🚨 Funky Mantis (DevMan) has evolved from a file-encryption toolkit into a full ransomware-as-a-service (RaaS) platform. Affiliates can build ransomware, buy network access, negotiate with victims, and manage attacks through a central web panel. #CyberSecurity #ransomeware #FunkyMantis
MalWhere?
@malwhere.bsky.social
👨💻APT Insights 🕵️♂️Tracking Cyber-Espionage Threats 💻Uncovering the Dark Side of the Digital World 👇Latest Threat Analysis & Updates https://malwhere.substack.com/
🚨 OpenAI has disclosed an unprecedented AI security incident after an experimental ChatGPT model escaped its testing sandbox and autonomously hacked AI platform during a cyber capability evaluation. The model reportedly sought benchmark answers by exploiting vulnerabilities. #CyberSecurity #AI
Post 1/2 🚨 Healthcare software firm Craneware has disclosed a cyberattack that resulted in unauthorized access and data exfiltration. Investigators confirmed employee data and subset of customer and partner records were accessed. #CyberSecurity #DataBreach #CraneWare
🚨 Researchers have documented what may be the first ransomware attack conducted entirely by an autonomous AI agent. #JadePuffer exploited a Langflow vulnerability, then autonomously performed reconnaissance, credential theft, privilege escalation and lateral movement. #CyberSecurity #AI #ThreatIntel
🚨 Operation DragonReturn is a suspected China-linked phishing campaign targeting Indian taxpayers, accountants, and finance teams. Victims receive fake Income Tax Department emails designed to deliver malware disguised as official tax software. #CyberSecurity #ThreatIntel #Phishing #DragonReturn
🚨 A threat actor is allegedly selling a 7GB intelligence package linked to Chinese firm ZRON, claiming it contains malware, surveillance tools, intelligence reports, and operational documentation spanning Asia, Europe, the Americas, and Eurasia. #CyberSecurity #ThreatIntel #ZRON #China #Leaks
🚨 Leaked documents show Japan's Ground Self-Defense Force unknowingly used counterfeit USB drives infected with malware. The devices, reportedly linked to a Chinese cyber operation, were connected to 50+ military systems, including those handling classified data. #CyberSecurity #ThreatIntel #USB
Post 1/3 🚨 New Windows Defender flaw CVE-2026-50656 ("RoguePlanet") has a public PoC exploit before a patch is available. The bug exploits a race condition in Defender and can lead to SYSTEM-level privilege escalation on Windows 10 & 11. #CyberSecurity #Windows #ThreatIntel #RougePlanet
Post 1/3 Chinese-linked APT Earth Lusca (Aquatic Panda)has expanded its SprySOCKS malware from Linux to Windows, targeting government organizations in Taiwan, Thailand, Pakistan, and Honduras. The move significantly broadens its cyber-espionage reach. #CyberSecurity #APT #ThreatIntel #aquaticpanda
🚨 A new npm supply-chain attack has infected 36 packages with IronWorm, a Rust-based infostealer targeting developer environments. The malware hunts for AWS, OpenAI, Anthropic, npm credentials, SSH keys, crypto wallets, and other sensitive secrets. #CyberSecurity #SupplyChainAttack #npm
🚨FrostyNeighbor, a Belarus-aligned APT, is escalating cyber-espionage ops across Eastern Europe—targeting Ukraine’s government, military, and critical sectors with spearphishing, exploits, and evolving malware chains. #CyberSecurity #APT #ThreatIntel #FrostyNeighbour #Belarus
🚨As energy markets shift, cyber espionage is following. A China-linked APT, FamousSparrow, has targeted an oil & gas firm in Azerbaijan—marking a rare move into a region traditionally dominated by Russian cyber activity. #CyberSecurity #APT #ThreatIntel #FamousSparrow #China
open.substack.com/pub/malwhere... New Post!! #Sanctions #China #Russia #NorthKorea #Iran #Cybersecurity #Cyber
Shadow Networks: The Top 10 Sanctioned Companies Powering Cyber Operations for China, Russia, North Korea, and Iran
The modern cyber battlefield is no longer dominated solely by anonymous hackers operating in dark basements.
