Visualização normal

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • TP-Link Archer AX55 Flaws Expose Routers to Code Execution Do Son
    A TP-Link Archer AX55 vulnerability (CVE-2026-18167) risks remote code execution via EasyMesh buffer overflow. Update to build 20260527 now. Related Posts: MikroTik RouterOS Vulnerability Exploited in the Wild: Patch and Defense Blueprint StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE The post TP-Link Archer AX55 Flaws Expose Routers to Code Execution appeared first on Daily CyberSecurity.
     

Prediction Market Betting Is Getting People Banned and Arrested

3 de Setembro de 2026, 18:48
This week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agents

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

20 de Agosto de 2026, 17:03
This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

  • ✇Cybersecurity News
  • Mozilla Rotates Firefox and Thunderbird Linux GPG Signing Key After Private Repo Exposure Do Son
    Mozilla rotated the Linux GPG signing key for Firefox and Thunderbird after a subkey copy was inadvertently pushed to a private GitHub repository. Related Posts: Apple Proposes New App Store Link-Out Fees of 5% to 15% in Epic Legal Battle Microsoft Copilot Super App: A Unified Platform Vision Google Gemini Hits 1 Billion Users - Now the Fastest-Growing App in Google History The post Mozilla Rotates Firefox and Thunderbird Linux GPG Signing Key After Private Repo Exposure appeared first on Dai
     

Fake The Odyssey Downloads Are Hiding Password-Stealing Malware

10 de Agosto de 2026, 11:21

Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.

The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic.

ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.
  • ✇Security Affairs
  • Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets Pierluigi Paganini
    Ernst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT teams. The platform stored support requests that may have included documents containing client tax information. “EY uses a third-party information technology service management platform to help EY information tech
     

Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets

17 de Julho de 2026, 18:34

Ernst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information.

Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT teams. The platform stored support requests that may have included documents containing client tax information.

“EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients. Support tickets submitted through the platform may include documents containing client tax information. On April 23, 2026, EY identified anomalous activity within that platform.” reads the data breach notification. ” “EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts. EY has worked with an independent cybersecurity firm to investigate the incident and confirm that the unauthorized access has been stopped, and our systems are now secure. Based on EY’s investigation and available evidence, between March 28, 2026, and April 12, 2026, an unauthorized third party accessed the platform referenced above and downloaded documents pertaining to a number of EY clients.”

Ernst & Young is one of the world’s Big Four professional services firms, providing audit, tax, consulting, cybersecurity, and transaction advisory services. The company operates in more than 150 countries, with around 406,000 employees and global revenues of approximately $53.2 billion in fiscal year 2025. Its access to sensitive client data makes it a high-value target.

Ernst & Young revealed that it detected anomalous activity on its networks on April 23 and launched an investigation into the security breach with the help of external cybersecurity experts.

The company determined that an unauthorized third party had accessed the said platform between March 28 and April 12 and downloaded multiple documents.

The compromised information included certain personal and financial data contained in or used to prepare tax filings.

At this time, it is unclear how many customers were impacted by the incident.

EY announced it has secured its systems, removed unauthorized access, and notified federal authorities. The company pointed out that it has no evidence of misuse of the exposed files or targeted attacks against specific individuals.

“At this time, we are not aware of any misuse or further exposure of your personal information as a result of this incident. Further, we do not have any indication your personal information was specifically targeted.” continues the notification. “Nevertheless, we are providing information about steps you can take to further secure your personal information.”

To support affected clients, EY is offering 24 months of identity monitoring and restoration services through Experian.

At this time, no ransomware group has claimed responsibility for the attack.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, EY)

  • ✇Firewall Daily – The Cyber Express
  • Operation Endgame Disrupts SocGholish, StealC Malware Networks Samiksha Jain
    Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware. Led by Europol and
     

Operation Endgame Disrupts SocGholish, StealC Malware Networks

Operation Endgame Disrupts SocGholish

Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware.

Led by Europol and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch ransomware attacks, financial fraud, and attacks against critical infrastructure.

Operation Endgame Targets Cybercrime Infrastructure

During the coordinated action, authorities targeted the infrastructure supporting malware delivery rather than focusing on a single malware family.

Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting malware distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.

According to Europol, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.

