• A new remote access trojan called Atroposia has emerged as one of the most concerning threats in the cybercriminal underground, offering an unprecedented combination of stealth capabilities and attack features.

    This modular malware operates as a turnkey criminal toolkit designed specifically to lower the technical barrier for threat actors of varying skill levels.

    Priced aggressively at approximately $200 monthly or $900 for six months, Atroposia democratizes sophisticated cyberattacks in ways previously reserved for advanced persistent threat groups.

    Atroposia portal (Source – Varonis)

    The malware represents a troubling trend in how modern cybercriminals bundle multiple offensive capabilities into user-friendly platforms.

    Similar to contemporaneous tools like SpamGPT and MatrixPDF, Atroposia packages hidden remote desktop takeover, credential harvesting, cryptocurrency wallet theft, DNS hijacking, and vulnerability scanning alongside encrypted command-and-control communications.

    Its intuitive control panel and plugin builder architecture mean even operators with minimal technical expertise can orchestrate complex intrusions against enterprise environments.

    The threat landscape shifted notably when Varonis researchers identified Atroposia circulating across underground forums.

    Varonis analysts noted the malware automatically escalates privileges through User Access Control bypass mechanisms and installs multiple persistence techniques to maintain access across system reboots.

    These capabilities allow attackers to blend seamlessly into compromised systems, evade antivirus software, and maintain long-term presence without triggering security alerts.

    Hidden Remote Desktop Access and System Persistence

    Atroposia’s most insidious feature centers on its hidden remote desktop protocol implementation, branded as HRDP Connect.

    Atroposia key features (Source – Varonis)

    This functionality spawns covert desktop sessions in the background, creating invisible shadow logins that grant attackers complete system interaction capabilities.

    When attackers exploit this feature, victims see no on-screen indication of remote control, allowing intruders to surveil activities, access sensitive documents, manipulate workflows, and piggyback on authenticated sessions without detection.

    The legitimate user remains entirely unaware of the intrusion occurring in real time.

    The hidden RDP capability bypasses traditional remote access monitoring systems since it doesn’t generate standard remote desktop notifications or logged-in user prompts.

    Attackers can conduct espionage and data theft activities while operating under the guise of legitimate user sessions.

    Combined with Atroposia’s dedicated file manager providing complete remote file system access, operators can exfiltrate sensitive data through fileless techniques that minimize on-disk footprints and evade data loss prevention systems.

    The malware’s Grabber module can automatically hunt files by extension or keyword, compress them into password-protected archives, and extract data entirely in memory, leaving minimal forensic traces.

    The emergence of Atroposia exemplifies how cybercrime continues evolving into a service industry where sophisticated attack capabilities no longer depend on threat actor expertise but rather financial access and market availability.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post New Atroposia RAT with Stealthy Remote Desktop, Vulnerability Scanner and Persistence Mechanisms appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The campaign leverages judicial document themes to distribute Hijackloader malware, which subsequently deploys PureHVNC remote access trojan (RAT)—marking the first observed instance where this combination has been used against Spanish-speaking users in Latin America. The campaign represents a significant tactical shift for threat actors operating in the region. Hijackloader, previously documented in campaigns targeting CrowdStrike […]

    The post PureHVNC RAT Distributed via Weaponized Judicial Documents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat intelligence researchers have identified a new ransomware-as-a-service (RaaS) operation called The Gentlemen’s RaaS, being actively recruited on underground hacking forums by an operator using the handle zeta88. The cross-platform threat represents a significant evolution in ransomware capabilities, offering attackers specialized encryption lockers for Windows, Linux, and ESXi systems coded in both Go and C […]

    The post New ‘Gentlemen’ RaaS Appears on Hacking Forums, Targeting Windows, Linux and ESXi appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Google has announced a significant security initiative that will fundamentally change how Chrome handles unsecured web connections.

    Beginning with Chrome 154’s release in October 2026, the browser will enable the “Always Use Secure Connections” feature by default, requiring users to approve access to any public website lacking HTTPS encryption before proceeding.

    This strategic shift represents a critical advancement in browser security, addressing a persistent vulnerability that attackers continue to exploit.

    Despite over a decade of progress toward universal HTTPS adoption, approximately 95 to 99 percent of Chrome navigations now use secure connections, leaving a small but significant percentage of traffic exposed to interception and manipulation attacks. The danger of unencrypted HTTP connections extends beyond mere data exposure.

    Understanding the Security Threat

    Attackers positioned between users and websites, known as man-in-the-middle actors, can hijack HTTP navigations entirely, redirecting users to malicious resources without detection.

    This method of attack has proven highly effective in real-world scenarios, with documented cases of commercial surveillance vendors and state-sponsored threat actors using HTTP interception to deliver zero-day exploits and compromise targeted devices.