open.substack.com
🚨Iran-linked MuddyWater hackers masked a cyber-espionage campaign as a Chaos ransomware attack. Using Microsoft Teams social engineering, they gained access, stole credentials, and established persistence—blurring the line between APT and cybercrime. #CyberSecurity #MuddyWater #ThreatIntel #Iran
🚨APT37 (aka ScarCruft/Ricochet Chollima) is pushing a new campaign—this time weaponizing a video game platform. Their known “BirdCall” backdoor now has an Android variant, turning trojanized apps into full-fledged spyware. #CyberSecurity #APT37 #Malware
🚨Threat group UNC6692 uses email bombing + fake IT helpdesk calls via Microsoft Teams to deploy “Snow” malware. Victims install a fake patch that drops a malicious extension for data theft after credential compromise. #CyberSecurity #Infosec #Malware #Snow #Microsoft
🚨CISA flags 4 exploited Microsoft bugs—including a 14-year-old “zombie” flaw still used in attacks. Agencies have 2 weeks to patch. Old vulnerabilities remain active threats. #CyberSecurity #Infosec #zombiebugs #microsoft #CVE
🚨Rockstar confirms a breach via a third-party flaw, with no player data impacted. ShinyHunters claims access and issues an extortion deadline. Stolen data likely includes internal corporate intel. #GTAV #SHINYHUNTERS #DATABREACH
🚨A new Lua-based malware, LucidRook, is targeting NGOs and universities in Taiwan via spear-phishing. Attributed to UAT-10362, a capable threat actor, the campaign uses password-protected archives and decoy government-themed lures to initiate infection. #malware #APT #cybersecurity
New Article #i-Soon #Topsec #Knownsec #BJIT #Geedge #NSCC #Venustech #GoLaxy open.substack.com/pub/malwhere...
The Contractor Leaks: Mapping China’s Cyber-Espionage Industry One Breach at a Time
For years, China’s cyber operations were attributed to shadowy APT names—clusters of activity without clear structure.
open.substack.com
🚨 North Korean-linked “Contagious Interview” campaign (WaterPlum) is using malicious VS Code projects to deploy StoatWaffle malware. Auto-executing tasks.json files trigger payloads when opened, marking a new tactic targeting developers. #CyberSecurity #ThreatIntel #NorthKorea #Malware
🚨 Reports of a potential Crunchyroll data breach claim ~100GB of user data was exfiltrated via a third-party vendor. The alleged March 2026 incident may involve emails, IPs, passwords, and payment data, raising concerns across the anime streaming community. #CyberSecurity #DataBreach #Crunchyroll
🚨 IBM X-Force uncovered “Slopoly,” likely AI-generated malware used by ransomware group Hive0163. The strain appeared in a live attack, signaling a shift as threat actors leverage AI to rapidly build tools and scale operations at lower cost. #CyberSecurity #Ransomware #AI #ThreatIntel #Slopoly
🚨China–Costa Rica tensions rise after Costa Rica linked an ICE cyberattack to suspected PRC-linked group UNC2814. Beijing denies involvement and demands technical evidence, turning the incident from a cyber investigation into a diplomatic dispute. #CyberSecurity #CyberEspionage #China #CostaRica
🚨 APT group “Silver Dragon” targeting Europe & Southeast Asia since mid-2024. Linked to the APT41 umbrella, the China-nexus threat actor focuses mainly on government entities, using server exploits and phishing to gain initial access. #APT #CyberEspionage #ThreatIntel #CyberSecurity
🚨 Snail-mail phishing targets crypto hardware wallet users. Fake letters posing as Trezor & Ledger claim mandatory “Authentication” or “Transaction” checks. Victims are pressured to scan QR codes tied to recovery-phrase theft campaigns. #Crypto #Phishing #HardwareWallet #CyberSecurity
🚨 Researchers uncovered OysterLoader, a stealthy multi-stage loader powering Rhysida ransomware attacks. Active since 2024, it spreads via fake downloads of PuTTY, WinSCP & AI tools, deploying malware through signed MSI files. A major enterprise threat. #CyberSecurity #Malware #ThreatIntel
🚨 DPRK-linked actors are infiltrating global firms via LinkedIn, posing as legit remote job candidates. Tracked as Jasper Sleet & Wagemole, the campaign funds weapons programs + enables espionage. Verified emails & badges boost credibility. #CyberSecurity #DPRK #ThreatIntel #LinkedIn #jaspersleet
🚨Mustang Panda has rolled out a new CoolClient variant with browser credential theft and clipboard monitoring. Kaspersky links it to targeted espionage via trusted software and multi-stage loaders, signaling an evolution in China-aligned tradecraft. #APT #China #CyberEspionage #MUSTANGPANDA