[caption id="attachment_112936" align="aligncenter" width="600"]Operation Endgame Image Soure: Europol[/caption] [caption id="attachment_112937" align="aligncenter" width="600"]Operation Endgame Strikes Malware Image Source: Europol[/caption]

SocGholish, Amadey and StealC Malware Played Different Roles

The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.

  • SocGholish functioned as a malware loader that distributed fake browser updates through compromised WordPress websites. Users who installed these fake updates unknowingly infected their systems, allowing attackers to gain initial access and later deploy ransomware or other malicious tools.
  • StealC malware primarily targeted sensitive information stored on infected devices, including passwords, authentication data, and digital identities. The stolen information was later used for fraud or traded within cybercriminal marketplaces.
  • Amadey was mainly distributed through phishing campaigns. It provided attackers with initial access to compromised systems while also offering information-stealing capabilities that enabled the theft of sensitive user data.

Microsoft reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.

Thousands of Infected WordPress Sites Cleaned

One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.

Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish botnet by taking control of domains and shutting down supporting servers.

Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.

The Dutch Police urged WordPress administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.

SocGholish Linked to Evil Corp

Authorities said SocGholish has been linked to Evil Corp, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.

Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.

Europol Coordinates Global Cyber Operation

Europol's European Cybercrime Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.

The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.

Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.
  • ✇Security Affairs
  • Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame Pierluigi Paganini
    Operation Endgame disrupted malware services like StealC and Amadey that enable ransomware, fraud, and attacks on critical infrastructure. Between June 15 and 19, 2026, Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK, and the US, alongside private firms like Microsoft, Bitdefender, IBM X-Force, Proofpoint, Infoblox, Shadowserver, Orange Cyberdefense, and a dozen other private partners. The operation target
     

Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame

24 de Junho de 2026, 15:43

Operation Endgame disrupted malware services like StealC and Amadey that enable ransomware, fraud, and attacks on critical infrastructure.

Between June 15 and 19, 2026, Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK, and the US, alongside private firms like Microsoft, Bitdefender, IBM X-Force, Proofpoint, Infoblox, Shadowserver, Orange Cyberdefense, and a dozen other private partners.

The operation targeted the infrastructure behind three malware families, SocGholish, Amadey, and StealC, that together form the opening stages of the cybercrime attack chain.

“The main common goal was to disrupt the “assembly lines” cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure.” reads the report published by EUROPOL. “Crypto assets of criminal origin currently valued at over EUR 41 million (USD 47 million) were identified, flagged, and thereby restricted from use. “

The numbers from the action are substantial. Law enforcement and private partners actioned 326 servers and 142 domains, recovered 27 million stolen login credentials, and identified, flagged, and restricted over €41 million in criminal cryptocurrency assets.

During the SocGholish portion of the operation, 14,971 infected websites were remediated, including restaurants, auto repair shops, and other everyday businesses whose WordPress installations had been quietly compromised and turned into malware distribution points. The Dutch Police removed vulnerabilities from infected sites and notified owners directly.

SocGholish works by injecting fake browser update prompts into legitimate websites. A visitor clicks what looks like a routine update, and the malware installs.

“This approach, which has caused countless victims, is primarily done by hacking websites built with WordPress and infecting them with malware.” continues the report.” The unauthorised access was then exploited for further crimes, such as installing ransomware for the purpose of digital extortion.”

SocGholish is linked to Evil Corp, the Russian cybercriminal group previously responsible for Zeus and Dridex, and associated with multiple large-scale ransomware and money-laundering operations.

Amadey has been running since October 2018 as a paid dropper service, spreading primarily through phishing campaigns. It gains initial access, delivers additional malware, and also has credential and clipboard stealing capabilities. StealC, which surfaced in January 2023, is the harvesting layer: it pulls passwords, stored credentials, digital identities, and sensitive data from compromised machines and makes them available for resale and fraud.

“Amadey gains initial access to devices, while StealC extracts passwords and sensitive data.” states the report. “Together, they form a critical link in the cybercrime supply chain.”

Microsoft linked both families to over 140,000 infected computers worldwide in just the first two weeks of May 2026.

The operational logic behind targeting these three families simultaneously is what makes this phase of Operation Endgame strategically significant. Rather than focusing on the ransomware payload at the end of the chain, the operation hit the tools that make every subsequent stage possible.

“Operation Endgame targets the initial access malware used to infect devices. Cybercriminals use this malware as a gateway to silently infiltrate victims’ systems and steal sensitive data.” reads the press release published by EuroJust. “By fighting the initial stage of the attack chain, the operation strikes at the heart of the entire ‘cybercrime-as-a-service’ ecosystem.”

