Threat Actors Adapting Android Droppers Even to Deploy Simple Malware to Stay Future-Proof

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android droppers have evolved from niche installers for heavyweight banking Trojans into universal delivery frameworks, capable of deploying even rudimentary spyware or SMS stealers. Initially, droppers served banking malware families that required elevated Accessibility permissions to harvest credentials. These small …

Chinese UNC6384 Hackers Leverages Valid Code Signing Certificates to Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A stealthy espionage campaign emerged in early 2025 targeting diplomats and government entities in Southeast Asia and beyond. At the heart of this operation lies STATICPLUGIN, a downloader meticulously disguised as a legitimate Adobe plugin update. Victims encountered a captive …

CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued a critical alert regarding three newly identified vulnerabilities being actively exploited by threat actors. On August 25, 2025, CISA added these high-risk Common Vulnerabilities and Exposures (CVEs) to its Known Exploited Vulnerabilities (KEV) Catalog, signaling immediate concern …

Hackers Actively Scanning to Exploit Microsoft Remote Desktop Protocol Services From 30,000+ IPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with threat actors deploying over 30,000 unique IP addresses to probe for vulnerabilities in Microsoft RD Web Access and RDP Web Client authentication portals.  The campaign represents one …

Hackers Sabotage Iranian Ships Using Maritime Communications Terminals in Its MySQL Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated campaign of cyber sabotage unfolded against Iran’s maritime communications infrastructure in late August 2025, cutting off dozens of vessels from vital satellite links and navigation aids. Rather than targeting each ship individually—a logistical nightmare across international waters—the attackers …

Proxyware Malware Mimic as YouTube Video Download Site Delivers Malicious Javascripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have observed a surge in deceptive sites masquerading as YouTube video download services to deliver Proxyware malware in recent weeks. Victims seeking to grab videos in MP4 format are redirected through ad pages that sporadically present a download …

Hackers Using PUP Advertisements to Silently Drop Windows Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent weeks, cybersecurity investigators have uncovered a novel campaign in which hackers leverage seemingly benign potentially unwanted program (PUP) advertisements to deliver stealthy Windows malware. The lure typically begins with ads promoting free PDF tools or desktop assistants that …

Chinese APT Hackers Using Proxy and VPN Service to Anonymize Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, cybersecurity researchers have observed a surge in targeted campaigns by a sophisticated Chinese APT group leveraging commercial proxy and VPN services to mask their attack infrastructure. The emergence of this tactic coincides with a broader shift toward …

New Android Spyware Disguised as an Antivirus Attacking Business Executives

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security teams have observed the emergence of a highly versatile Android backdoor, Android.Backdoor.916.origin, masquerading as a legitimate antivirus application. Distributed via private messaging services under the guise of “GuardCB,” its icon closely mimics the emblem of the …

Kimsuky APT Data Leak – GPKI Certificates, Rootkits and Cobalt Strike Personal Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In late June 2025, a significant operational dump from North Korea’s Kimsuky APT group surfaced on a dark-web forum, exposing virtual machine images, VPS infrastructure, customized malware and thousands of stolen credentials. This leak offers an unprecedented window into the …