« 2025 »

778 reports

2025-03-24
Rekt
#Zoth
2025-03-27 • pcaversaccio

Paolo Caversaccio analyzed `1inch-analysis.app`, a malicious macOS bundle sent to 1inch cofounder Anton Bukov by the fake security researcher persona Nick L. Franklin. The source attributes the incident with high confidence to the AppleJeus/Citrine Sleet/…

#CitrineSleet
2025-03-26 • ESET

ESET profiles RansomHub as the dominant ransomware-as-a-service group that rose after law-enforcement disruption of LockBit and BlackCat. The research links RansomHub activity to tooling trails associated with Play, Medusa, and BianLian affiliates and doc…

#Andariel #Play
2025-03-24 • Security Alliance

SEAL tracks ELUSIVE COMET as an active threat to cryptocurrency users, using carefully built personas and entities such as Aureon Capital, Aureon Press, and The OnChain Podcast to appear legitimate. The actor initiates contact through Twitter DMs or email…

#ElusiveComet
2025-03-24 • Rekt

Zoth lost about $8.4 million after an attacker used compromised admin privileges to upgrade the USD0PPSubVaultUpgradeable proxy contract and drain funds. The attack withdrew 8.85 million USD0++ tokens, converted them to DAI, and transferred the proceeds a…

#Zoth
2025-03-22 • Chollima Group

Chollima Group found an exposed Google Drive folder tied to a North Korean IT worker that contained identity documents, resumes, payment records, notes and IP Messenger chat logs from late 2022 to early 2023. The logs show roughly 500 direct messages acro…

#ITWorker
2025-03-20 • Hauri

APT37 activity is described using malicious LNK files disguised as Microsoft Store update content to trigger infection. When executed, the LNK drops a decoy document and batch file, changes the shortcut into an HTML file, and uses obfuscated code to retri…

#APT37 #LNK