Take out the loader, and the ransomware operator has no foothold to monetize.

Victim notifications went out through HaveIBeenPwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and the Dutch National Cyber Security Centre. WordPress site owners whose credentials were leaked have been urged to change login credentials, enable multi-factor authentication, delete any unknown admin accounts, and keep their installations updated. For ordinary users, the advice on SocGholish is the same it’s always been and apparently still needs repeating: genuine software updates come from official sources through system settings or app stores, not from browser pop-ups that scream for immediate action.

Operation Endgame is described by Europol as the largest international operation ever undertaken to tackle ransomware enablers worldwide. More than 30 public and private parties support its actions on an ongoing basis.

The operation has an active suspect portal. The message from every law enforcement statement is consistent: each takedown raises costs, degrades operations, and generates intelligence for the next one.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Operation Endgame)

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks

Operation Endgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.

💾

  • ✇Firewall Daily – The Cyber Express
  • Sunil Varkey Joins Hexaware Technologies as EVP & CISO Samiksha Jain
    Sunil Varkey has been appointed as Executive Vice President (EVP) and Chief Information Security Officer (CISO) at Hexaware Technologies, where he will lead the company's information security strategy, governance, risk management, and enterprise resilience initiatives. The appointment marks the latest leadership role for the cybersecurity veteran, who brings more than three decades of experience across global enterprises and multiple industry sectors. Based in Chennai, India, and operating in
     

Sunil Varkey Joins Hexaware Technologies as EVP & CISO

Sunil Varkey

Sunil Varkey has been appointed as Executive Vice President (EVP) and Chief Information Security Officer (CISO) at Hexaware Technologies, where he will lead the company's information security strategy, governance, risk management, and enterprise resilience initiatives. The appointment marks the latest leadership role for the cybersecurity veteran, who brings more than three decades of experience across global enterprises and multiple industry sectors. Based in Chennai, India, and operating in a hybrid work model, Varkey will be responsible for strengthening enterprise cybersecurity governance, risk management frameworks, and overall security strategy at Hexaware Technologies. His appointment was announced in June 2026.

Sunil Varkey to Lead Cybersecurity Strategy at Hexaware Technologies

In his new role, Sunil Varkey will oversee key areas including information security governance, enterprise risk management, and resilience initiatives. His responsibilities align with Hexaware Technologies' broader technology and growth objectives as the company continues to support large-scale digital transformation programs for clients worldwide. Hexaware Technologies delivers technology-led services across application development, cloud services, automation, data analytics, and enterprise IT operations. The company serves organizations across multiple industries and supports digital modernization initiatives at scale. Varkey's appointment comes as organizations continue to focus on strengthening cybersecurity programs and managing digital risks across increasingly complex technology environments.

More Than 30 Years of Cybersecurity Leadership Experience

Varkey brings over 30 years of experience in cybersecurity leadership spanning banking, telecommunications, IT services, manufacturing, and enterprise technology sectors. His professional experience extends across India, the Middle East, and the United States. His areas of expertise include cybersecurity governance, risk and compliance (GRC), security architecture, incident response, DevSecOps, cloud security, privacy management, cyber defense, business continuity management, security operations, and AI security. Prior to joining Hexaware Technologies, Varkey served as Cyber Security Consultant and Advisor at TAHAKOM in Riyadh, Saudi Arabia, from June 2023 to March 2025. In that role, he worked alongside the organization's CISO to enhance cybersecurity resilience and strengthen security posture. Before TAHAKOM, he held the position of Vice President and Chief Technology Officer for EMEA and APJ at Forescout Technologies Inc. between April 2021 and November 2022. Based in Dubai, he focused on IT/OT security strategy, enterprise cybersecurity advisory services, and product positioning across global markets.

Leadership Roles Across Global Organizations

Between March 2020 and January 2021, Varkey served as Managing Director and Global Head of Cyber Security Assessments and Testing at HSBC in Hyderabad. He led a team of approximately 300 professionals responsible for penetration testing, threat modeling, vulnerability management, and third-party security risk assessments. Earlier, from December 2018 to February 2020, he worked as CTO and Security Strategist for the Middle East, Africa, and Eastern Europe region at Symantec. His responsibilities included developing cybersecurity strategies for enterprise, government, industrial, and financial sector organizations. His career also includes senior leadership positions such as Global CISO at Wipro, CISO for Security and Privacy at Idea Cellular, and Vice President of Security Engineering at Barclays. Additionally, he held global security leadership roles at GE Capital, Genpact, Paramount Computer Systems, and other multinational organizations.

