cybercrime29 articles
Russian Hacker Extradited Over Excel Macro Campaign That Hit 80,000 Freelance Platform Users
A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited from Cyprus and charged in the US for orchestrating a malware campaign in 2016–2017 that used around 255 fake accounts on a freelance platform to send malicious Excel attachments to approximately 80,000 users. The attachments tricked recipients into running macros that installed two remote access tools — TVRAT and DarkVNC — giving attackers covert control of victims' computers and enabling theft of credentials and personal data. The case highlights the ongoing abuse of freelance and job-hunting platforms as attack vectors, a tactic also currently employed by state-sponsored groups such as North Korea's Lazarus and Russia's Sandworm.
Chinese Threat Actor Is Quietly Hijacking Brazilian Government Websites to Rank Gambling Pages
A Chinese-speaking cybercrime group called Gambling Goblin (linked to Earth Berberoka) has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules that silently redirect visitors to fake app stores promoting illegal online gambling and sports betting. The primary objective appears to be large-scale SEO manipulation, exploiting the high-reputation domains of legitimate government sites to artificially boost search rankings for gambling pages, with over 630,000 URLs reportedly generated across hijacked Brazilian government subdomains. The group deploys a sophisticated toolkit including backdoors, a RAT, credential stealers, and an SSH brute-forcer, and it is part of a broader trend of China-aligned actors using similar server-hijacking techniques — mirroring a parallel campaign by a separate group called GhostRedirector that targeted IIS servers across Brazil, Thailand, and Vietnam.
ShinyHunters Padded the Carhartt Breach With Millions of Fake Records
Carhartt suffered a data breach affecting approximately 12.9 million individuals — roughly half the 25 million claimed by hacking group ShinyHunters, which had padded the dataset with millions of lines of synthetic data. Troy Hunt of Have I Been Pwned uncovered the inflation through careful analysis, using tools to identify fake email domains, implausible demographics, and other anomalies before arriving at the genuine figure. The real breach exposed names, email addresses, phone numbers, and physical addresses, with Carhartt yet to publicly comment on the incident.
£8K Phishing Kit Promises to Plant Fake Passkeys and Haunt Compromised Accounts Long After You've Changed Your Password
A $10,000 phishing kit called iAuthFlow v2, advertised on Russian-language cybercrime forums, uses a browser-in-the-middle technique to hijack authentication sessions and secretly enroll attacker-controlled passkeys on compromised accounts — allowing persistent access even after victims change their passwords. The kit relays the victim's login interaction through an attacker-controlled browser, then exploits the authenticated session to register a rogue passkey, reportedly completing the process within seconds. Security researchers warn that incident response must go beyond password resets and session revocation, requiring a thorough audit of all post-compromise account changes, including newly enrolled passkeys, OAuth grants, and recovery methods.
LockBit Claims US Bank Scalp With September Leak Deadline
US Bank is investigating claims by ransomware group LockBit that it breached the bank and stole data, with a threat to leak the information on September 3 unless an undisclosed ransom is paid. The bank states there is currently no indication its internal systems were compromised or that unauthorized access occurred. LockBit, which re-emerged in 2025 with a new ransomware variant after a law enforcement takedown in 2024, has a history of retaining victim data even after ransoms are paid.
Threat Actor Claims Millions of Corporate Records Lifted from Azure Tenants
A threat actor called "TheHatman" is claiming to have stolen millions of employee records from the Microsoft Azure environments of major corporations including McDonald's, Vodafone, Tata Consultancy Services, and Kyndryl, with the data reportedly including sensitive details such as employee IDs, job titles, and accounts with Global Administrator privileges. Security firm Hudson Rock assessed the data as "highly likely authentic" but could not determine the exact method of access, suggesting possibilities such as infostealer malware, phishing, or weak multi-factor authentication. Tata Consultancy Services has denied finding credible evidence of a breach, stating the referenced information appears to be over four years old and limited to basic employee data.
France's Tax Authority Confirms Data Breach After Hacker Hawks 2 Million Taxpayer Records Online
France's tax authority (DGFiP) has confirmed a data breach that occurred in late June 2026, in which an attacker using stolen credentials and an MFA bypass technique accessed and extracted data on approximately 2 million taxpayers. The alleged criminal, known as "ZeroBytes," advertised the stolen database on a cybercrime forum and claimed to still have access to DGFiP's systems, though the agency disputes this and says access was severed during a routine audit. The incident is one of several significant cyberattacks targeting French public sector organisations in 2026, following earlier breaches affecting the Finance Ministry, Health Ministry, and the passport and driver's licence agency France Titres.
