital tem revolucionado a medicina. Prontuários eletrônicos, equipamentos conectados à internet, sistemas integrados de gestão e plataformas de telemedicina tornaram os hospitais mais ágeis e eficientes. No entanto, essa rápida evolução trouxe consigo um desafio crítico: o aumento exponencial da vulnerabilidade a ataques cibernéticos.

Hoje, as instituições de saúde figuram entre os alvos mais visados por criminosos digitais. Além do alto valor comercial das informações armazenadas, que incluem dados pessoais, históricos médicos e registros financeiros, esses ambientes dependem da disponibilidade ininterrupta de seus sistemas para garantir a assistência à vida. Quando ocorre um incidente cibernético, os impactos vão muito além do vazamento de dados. A indisponibilidade tecnológica pode paralisar consultas, suspender cirurgias, adiar exames laboratoriais e até comprometer o funcionamento de dispositivos médicos essenciais.

Para Flavio Cruz, da Cyrex Security, empresa especializada em cibersegurança, o setor precisa tratar a proteção digital como um pilar estratégico de continuidade operacional. “Os hospitais estão hiperconectados e essa transformação trouxe ganhos inestimáveis para a qualidade da assistência. Porém, quanto maior a conectividade, maior é a superfície de ataque. Um incidente na saúde não representa apenas prejuízo financeiro; ele afeta diretamente a ponta do atendimento e coloca vidas em risco. Por isso, investir em prevenção, monitoramento contínuo e planos de resposta a incidentes deixou de ser uma demanda exclusiva da TI e passou a ser uma necessidade de governança corporativa”, afirma o executivo.

Para mitigar esses riscos, especialistas recomendam medidas fundamentais como a segmentação de redes hospitalares, a atualização constante de softwares, o uso de autenticação multifator (MFA) e a realização de backups isolados e protegidos. Contudo, o fator humano continua sendo decisivo: treinar e capacitar os colaboradores para identificar tentativas de fraude e engenharia social é indispensável, já que esta segue como uma das principais portas de entrada para invasões.

A necessidade de amadurecer a segurança digital é respaldada por dados globais contundentes. De acordo com o relatório Cost of a Data Breach 2025, da IBM, o segmento de saúde registrou o maior custo médio por incidente entre todos os setores analisados, atingindo a marca de US$ 7,42 milhões por violação de dados. Além disso, as organizações do setor levaram, em média, 279 dias para identificar e conter um ataque, um longo período em que operações críticas podem permanecer sob ameaça.

Outro levantamento da IBM, o X-Force Threat Intelligence Index 2025, aponta que 70% dos ataques atendidos por sua equipe de resposta a incidentes tiveram como alvo organizações de infraestrutura crítica, grupo no qual os hospitais estão inseridos. Em mais de um quarto dos casos, os invasores exploraram vulnerabilidades conhecidas que poderiam ter sido corrigidas, o que reforça a urgência de auditorias e correções constantes em equipamentos e aplicações.

No Brasil, o cenário é igualmente alarmante. Hospitais, clínicas e operadoras de saúde vêm sofrendo sucessivas tentativas de ransomware e sequestro de dados nos últimos anos. “Os dados mostram que a saúde virou uma prioridade para o crime organizado digital. Quando uma instituição para devido a um ataque, estamos falando de pacientes sem acesso ao próprio histórico clínico. A cibersegurança deve caminhar lado a lado com a segurança assistencial. Afinal, investir em prevenção custa muito menos do que remediar a paralisação de uma operação hospitalar”, conclui Flávio Cruz.

Threat landscape for industrial automation systems. Q1 2026

All threats

The percentage of ICS computers on which malicious objects were blocked continued to decrease, reaching 19.6% in Q1 2026. This is the lowest value in three years, and it is 1.4 times lower than in Q2 2023.

Percentage of ICS computers on which malicious objects were blocked, Q2 2023–Q1 2026

Percentage of ICS computers on which malicious objects were blocked, Q2 2023–Q1 2026

Regionally, the percentages ranged from 9.1% in Northern Europe to 27.4% in Africa.

Regions ranked by percentage of attacked ICS computers

Regions ranked by percentage of attacked ICS computers

The percentage of ICS computers on which malicious objects were blocked increased in five regions over the quarter, most notably in Southern Europe, Northern Europe, and Russia.

In Q1 2026, Southern Europe led the way in growth for internet and email threats. The region also saw the fastest growth in spyware, as well as malicious scripts and phishing pages.