    Unlike HTTPS sites that display “Not Secure” warnings, many HTTP sites immediately redirect to HTTPS, rendering the user completely unaware that an attack opportunity existed.

    setting warns users before accessing a site without HTTPS
    Setting warns users before accessing a site without HTTPS

    The Chrome Security team states that any unencrypted navigation, even at a small percentage, poses a potential risk to attackers.

     Because these threats are not theoretical but actively exploited through readily available interception tools, the security implications justify aggressive mitigation strategies.

    Google’s rollout strategy demonstrates careful consideration of user experience and the complexities of real-world deployment.

    In April 2026, Chrome 147 will enable the feature exclusively for the over one billion users who have voluntarily opted into Enhanced Safe Browsing protections.

    This initial phase provides a testing environment to validate warning frequency and user behavior before broader deployment.

    HTTPS adoption expressed as a percentage of main frame page loads
    HTTPS adoption expressed as a percentage of mainframe page loads

    Chrome 141 already conducted a pilot program, revealing that the median user encounters fewer than 1 warning per week, with even heavy internet users experiencing fewer than 3 warnings.

    This data contradicts assumptions about disruptive notification frequency, providing confidence for full-scale implementation.

    A particularly thoughtful aspect of this initiative involves differentiating between public and private sites.

    While Google will enforce strict HTTPS requirements for public websites, the implementation acknowledges that private sites, including local network devices and internal corporate systems, present reduced attack surfaces.

    When analyzing platform statistics excluding private site traffic, HTTPS adoption rates approach 97 to 99 percent across all systems, indicating that most remaining HTTP usage concentrates on private infrastructure where obtaining trusted HTTPS certificates remains technically complicated.

    “Always Use Secure Connections,” available at chrome://settings/security
    “Always Use Secure Connections,” available at chrome://settings/security

    Website developers and IT professionals should immediately enable the “Always Use Secure Connections” setting to identify potentially affected sites.

    Organizations managing Chrome deployments can reference Google’s comprehensive adoption guide to understand warning conditions and mitigation strategies.

    Many HTTP-using organizations simply haven’t prioritized HTTPS migration, while others depend on HTTP for local network device configuration, a scenario now addressable through Chrome’s new local network access permission system.

    Users retain full control, remaining able to disable warnings through settings if necessary, though Google strongly encourages adopting secure connections as standard practice moving forward.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Chrome to Alert Users “Always Use Secure Connections” While Opening Public HTTP Sites appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A critical vulnerability discovered in Google Messages for Wear OS has exposed millions of smartwatch users to a significant security risk. Identified as CVE-2025-12080, the flaw allows any installed application to send text messages on behalf of the user without requiring permissions, confirmation, or user interaction. Security researcher Gabriele Digregorio discovered the vulnerability in March […]

    The post Google Wear OS Flaw Lets Any App Send Texts on Behalf of Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fraudulent investment platforms impersonating legitimate cryptocurrency and forex exchanges have emerged as the primary financial threat across Asia, with organized crime groups operating at unprecedented scale. These sophisticated scams leverage social engineering tactics to deceive victims into transferring funds to attacker-controlled systems, blurring the lines between legitimate trading and criminal enterprise. The threat extends far […]

    The post Cybercriminals Launch Flood of Fake Forex Platforms to Harvest Logins appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A threat actor has claimed responsibility for breaching HSBC USA, the American division of the global investment bank and financial services holding company. The cybercriminal posted an extensive database for sale on underground forums, alleging it contains fresh and comprehensive customer data stolen from the financial institution. Massive Collection of Sensitive Customer Data According to […]

    The post Hackers Allegedly Leak HSBC USA Customer and Financial Information appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • BeyondTrust’s annual cybersecurity predictions point to a year where old defenses will fail quietly, and new attack vectors will surge. Introduction The next major breach won’t be a phished password. It will be the result of a massive, unmanaged identity debt. This debt takes many forms: it’s the “ghost” identity from a 2015 breach lurking in your IAM, the privilege sprawl from thousands of new

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Organizations in Ukraine have been targeted by threat actors of Russian origin with an aim to siphon sensitive data and maintain persistent access to compromised networks. The activity, according to a new report from the Symantec and Carbon Black Threat Hunter Team, targeted a large business services organization for two months and a local government entity in the country for a week. The attacks

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Researchers have unveiled a groundbreaking attack dubbed “TEE.fail” that fundamentally compromises the security guarantees of Trusted Execution Environments (TEEs) from Intel and AMD by exploiting DDR5 memory architecture. The attack demonstrates how even the most advanced hardware-backed security features can be defeated using surprisingly accessible electronic equipment, raising critical questions about the future of confidential […]

    The post New TEE.fail Exploit Steals Secrets from Intel & AMD DDR5 Trusted Environments appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