White House Outsources Cyber Offence to Private Firms in Unprecedented Anti-Crime Push
The White House has issued a presidential memorandum establishing a program that allows vetted private US companies to conduct offensive and intelligence-gathering cyber operations against foreign cybercrime organizations, under the supervision of a National Coordination Center co-managed by the DOJ and DHS. Participating firms must undergo rigorous vetting, sign formal contracts, and post a bond of at least $1 million, with all operations requiring written federal approval and multi-agency review before execution. The program prohibits actions that could cause loss of life, constitute an act of war, or inadvertently affect US persons or domestic systems.
Ransom Cartel Kingpin Gets 16 Years While Half His Crew Remains at Large
Maksim Silnikau, a 40-year-old Belarusian national, was sentenced to 16 years in prison for creating and operating Ransom Cartel, a ransomware-as-a-service operation that targeted at least 18 companies between 2021 and 2023. He built the criminal enterprise by providing locking software, stolen credentials, and an affiliate management system, routing ransom payments through cryptocurrency mixers. A separate federal case in New Jersey related to the Angler Exploit Kit malvertising scheme remains unresolved, with two co-defendants still at large.
Snowflake Breach Hacker Pleads Guilty: 100 Million Records, Stale Passwords, and No MFA
Connor Riley Moucka, 26, pleaded guilty to computer fraud, wire fraud, and identity theft charges related to the 2024 breaches of Snowflake customer accounts, which compromised at least 165 organizations and exposed records of over 100 million people. The attacks required no sophisticated exploits — attackers simply used old credentials harvested years earlier by infostealer malware on accounts with no multi-factor authentication enabled. Moucka faces a mandatory two-year minimum plus up to 30 years on additional charges and is due to be sentenced on October 27, 2025.
River Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.
River Bank & Trust suffered a ransomware attack on June 16, in which hackers accessed portions of its network and exfiltrated data, prompting the company to take affected systems offline and disable compromised accounts. The bank engaged with the threat actors and obtained representations that the stolen data had been deleted, likely following a ransom payment. The investigation is ongoing, and River has yet to determine whether personal information was stolen or whether the incident will materially impact its business.
ExfilSquad Claims Police Database Scalp as UK Public Sector Breach Spree Continues
The Police National Legal Database (PNLD) has confirmed a data breach in which cybercriminals stole names, organisations, and work email addresses belonging to police officers, criminal justice staff, government partners, and customers, with no evidence that passwords were compromised. The breach is linked to an extortion group called "ExfilSquad," which claims to have stolen a 1.9 GB dataset containing around 135,000 law enforcement contact records, and also claimed responsibility for a recent breach of the UK Department for Education affecting over 607,000 records. Key details — including how attackers gained access, the exact number of victims, and whether a ransom was demanded — have not yet been disclosed.
Flying Eagle Android RAT Source Code Leaks, Fingerprints Spotted on 170 Servers
Source code for the Flying Eagle Android RAT framework is circulating on criminal Telegram channels, with researchers at Hunt.io and NetAskari identifying matching infrastructure on 170 internet servers, though this figure reflects server fingerprints rather than confirmed victims or active command-and-control systems. The toolkit, disguised as a fake Chinese public security app, supports keystroke and payment-password capture, screen recording, camera access, and phishing overlays, and its builder generates obfuscated APKs with encrypted C2 URLs. Researchers also identified a separate Android RAT called Night Dragon being promoted by one of the same Telegram channels, though it appears to be an independent, financially motivated tool unrelated to the 2011 espionage campaign of the same name.
US Pulls the Visa Rug from Under Foreign Cybercriminals
US Secretary of State Marco Rubio has announced that the US will deny visas to foreign nationals involved in cybercrime and cyber-enabled scams, with restrictions potentially extending to their immediate families. The policy targets overseas fraudsters — particularly Chinese transnational criminal organisations — who defrauded American citizens of over $10 billion in 2024 through investment scams and sextortion schemes. The restrictions draw on Section 212(a)(3)(C) of the Immigration and Nationality Act, a provision Rubio has previously used to impose visa bans on foreign officials who suppress free expression and workers who facilitated illegal immigration.
