• Russian hackers are using a new remote access toolkit called “CTRL” to silently hijack Remote Desktop Protocol (RDP) sessions via FRP-based reverse tunnels, enabling stealthy, hands-on access to compromised Windows systems. The toolkit blends credential theft, keylogging, and RDP abuse into a cohesive post-exploitation framework that currently flies under the radar of public malware scanners […]

    The post Russian Hackers Deploy “CTRL” for RDP Hijacking appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There’s a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A dark web market known as Threat Market is listing 375TB of Lockheed Martin data, which it claims was provided by a group calling itself ‘APT Iran.’

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A fully operational TheGentlemen ransomware toolkit on an exposed server, revealing victim credentials, ngrok tokens, and a complete pre-encryption playbook. This led them to an unauthenticated HTTP server at 176.120.22[.]127:80, hosted by Russian bulletproof provider Proton66 OOO, exposing 126 files across 18 subdirectories and about 140 MB of data. Proton66 has previously been tied to […]

    The post Exposed Server Leaks TheGentlemen Ransomware Toolkit, Credentials, and Ngrok Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A recent investigation as exposed how a suspected North Korean IT worker allegedly used a stolen identity, AI-generated resume content, and scripted interview answers to try to secure a senior remote role at U.S.-based threat intelligence firm Nisos. The case highlights how DPRK IT employment schemes are evolving by combining traditional fraud with modern AI […]

    The post North Korean IT Worker Used Stolen Identity, AI-Generated Resume in Job Scam appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • What is really slowing Tier 1 down: the threat itself or the process around it? In many SOCs, the biggest delays do not come from the threat alone. They come from fragmented workflows, manual triage steps, and limited visibility early in the investigation. Fixing those process gaps can help Tier 1 move faster, reduce unnecessary escalations, and improve how the entire SOC responds under pressure

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CrySome RAT is a newly observed, advanced .NET remote access trojan that combines full‑featured post‑exploitation tooling with unusually hardened persistence, AV-killing, and anti‑removal logic, making it a serious long‑term threat to Windows environments. The client component (Crysome.Client.exe) communicates with a TCP‑based C2 operated by CrySome.Server.exe, with debug logging falling back to a Crysome_debug.log path if […]

    The post CrySome RAT: Stealthy .NET Malware Adds AV Killer, HVNC Features appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Starting April 1, 2026, the Indian government will officially enforce a nationwide ban on the sale of internet-connected CCTV cameras from major Chinese manufacturers, including Hikvision, Dahua, and TP-Link. This decisive market restriction is fundamentally driven by escalating national security concerns. Officials aim to eliminate inherent hardware vulnerabilities that could potentially enable foreign espionage operations […]

    The post India Set to Ban Hikvision, TP-Link Devices in April appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • In his 2025 book, AI, Automation, and War, Anthony King implores the reader to understand artificial intelligence as a phenomenon most closely related to organizational structure: "It is vital that we recognise and try to understand this military-tech complex, especially since…so much of the literature has fetishized AI as a technology, ignoring its organisational aspects."

    To understand how AI is being used in the war on Iran, we must understand where Anthropic’s Claude sits in the larger targeting system called Maven—and how the Pentagon's quest for faster AI deployment threatens to overwhelm its planners' ability to validate relevant data.

    Maven, evolved

    After the U.S. military captured Venezuelan President Nicolás Maduro, reports indicated that Pentagon leaders had planned the mission with AI tools made by Anthropic, including the Claude chatbot. Similar reports have emerged since the U.S. and Israel began striking Iran on Feb. 28; the Washington Post, for example, reported that “AI tools are helping gather intelligence, pick targets, plan bombing missions and assess battle damage at speeds not previously possible.”

    Questions about AI deepened after a Tomahawk missile killed 175 people at a girl’s school in Minab, Iran. Week in Worcester quoted a DOD logistics programmer who said that the department had increased its use of “a Claude-based system over the past year, integrating it with many core operational decisions.”

    But this is not quite the right way to understand Claude’s role at U.S. Central Command. 

    The Anthropic chatbot is part of the larger Maven Smart System, which descends from the 2010s-era Project Maven. Google designed Maven to help analysts glean insights from oceans of video data. But the Silicon Valley titan withdrew in 2018, spurred by employees wary of helping the Pentagon. Work on Maven was taken over by Palantir, which in September 2024 announced a new contract from the DEVCOM Army Research Laboratory to improve its Maven Smart System. The contract, which is potentially worth nearly $100 million over five years, has evidently enabled Palantir to expand Maven’s functions.