Focus on Governance, Risk Management, and Enterprise Resilience

Throughout his career, Varkey has overseen cybersecurity functions covering governance, compliance, strategy, security engineering, incident response, privacy, cloud security, cyber defense, and enterprise resilience. His experience includes leading security programs for organizations with large-scale user bases and complex operational environments. At Wipro, he served as Global CISO for a technology company supporting more than 200,000 end users. At Idea Cellular, he led security and privacy initiatives for a telecom operator with approximately 120 million subscribers. With his appointment, Hexaware Technologies adds a cybersecurity leader with extensive experience in building and scaling security programs across global enterprises. The move underscores the company's continued focus on strengthening cybersecurity operations, governance frameworks, and digital risk management capabilities as part of its ongoing technology initiatives.

Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

Deleted Google API Keys remain active for up to 23 minutes after deletion, exposing GCP, Gemini, BigQuery, and Maps data to attackers.

Operation Epic Fury Exposes Critical OT Security Gaps in U.S. Oil and Gas Sector

Operation Epic Fury

The cybersecurity posture of the U.S. oil and gas sector has come under renewed scrutiny following Operation Epic Fury, with a new independent survey revealing a disconnect between operator confidence and actual operational technology (OT) security capabilities. While companies across the upstream and midstream energy segments have accelerated cybersecurity investments since the February 28 launch of Operation Epic Fury, the findings suggest many organizations may still lack the tools needed to identify real-time cyber threats targeting OT environments.  The independent survey, conducted on behalf of Tosi, examined the views of OT decision makers across U.S. oil and gas operators. The research found that most respondents believe they can detect an active OT cyber breach within 24 hours. However, the same OT decision makers acknowledged relying heavily on systems and processes not specifically designed to monitor OT infrastructure.  According to the survey data, 87 percent of operators rated themselves as confident in their ability to detect an OT breach within a day, assigning their organizations a score of four or five on a five-point confidence scale. Despite that confidence, 51 percent said their detection capabilities primarily depend on IT security tools that provide only limited visibility into OT-specific network traffic.  Another 27 percent of respondents said they would depend on field operators or technicians identifying irregularities manually, while only 16 percent reported using continuous OT monitoring as the primary basis for cyber threat detection. Sakari Suhonen, CEO of Tosi U.S., warned that this gap represents a major vulnerability for the energy sector in the wake of Operation Epic Fury.  “This is the most consequential blind spot in U.S. energy infrastructure right now,” Suhonen said. “The sector has the budget, the executive attention, and the will to act. What it does not yet have is detection that actually sees OT. After Operation Epic Fury, that distinction is the difference between catching an intrusion in hours and finding out about it from a production outage.” 

Operation Epic Fury Drives Rapid OT Security Spending 

The independent survey was fielded in April 2026, approximately six weeks after Operation Epic Fury began. Researchers noted that the speed of the sector’s response has been unusually aggressive compared to previous cybersecurity cycles.  One of the clearest trends identified by OT decision makers involved changing perceptions of cyber risk. Sixty-three percent of surveyed operators said cyber risk is now higher than it was before February 28, with 13 percent describing the increase as significant.  Respondents identified several key factors contributing to elevated risk levels, including growing convergence between IT and OT systems, increased targeting of energy infrastructure by state-sponsored cyber actors, and expanding dependence on third-party remote access technologies.  The independent survey also showed that emergency cybersecurity funding is already being deployed. Ninety-four percent of operators said they had either approved or were actively reviewing unplanned OT security spending linked directly to the post-Operation Epic Fury threat landscape. Among OT decision makers surveyed, 95 percent expect OT cybersecurity budgets to increase over the next 12 months, while one in four anticipated budget growth exceeding 20 percent. 

