Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese-linked advanced persistent threat group known as Camaro Dragon launched a targeted cyberespionage campaign against entities in Qatar just one day after the outbreak of new hostilities in the Middle East on March 1, 2026. The group used war-themed …

GhostClaw Mimic as OpenClaw to Steal Everything from Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous malware campaign targeting software developers has surfaced, with a rogue npm package posing as a trusted developer tool to silently drain credentials, crypto wallets, SSH keys, browser sessions, and even iMessage conversations. The package, published under the name @openclaw-ai/openclawai, …

ScamAgent- AI Agent Built by Researchers that Run Fully Autonomous Scam Calls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ScamAgent is an autonomous, multi-turn AI framework developed by researcher Sanket Badhe at Rutgers University that demonstrates how large language models (LLMs) can be weaponized to conduct fully automated scam calls. By integrating goal-driven planning, contextual memory, and real-time text-to-speech …

Hackers Attack Employees Over Microsoft Teams to Trick Them Into Granting Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers Attack Over Microsoft Teams A social-engineering campaign abusing Microsoft Teams and Windows Quick Assist is evolving again, with BlueVoyant warning that the attackers are now deploying a newly identified malware family called A0Backdoor after convincing employees to hand over …

Hackers Use Fake CleanMyMac Site to Deploy SHub Stealer and Hijack Crypto Wallets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A convincing fake website posing as the popular Mac utility CleanMyMac is actively pushing dangerous macOS malware called SHub Stealer onto unsuspecting users. The site, hosted at cleanmymacos[.]org, has no connection to the real CleanMyMac software or its developers, MacPaw. …

BoryptGrab Stealer Spreads via Fake GitHub Repositories, Stealing Browser and Crypto Wallet Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new data-stealing malware called BoryptGrab has been quietly spreading across Windows systems through a network of fake GitHub repositories, tricking users into downloading what appear to be popular free software tools. The campaign, which has been active since at …

Iran-Linked Hackers Target U.S. Critical Infrastructure Amid Rising Cyber Threat Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Iranian advanced persistent threat group known as Seedworm — also tracked as MuddyWater, Temp Zagros, and Static Kitten — has been found actively operating inside the networks of multiple U.S. organizations since early February 2026, raising serious alarms across …

MaaS VIP Keylogger Campaign Uses Steganography and In-Memory Execution to Steal Credentials at Scale

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated credential-stealing campaign built around a tool called VIP Keylogger has emerged as a serious threat to organizations and individuals. Unlike conventional malware that drops files onto a victim’s hard drive, this keylogger runs entirely in memory, making it …

Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Signal has officially confirmed an ongoing wave of targeted phishing campaigns resulting in successful account takeovers for high-profile users, including journalists and government officials. The encrypted messaging service explicitly stated that its core infrastructure and end-to-end encryption protocols remain intact …

Vietnam-Based Cybercrime Network Enables Fraudulent Account Signups at Scale

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sprawling cybercrime ecosystem rooted in Vietnam has been linked to large-scale fraudulent account registration campaigns targeting service providers and online platforms worldwide. Researchers traced this activity to an infrastructure cluster internally designated O-UNC-036, which uses disposable email addresses and …