    Conceptualization of Palantir’s Maven Smart System by Jorge Morejon / Forecast International

    Today’s Maven can be understood as a system of sub-components. Some are functional: command-and-control, target intelligence, battle damage assessment, and so forth. Others are bespoke AI models, designed, say, to detect objects in geospatial intelligence. Ultimately, Maven performs three core functions: it generates targets, matches munitions with targets, and assesses strike damage. 

    To generate targets, for example, Maven cross-references a mix of open-source and closed-source information (think: DIA’s military databases) to identify potential targets, before and during a conflict. The closed-source data is likely the military’s classified data. The value of open-source data probably grows after the conflict begins; it might include social media with hints about enemy forces’ disposition and movement.

    Claude appears to be an add-on to Maven, not a necessary component, for two reasons. First, the parts of Maven that do battle damage assessments and data fusion and so forth predate all LLMs, let alone Claude. And Palantir’s Artificial Intelligence Platform, or AIP, was making certain AI models accessible before Claude was even integrated with DOD classified networks. And second, Claude does not directly provide targeting recommendations, but rather—according to Joshi—helps synchronize other modules and AI models. It can be thought of as a sophisticated interface that simplifies the tasks of the human operator.

    How the military plans

    To understand how Maven is used in the military’s targeting process, we must understand the process itself. As described by The Economist’s Shashank Joshi, it runs like this:

    1. A commander requests options for targeting in specific scenarios.
    2. An intelligence directorate uses satellite imagery, signals intelligence, and other sources to build a database of thousands of possible targets—and “no strike” lists of buildings like schools.
    3. A “weaponeer” matches targets with available munitions.
    4. A lawyer informs the commander of the consequences of various strikes.
    5. The Strategy and Plans Directorate converts the database into a war plan.
    6. Operations uses the war plan’s guidance to produce air tasking orders for operational units.

    Maven’s usefulness might be described as compressing at least some of these stages of target acquisition. DOD policy still requires that all targets be selected by humans, but CENTCOM’s Adm. Charles Cooper said that his planners have found that AI can help them do days or hours of work in seconds. This helps U.S. forces move more quickly than enemies can react. 

    But the accidental strike on the girls’ school indicates that Maven enables the targeting process to move more swiftly than humans can validate the steps from target generation to selection. The Pentagon’s preliminary investigation found that the school building used to be part of an adjacent Iranian military base, but was “fenced off” sometime between 2013 and 2016, according to a New York Times report. The Defense Intelligence Agency apparently missed that change, and the school was consequently designated a target.

    The apparent failure of CENTCOM to validate the data provided to it by DIA means that the speed of target acquisition overwhelmed the ability to verify targets with the National Geospatial-Intelligence Agency’s data. (This trend is even more prominent in the Israel Defense Forces.) And it also suggests that Anthropic CEO Dario Amodei’s emphasis on reliability in decisions to use lethal force is not a sufficient framing to understand DOD’s disposition.)

    This problem is not new, as Kevin Baker details in The Guardian. Efforts to generate targets faster than one’s adversary can respond date, at least, to the Vietnam War and the Cold War’s nuclear-deterrence doctrines. The use of defense technologies like Maven today should be understood as a prioritization of tactics over strategy – “operational excellence,” as Joshi notes, but without a “causal mechanism” that links targets with overarching war aims. 

    Maven is soon to become a DOD program of record. By April 8, it is to be transferred from the National Geospatial-Intelligence Agency to the Chief Digital Artificial Intelligence Office, per a March 9 letter from Deputy Secretary of Defense Steve Feinberg. The move is intended to allow the Pentagon to fund and further entrench the system over longer stretches of time.

    Defense suppliers should note DOD’s new demand for technologies that can serve systems like Maven; it shows that at least some portions of the AI Acceleration Strategy are being executed in earnest. How the Pentagon reacts to this new wrinkle in the decades-old problem of technology outracing human checks remains to be seen.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new variant of the ClickFix attack technique that shifts execution away from commonly monitored tools like PowerShell and mshta, instead abusing native Windows components such as rundll32.exe and WebDAV. This evolution allows attackers to bypass traditional script-based detection mechanisms, increasing the likelihood of a successful, stealthy compromise. The attack begins similarly to earlier ClickFix […]

    The post ClickFix Evades PowerShell Detection via Rundll32 and WebDAV appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