« Reports in 2025 »

792 reports

2025-01-29 • Google

Google Threat Intelligence Group examined how government-backed APT and information-operations actors attempted to use Gemini for operational support. The source says actors used the tool mainly for research, troubleshooting, content generation, localizat…

#APT43 #ITWorker
2025-01-24 • Nurilab

NuriLab analyzes Maui ransomware, a file-encryption malware family reported in U.S. advisories as affecting public health and healthcare organizations since 2021. The report says Maui likely spread through X-PopUp, an open-source messenger used by small a…

#Maui
2025-01-24 • KRCERT

KISA analyzes four malware types attributed to Lazarus activity observed in 2024 incidents affecting South Korean private-sector organizations, including IT companies and a major media company. The first type uses DLL side-loading, MachineGuid-based CRC32…

#Lazarus
2025-01-24 • Rekt

Rekt News describes a January 2025 compromise of Phemex hot wallets that drained roughly $73 million across more than a dozen blockchains. The attacker moved through wallets on Ethereum, Solana, XRP, Bitcoin, BSC, Sui, Base, Tron, Litecoin, Avalanche, Arb…

#Cryptocurrency #Phemex
2025-01-23 • USFBI

The FBI warned that North Korean IT workers have expanded beyond revenue generation into data theft and extortion against U.S. businesses. Recent cases include workers using unlawful network access to exfiltrate proprietary data and code, copy repositorie…

#ITWorker