In Russia, the percentage of ICS computers on which malicious objects were blocked exceeded the figures for the previous two quarters. Russia saw an increase in the percentage for threats from the internet, and a slight increase in the figure for threats from email clients (Russia is one of three regions where this figure did not decrease).

Among the threat categories, the greatest increases were observed in the percentages for denylisted internet resources, as well as spyware (distributed in the region via the internet and email clients).

Selected industries

Biometric systems (26.4%) traditionally rank top among the industries and OT infrastructure types covered in this report in terms of the percentage of ICS computers on which malicious objects were blocked. These systems are characterized by internet access, extensive email use for data exchange and approvals (such as access granting), and, in many cases, minimal cybersecurity controls within the organizations that use these systems.

Industries ranked by the percentage of ICS computers on which malicious objects were blocked

Industries ranked by the percentage of ICS computers on which malicious objects were blocked

Biometric systems rank first among industries in terms of email threats. At the same time, unlike other industries, the percentage for email threats in biometric systems exceeds that for internet threats.

In all selected industries, the global average follows a downward trend. In Q1 2026, the percentage of ICS computers on which malicious objects were blocked increased only in the manufacturing sector — by 1.0 pp. The percentages for this industry increased across 10 regions, with the most notable increases in Western Europe, Northern Europe, and Russia.

Threat categories

In Q1 2026, Kaspersky security solutions blocked malware from 10,052 different malware families of various categories on industrial automation systems.

Over the quarter, the percentage of ICS computers on which denylisted internet resources were blocked increased (after decreasing over the previous two quarters), and there was a slight increase in the percentage for AutoCAD malware.

Percentage of ICS computers on which the activity of malicious objects from various categories was prevented

Percentage of ICS computers on which the activity of malicious objects from various categories was prevented

Malicious scripts and phishing pages (JS and HTML)

Malicious scripts and phishing pages retained their to spot among threat categories by the percentage of ICS computers on which these threats were blocked. The global average in Q1 2026 was 6.56%.

Over the quarter, the percentages increased in four regions. The most significant change was observed in Southern Europe (9.85%, +0.94 pp). The figures for malicious scripts in the region increased over three consecutive quarters.

Among the selected industries, across all regions, the highest percentages for the malicious scripts and phishing pages category were recorded for biometric systems (19.59%) and building automation (15.43%) in Southern Europe. These same industries lead in similar rankings for malicious documents and spyware.

Spyware

The percentage of ICS computers on which spyware was blocked decreased over two consecutive quarters, dropping to 3.73%. Despite the decline, spyware has ranked second among threat categories by the percentage of attacked computers for three consecutive quarters.

The percentages increased in five regions over the quarter, most notably in Southern Europe (5.46%, +0.35 pp) and Russia (2.84%, +0.24 pp).

In Southern Europe, the percentage of ICS computers on which spyware was blocked increased in all the selected industries except manufacturing. The greatest increase was observed in biometric systems.

Among the selected industries, the highest percentage of spyware in Russia was recorded in biometric systems. That said, the percentage of ICS computers on which spyware was blocked increased in all industries in the region except construction. The percentage figure has been increasing for two consecutive quarters in the oil and gas industry (by a factor of 1.63 over six months), and for three consecutive quarters in engineering and ICS integration, as well as electric power. In the remaining sectors, the values have been fluctuating.

Percentage of ICS computers on which spyware was blocked in various industries in Russia, Q3 2025–Q1 2026

Percentage of ICS computers on which spyware was blocked in various industries in Russia, Q3 2025–Q1 2026

Denylisted internet resources

The percentage of ICS computers on which denylisted internet resources were blocked increased to 3.54%.

The most notable increase over the quarter occurred in Southeast Asia (4.58%, +0.65 pp). Among the industries in the region, the highest percentage figures for this threat category were recorded in electric power and construction. Over the quarter, the largest increases in percentages figures were observed in the electric power and manufacturing industries.

In North America (Canada), denylisted internet resources (2.14%) showed the greatest increase among all categories — by a factor of 1.22.

Among the selected industries across all regions, the highest percentage figures for the denylisted internet resources category were in the electric power (7.11%) and construction (6.25%) industries in Southeast Asia.

Malicious documents (Microsoft Office + PDF)

The percentage figure for this category decreased over two consecutive quarters, reaching its lowest value (1.56%) for the entire period of observations in Q1 2026. It increased just in two regions: Australia and New Zealand (1.12%, +0.04 pp), and Russia (0.62%, +0.01 pp).