Stadler Rail Tells Ransomware Gang to Take a Hike on a CHF 10 Million Demand
Swiss rail manufacturer Stadler Rail refused a CHF 10 million ransom demand from the Everest ransomware gang after attackers accessed technical data from a supplier via a shared data exchange platform using compromised credentials. The company stated that no personal or security-relevant data was affected and that its own IT systems remained fully intact. Unusually, Stadler has not appeared on Everest's data leak site despite refusing to pay, which departs from the typical ransomware extortion playbook.
Kratos Phishing Kit Dismantled: 200 Servers Down, But 1,800 Customers Still Have the Code
German and US authorities, alongside Indonesian police, have dismantled Kratos, a major phishing-as-a-service platform that enabled around 1,800 criminal customers to run approximately 15,000 phishing campaigns per month, taking more than 200 servers offline and arresting its alleged developer. The kit was particularly dangerous due to its adversary-in-the-middle capability, which stole live Microsoft 365 session cookies alongside credentials, allowing attackers to bypass multi-factor authentication entirely. However, the takedown leaves the kit's existing customer base and their copies of the code untouched, raising concerns that similar operations could resurface under a new name.
Meet Dolphin X: The Infostealer With an AI Profiler That Tells Crooks Which Victims Are Worth Robbing First
Varonis Threat Labs has discovered a new Windows malware called Dolphin X, sold on cybercrime forums, which targets over 300 applications and can steal credentials, cryptocurrency wallets, SSH keys, and cloud tokens. Its most notable feature is an AI Profiler that analyses victims' app usage, browsing history, and installed software to rank them by likely profitability, helping criminals prioritise their attacks — something researchers say has never been seen before in malware. Sold through a tiered subscription model starting at around $80 per month, the malware lowers the technical barrier for cybercriminals and includes advanced detection-evasion capabilities, prompting security experts to advise defenders to focus on behavioural threat detection rather than file signatures.
Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to Pay
The Anubis ransomware group has claimed responsibility for a cyberattack on Fairlife, a Coca-Cola subsidiary, which disrupted production and resulted in the theft of approximately 1 TB of confidential data. The group is threatening to leak the stolen data unless a ransom is paid within one week. Active since December 2024, Anubis employs a double-extortion model and has targeted roughly 100 organisations, and is also notable for a "wiper mode" feature that can permanently delete victims' files.
One Hacker, Eight Dental PCs, and Google's Own AI Running the Operation
A Russian-speaking threat actor called "bandcampro" used Google's open-source Gemini CLI AI tool to operate a small botnet of eight dental clinic computers, with the AI handling approximately 89% of all text output and performing tasks such as migrating command-and-control infrastructure, debugging errors, and managing compromised machines via natural language prompts in Russian. Analysis of 200 session logs revealed the threat actor also leveraged the AI for password cracking, WordPress compromise, and planning cryptocurrency fraud targeting elderly people in the US and Canada. Researchers warn that the entire operation was condensed into just three portable text files, making the infrastructure easily disposable and replicable, and that this "skill-file" model could spread widely, effectively enabling even low-skilled actors to deploy AI-powered hacking operations with minimal effort.
23 Million Paidwork Users' Data Dumped Online After Alleged March Breach
A data breach at microtask platform Paidwork has exposed the personal and financial information of over 23 million users, with a stolen 11 GB database first advertised on a cybercrime forum in April and later added to Have I Been Pwned in July. The leaked data is extensive, including bank account numbers, passwords, addresses, transaction records, and more, with the breach traced back to an intrusion in March. Paidwork has yet to publicly acknowledge the incident or respond to press inquiries, leaving affected users advised to change passwords, monitor their finances, and watch for phishing attempts.
Armenia Locks Up Russian Tourist Named Aleksandr Ermakov. Problem: There Are Two of Them.
Armenia has detained a Russian tourist, Aleksandr Yuryevich Ermakov, at Yerevan's airport on a US extradition request targeting a REvil ransomware suspect of the same name, but his lawyers argue Washington has the wrong man. The US and allied governments actually want Aleksandr Gennadievich Ermakov, a sanctioned cybercriminal linked to the hack of Australian health insurer Medibank and convicted in Russia for co-writing the SugarLocker ransomware, who is currently serving a sentence barring him from leaving Russia. The mix-up may stem from the US warrant omitting the patronymic that distinguishes the two men, with the detained man's lawyers noting that no fingerprints or full passport data have been produced to confirm his identity.