OT Decision Makers Prioritize Detection and Visibility 

The survey findings indicate that OT decision makers are placing greater emphasis on visibility and detection capabilities rather than traditional perimeter security tools.  When respondents were asked to identify the single most important OT security capability to improve over the next year, 22 percent selected continuous monitoring and anomaly detection. Another 20 percent pointed to OT-specific incident detection and response solutions.  Additional priorities included asset discovery at 15 percent and OT-specific secure remote access at 14 percent. Combined, detection, visibility, and remote access technologies accounted for 71 percent of all named priorities among surveyed OT decision makers.  At the same time, operational disruptions linked to cybersecurity incidents appear widespread throughout the sector. According to the independent survey, 99 out of 100 operators reported experiencing at least one category of cyber incident since February 28.  Ransomware affecting OT-connected systems impacted 48 percent of operators surveyed, while another 48 percent reported precautionary OT shutdowns triggered by incidents originating on the IT side of operations. 

Human Challenges Continue to Slow OT Security Progress 

Despite the increase in cybersecurity spending following Operation Epic Fury, many organizations continue to struggle with internal operational barriers. The independent survey found that 45 percent of operators consider the cultural divide between IT and OT teams to be the single largest obstacle preventing faster cybersecurity improvements. Respondents said IT security personnel often lack the specialized expertise required to secure OT environments effectively.  Operational risk aversion ranked as the second-largest barrier at 28 percent. By contrast, only 11 percent of respondents identified budget constraints as a major challenge, marking a notable change from previous industry research in which financial limitations consistently ranked as the top concern for OT decision makers.  The findings emerge amid continuing warnings from federal authorities regarding Iran-aligned cyber activity targeting Western critical infrastructure after Operation Epic Fury. On April 7, six U.S. federal agencies — including the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Energy — issued joint advisory AA26-097A. The advisory confirmed that Iranian-affiliated threat actors were actively disrupting programmable logic controllers across U.S. energy, water, and government sectors, resulting in operational disruptions and financial losses.  The Railroad Commission of Texas later issued a parallel warning to operators on April 10. According to Tosi, the independent survey represents the first dataset quantifying how the oil and gas sector itself is responding to the cybersecurity environment created by Operation Epic Fury. Suhonen said the industry’s next decisions regarding OT security investments will determine whether organizations close existing detection gaps or reinforce systems that remain ineffective for OT environments.  “The next twelve months will see oil and gas spend more on OT security than in the previous several years combined,” Suhonen said. “That spend will land in one of two places. It will close the detection gap with OT-native monitoring, asset visibility, and purpose-built secure remote access. Or it will deepen the IT-tool stack that operators have already told us they cannot see what they need it to see. The data is unambiguous about which path the market needs to take.” 
  • ✇Firewall Daily – The Cyber Express
  • JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign Samiksha Jain
    A newly identified cyber campaign involving JanaWare ransomware is targeting users in Turkey, with researchers linking the activity to a customized version of the Adwind Remote Access Trojan (RAT). The findings come from an analysis by researchers at Acronis’ Threat Research Unit (TRU), who identified the threat cluster during an investigation into suspicious Java-based malware samples. According to the researchers, the JanaWare ransomware operation appears to have been active since at least
     

JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign

JanaWare Ransomware Targets Turkish Users

A newly identified cyber campaign involving JanaWare ransomware is targeting users in Turkey, with researchers linking the activity to a customized version of the Adwind Remote Access Trojan (RAT). The findings come from an analysis by researchers at Acronis’ Threat Research Unit (TRU), who identified the threat cluster during an investigation into suspicious Java-based malware samples. According to the researchers, the JanaWare ransomware operation appears to have been active since at least 2020. Evidence from malware samples and infrastructure indicates that the campaign has continued into late 2025, suggesting sustained activity with limited visibility. The attack relies on a modified Adwind RAT that includes polymorphic capabilities. This allows the malware to change its structure across infections, making detection more difficult. Combined with code obfuscation, these techniques have likely contributed to the campaign remaining relatively unnoticed. Unlike large ransomware groups that focus on high-value enterprise targets, JanaWare ransomware appears to follow a different strategy. Observed ransom demands range between $200 and $400, pointing to a model that prioritizes volume over large individual payouts.

Phishing Identified as Primary Infection Vector

The JanaWare ransomware campaign primarily spreads through phishing emails. Victims are lured into clicking malicious links, which lead to the download of a Java archive file. In many observed cases, the payload is hosted on cloud storage platforms. Telemetry data reviewed by researchers shows a consistent attack chain. A phishing email is opened in Microsoft Outlook, followed by a browser session that downloads the malicious file. The file is then executed using Java, triggering the infection. [caption id="attachment_111347" align="aligncenter" width="761"]JanaWare Ransomware Image Source: Acronis’ Threat Research Unit (TRU)[/caption] User reports on public cybersecurity forums also describe similar incidents, supporting the assessment that phishing is the main entry point.