Among the selected industries across all regions, the highest percentages for malicious documents were recorded for biometric systems (9.02%) and building automation (6.97%) in Southern Europe. These same industries also lead in similar rankings for malicious scripts and spyware.

Ransomware

The percentage of ICS computers on which ransomware was blocked has decreased for two consecutive quarters, dropping to 0.14%. This is the lowest value among all categories.

The percentage increased in two regions: North America (Canada) (0.11%, +0.04 pp) and slightly in Northern Europe (0.06%, +0.01 pp).

Among the selected industries across all regions, the highest percentages for ransomware were recorded in the oil and gas and manufacturing industries (0.92% and 0.65%, respectively) in Central Asia and the South Caucasus, and in biometric systems (0.89%) in Russia.

Miners in the form of executable files for Windows

The percentage of ICS computers on which miners in the form of executable files for Windows were blocked decreased to 0.59%.

The percentage increased in seven regions. The largest increase was observed in Africa (0.63%, +0.16 pp). Among the selected industries, the largest increases in the region were in the manufacturing and oil and gas industries.

Among the selected industries across all regions, the highest percentages for miners in the form of executable files were recorded in construction (1.99%), biometric systems (1.98%), and the oil and gas industry (1.97%) in Central Asia and the South Caucasus.

Web miners

The percentage of ICS computers on which web miners were blocked has been declining for a year, and in Q1 2026, it reached the lowest value for the entire period under review (0.22%).

At the same time, the percentage increased in seven regions. The largest increases were observed in South Asia (0.28%, +0.11 pp), the Middle East (0.31%, +0.09 pp), and Africa (0.34%, +0.08 pp). Despite the increases, the percentages in these regions for Q1 2026 did not exceed those observed in 2023–2024 and in Q1 2025.

Among the selected industries across all regions, the highest percentages for web miners were recorded for biometric systems (0.97%) in Russia. Biometric systems in South Asia (0.79%) ranked second, and the electric power sector in Southeast Asia (0.76%) ranked third.

Worms

The percentage of ICS computers on which worms were blocked decreased to 1.33%.

The percentage decreased across all regions following an increase in the previous quarter (due to a wave of phishing attacks that distributed the Backdoor.MSIL.XWorm backdoor worm across all regions of the world).

Among the selected industries across all regions, the highest percentage figure for worms was recorded for biometric systems (4.80%) in Central Asia and the South Caucasus. Two industries in Africa – biometric systems (4.04%) and electric power (3.53%) – took the second and third spots, respectively.

Viruses

The percentage of ICS computers on which viruses were blocked decreased to 1.31%.

The top 3 regions by this figure remained the same: Southeast Asia (6.11%, first by a wide margin), Africa (4.15%), and East Asia (2.97%). These same regions are also among the leaders by the percentage of systems affected by AutoCAD malware. The largest increase in this figure was observed in Africa (+0.41 pp).

Among the selected industries across all regions, the highest percentages for viruses were recorded in the construction industry (6.35%) and building automation (5.50%) in Southeast Asia.

Malware for AutoCAD

The percentage of ICS computers on which malware for AutoCAD was blocked increased to 0.30%.

The most notable increase over the quarter was observed in Africa, with the region’s percentage figure rising by 0.47 pp, a very significant increase for this category, and almost doubling (to 0.91%).

Among the selected industries across all regions, the highest percentages for AutoCAD malware were recorded in the construction industry in East Asia (5.58%) and Southeast Asia (3.87%).

Main threat sources

In Q1 2026, the average percentages across all threat sources, except threats from the internet, decreased globally.

Percentage of ICS computers on which malicious objects from various sources were blocked

Percentage of ICS computers on which malicious objects from various sources were blocked

Internet

The percentage of ICS computers on which threats from the internet were blocked increased to 7.88%. However, over the past three years, the percentage figure for internet threats has followed a downward trend.

The largest increases in the percentages were recorded in Southern Europe (8.59%, +0.59 pp), Southeast Asia (10.16%, +0.55 pp), and Northern Europe (4.47%, +0.51 pp).

Among the selected industries across all regions, the highest percentages for threats from the internet were recorded in electric power (13.16%) and construction (12.55%) in Southeast Asia, and in the engineering and ICS integration sector (12.33%) in South Asia.

Email clients

The percentage of ICS computers on which threats delivered via email clients were blocked decreased to 2.59%. This is a three-year low.