Google and FBI Knock Out NetNut Proxy Network Backed by Millions of Infected Devices
Google, the FBI, and other partners disrupted NetNut (also known as Popa), a residential proxy network comprising over 2 million infected Android devices, including smart TVs and streaming boxes compromised through malicious apps. The network, linked to Israeli firm Alarum Technologies, rented proxy access to cybercriminals and espionage groups, with 316 distinct threat clusters observed using it in a single week. Google's actions included disabling associated accounts, dismantling backend infrastructure, and removing infected apps via Google Play Protect, resulting in a significant reduction in the botnet's available devices.
Google and FBI Kneecap NetNut's 2 Million-Device Proxy Botnet
Google, the FBI, and other partners have significantly disrupted NetNut, a residential proxy network that had enrolled at least 2 million devices — mostly TV-streaming hardware — into a botnet used by cybercriminals to disguise malicious traffic as coming from ordinary homes and businesses. In a single week in June 2026, over 316 distinct threat clusters, including cybercriminal and espionage groups, were observed using NetNut exit nodes for activities such as password spraying and masking their origins. Researchers warn that lasting disruption is difficult, as proxy operators tend to simply buy capacity from competitors when their own networks are degraded, and call for broader, coordinated efforts involving ISPs and technology platforms.
Meet Atlas RAT: The Chinese Cybercrime Group Now Targeting Europe
A Chinese-speaking cybercrime group known as TA4922 has expanded its operations into Europe, targeting organisations in Germany, Italy, the UK, and South Africa using newly documented malware including the Atlas RAT backdoor. The group employs localised phishing lures mimicking payroll notices, tax filings, and government communications, and has dramatically increased its activity since March 2026, conducting more unique campaigns than any other tracked cybercrime actor. Researchers at Proofpoint note that the malware's surveillance capabilities — including keylogging, screen capture, and webcam recording — could potentially be sold to or leveraged by espionage groups.
1.4 Million Scam Accounts Taken Down in Southeast Asia Crackdown
In a coordinated operation called "Disruption Week," law enforcement agencies including the US Department of Justice and Royal Thai Police, alongside major tech companies such as Meta, Microsoft, and Google, dismantled scam networks operating out of Southeast Asia. The effort resulted in over 1.4 million social media and Microsoft accounts being disrupted, 63 arrests, and more than $3.8 million in cryptocurrency assets frozen. The targeted scam compounds, located in Cambodia, Laos, and Burma, had been trafficking workers under false pretenses and forcing them to carry out large-scale fraud operations against victims in the US and abroad.
Dutch Authorities Axe 17-Million-Device Botnet Tied to Russian Proxy Firm
Dutch authorities, in a joint operation between police and the National Cyber Security Center, dismantled a botnet comprising over 17 million devices managed by 200 servers, after a security researcher reported the network. The botnet has been linked to ASOCKS, a Russia-based residential proxy service reportedly used for criminal activities such as DDoS attacks, phishing, and hiding users' identities. The host infrastructure, based in the Netherlands, was seized and taken offline by the hosting provider.
Play Ransomware Claims MyPillow Scalp — Lindell Says It's a Political Stitch-Up
The Russian-language ransomware group Play has claimed to have stolen sensitive financial and personal data from Mike Lindell's MyPillow, setting a Friday deadline for the company to make contact before publishing the data. Lindell has denied the breach, dismissing the claims as a politically motivated "hit job" related to his gubernatorial campaign. Play has targeted over 900 organisations since 2022 and is known for data theft and extortion tactics.
Dutch Police Nab Suspect Who Repeatedly Hacked Ajax Amsterdam's IT Systems
Dutch police arrested a 35-year-old man from Buren on suspicion of repeatedly hacking into Ajax Amsterdam's computer systems in early 2026. The attacker exploited vulnerabilities in the club's IT infrastructure to access data on hundreds of individuals, modify stadium bans, and potentially manipulate over 42,000 season tickets and 300,000 fan accounts. Ajax has since patched the vulnerabilities and notified the Dutch Data Protection Authority and police.
Microsoft Dismantles Shady Code-Signing Operation Fuelling Ransomware Campaigns
Microsoft has taken down a malware-signing service that threat actors were using to get ransomware and other malicious software past Windows security defences. The operation targeted a cybercriminal outfit providing a kind of laundering service for malware, giving it legitimately signed certificates so it looked trustworthy to the operating system.