Geofencing Restricts Janaware Ransomware Attacks to Turkey

A key feature of the JanaWare ransomware is its use of geofencing. The malware is designed to execute only on systems that meet specific regional criteria linked to Turkey. It checks system language, locale settings, and external IP geolocation before proceeding. If the system does not match Turkish parameters, the malicious activity is halted. Researchers note that this approach likely serves both operational and defensive purposes. It allows attackers to focus on a specific region while reducing exposure to global security monitoring and automated analysis systems.

Obfuscation and Polymorphism Hinder Detection

The JanaWare ransomware incorporates multiple techniques to evade detection. Researchers identified the use of known obfuscation tools such as Stringer and Allatori, alongside custom methods that complicate analysis. The malware also includes a self-modifying component that alters its file structure during deployment. By adding random data to its Java archive, each instance generates a unique file hash, limiting the effectiveness of signature-based detection. In addition, the malware contains embedded configuration parameters that control its behavior. These include command-and-control server details, communication ports, and authentication values used during initial connections.

Security Controls Disabled Before Encryption Stage

Before encrypting files, the malware attempts to weaken system defenses. It executes commands to disable Microsoft Defender, suppress security alerts, and remove recovery mechanisms such as Volume Shadow Copies. It also interferes with Windows Update and scans for installed antivirus software. These steps reduce the likelihood of detection or recovery once the ransomware payload is activated. The encryption process is carried out by a secondary module delivered after the initial compromise. This module uses AES encryption and communicates with command-and-control infrastructure over the Tor network.

Turkish-Language Ransom Notes Signal Targeted Approach

After encryption, the malware drops ransom notes across affected systems. These notes are written in Turkish and instruct victims to contact the attackers through encrypted communication channels such as qTox or Tor-based websites. Researchers say the consistent use of Turkish-language content, combined with geofencing, indicates a deliberate focus on users in Turkey rather than a broad, global campaign. The JanaWare ransomware campaign highlights how targeted, lower-profile operations can persist over long periods without drawing significant attention. By focusing on home users and small businesses, and keeping ransom demands relatively low, the attackers appear to maintain a steady but less visible operation. Researchers caution that such localized campaigns may continue to operate alongside larger ransomware groups, adding another layer to the evolving threat landscape.

Almost half a million Lloyds customers had personal data exposed in IT glitch

Letter from group published by MPs blames 12 March glitch on software update to its mobile banking apps

Lloyds Banking Group exposed the personal data of nearly 500,000 customers in an IT glitch that left people’s payments, account details and national insurance numbers visible to other users, a committee of MPs has revealed.

A letter from Lloyds, published by MPs on the Treasury select committee on Friday, blamed the glitch on a software defect introduced during an IT update to its Lloyds, Halifax and Bank of Scotland mobile banking apps overnight into 12 March.

Continue reading...

© Photograph: David Burton/Alamy

© Photograph: David Burton/Alamy

© Photograph: David Burton/Alamy

  • ✇Data and computer security | The Guardian
  • Louis Vuitton says UK customer data stolen in cyber-attack Mark Sweney
    Lead brand of French luxury group LVMH reassures customers financial data such as bank details were not takenLouis Vuitton has said the data of some UK customers has been stolen, as it became the latest retailer targeted by cyber hackers.The retailer, the leading brand of the French luxury group LVMH, said an unauthorised third party had accessed its UK operation’s systems and obtained information such as names, contact details and purchase history. Continue reading...
     

Louis Vuitton says UK customer data stolen in cyber-attack

Lead brand of French luxury group LVMH reassures customers financial data such as bank details were not taken

Louis Vuitton has said the data of some UK customers has been stolen, as it became the latest retailer targeted by cyber hackers.

The retailer, the leading brand of the French luxury group LVMH, said an unauthorised third party had accessed its UK operation’s systems and obtained information such as names, contact details and purchase history.

Continue reading...

© Photograph: SOPA Images/LightRocket/Getty Images

© Photograph: SOPA Images/LightRocket/Getty Images

© Photograph: SOPA Images/LightRocket/Getty Images

❌
❌