The percentage of this threat source increased in three regions: Southern Europe (6.54%, +0.2 pp), East Asia (1.5%, +0.09 pp), and slightly in Russia (0.7%, +0.04 pp).

Among the selected industries across all regions, the highest percentages for email threats were recorded for biometric systems (19.78%) and building automation (12.34%) in Southern Europe. In these two industries, the percentage of ICS computers on which email threats are blocked is higher than the percentage for threats from the internet. A similar situation was observed in two other instances, both in biometric systems (in South America and Southeast Asia).

Removable media

The percentage of ICS computers on which threats were detected when connecting removable media continued to decrease, reaching its lowest value for the period under review (0.26%).

Among the selected industries across all regions, the highest percentages for removable media threats blocked on ICS computers were observed in the electric power sector in Central Asia and the South Caucasus (1.45%), East Asia (1.34%), and Africa (1.16%).

Network folders

The percentage of ICS computers on which threats are blocked in network folders is steadily decreasing. In Q1 2026, it was the lowest for the period under review (0.029%).

East Asia has traditionally led by a wide margin. The percentage for East Asia (0.135%) is 27 times higher than the lowest regional value (recorded in Northern Europe).

The largest increases in the percentages for threats from network folders were observed in Africa (0.037%, +0.006 pp) and South America (0.013%, +0.006 pp).
Among the selected industries across all regions, the construction industry in East Asia, at 0.36%, holds the top positions in the ranking by the percentage of ICS computers on which threats are blocked in network folders.

For more information on industrial threats see the full version of the report.

Relatório Executivo de Inteligência Cibernética – Vazamento de Dados do domínio gov.il pertence oficialmente ao Governo do Estado de Israel

O IDCiber Threat Intelligence Center, por meio do monitoramento contínuo de fontes abertas, fóruns clandestinos e canais especializados, identificou a divulgação de uma alegada base de dados associada ao domínio governamental www.gov.il, anunciada por um ator de ameaça em 22/06/2025. Segundo a publicação analisada, o grupo afirma ter explorado uma vulnerabilidade de API e obtido acesso não autorizado a informações de aproximadamente 268.938 registros de cidadãos, contendo dados pessoais diversos. As evidências observadas incluem amostras de registros supostamente extraídos da base comprometida e disponibilizados em plataforma pública de compartilhamento de conteúdo. Em conformidade com as melhores práticas de proteção à privacidade, os dados pessoais identificáveis (PII) presentes nas amostras foram anonimizados nesta análise, não sendo reproduzidos nomes, documentos, telefones, endereços, e-mails, identificadores ou quaisquer informações que permitam a identificação direta de indivíduos.

IDCiber Threat Intelligence Center
IDCiber Threat Intelligence Center

A análise preliminar indica que o conjunto de informações alegadamente exposto contém categorias de dados de elevada sensibilidade, incluindo dados cadastrais, informações demográficas, informações de contato, dados de localização e outros atributos pessoais. Caso a autenticidade e atualidade da base sejam confirmadas pelas autoridades competentes, o incidente poderá representar riscos significativos de fraude, engenharia social, campanhas de phishing direcionado, roubo de identidade, comprometimento de contas e outras atividades criminosas. O anúncio também demonstra intenção de monetização dos dados por parte do ator de ameaça, que disponibilizou canal de contato para potenciais interessados na aquisição do conteúdo.

Até o momento da análise, as evidências observadas permitem confirmar a existência de uma publicação reivindicando a violação e exibindo amostras de registros, porém a validação integral da autenticidade, integridade, abrangência e origem dos dados requer investigação técnica complementar pelas entidades responsáveis. Considerando o potencial impacto sobre cidadãos e organizações governamentais, recomenda-se a realização de procedimentos de resposta a incidentes, validação dos dados expostos, revisão dos controles de acesso, análise de vulnerabilidades em APIs, monitoramento reforçado de credenciais e comunicação adequada às partes potencialmente afetadas.

IDCiber Threat Intelligence Center
IDCiber Threat Intelligence Center
  • Classificação do incidente: Vazamento de Dados (Data Breach)
  • Organização alvo: Domínio governamental (www.gov.il)
  • Data da divulgação identificada: 22/06/2025
  • Volume alegado de impacto: 268.938 registros
  • Tipo de informação exposta: Dados pessoais e cadastrais (PII) – informações anonimizadas neste relatório
  • Severidade estimada: Alta
  • Status: Publicação identificada e em monitoramento

Fonte: IDCiber Threat Intelligence Center.

❌