Visualização normal

Antes de ontemStream principal

Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

24 de Agosto de 2026, 12:00
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access to your savings. Read more in my article on the Hot for Security blog.
  • ✇Graham Cluley
  • Fake IRS letters target cryptocurrency holders Graham Cluley
    Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Hot for Security blog.
     

Fake IRS letters target cryptocurrency holders

4 de Agosto de 2026, 06:02
Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"? If so, it's time to hit the brakes, because it sounds like someone is trying to scam you. Read more in my article on the Hot for Security blog.
  • ✇Schneier on Security
  • Some Claude Chats Are Searchable on Google Bruce Schneier
    And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses. What seems to be the issue is a user setting about data sharing. Anthropic’s position is that it’s not their problem: “We give people control over sh
     

Some Claude Chats Are Searchable on Google

4 de Agosto de 2026, 07:13

And it’s personal information (alternate link):

The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses.

What seems to be the issue is a user setting about data sharing. Anthropic’s position is that it’s not their problem:

“We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google,” the company said in a statement. “These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”

Here’s how to fix it.

Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure

A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning…

Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses

Blockchain analysts have linked a rapid series of Bitcoin wallet drains to a reported vulnerability in Coldcard firmware. A total of 1,196 addresses lost a combined 1,082.65 BTC, valued at approximately $70.2 million, in just 41 minutes on July 30, 2026. Galaxy Research stated that its transaction-flow analysis was based on a pattern initially identified […]

The post Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Online ad firm Adform’s script compromised to steal cryptocurrency

31 de Julho de 2026, 18:09
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
  • ✇Graham Cluley
  • North Korea’s elite hackers turned on their own government – and got caught Graham Cluley
    For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. Read more in my article
     

North Korea’s elite hackers turned on their own government – and got caught

30 de Julho de 2026, 06:17
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. Read more in my article on the Hot for Security blog.

What Is Cryptocurrency and How Does It Actually Work?

Learn how cryptocurrency works, from blockchains and wallets to private keys, custody, and secure transactions, with practical security tips. for confident use.
  • ✇Firewall Daily – The Cyber Express
  • Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure Samiksha Jain
    Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries. The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside th
     

Three Russians Indicted in $62M Cybercrime Scheme Targeting U.S. Infrastructure

Three Russian cybercrime indictment

Three Russian nationals have been charged in a sweeping Russian cybercrime indictment tied to an alleged bulletproof hosting operation that U.S. authorities say enabled ransomware, malware, phishing, and other cybercriminal activities, resulting in more than $62 million in losses to victims across the United States and several other countries.

The U.S. Attorney's Office for the Northern District of Ohio announced the unsealing of the indictment following a seven-year investigation. Alongside the criminal charges, the U.S. Department of State is offering a reward of up to $10 million for information on foreign government-linked associates connected to the operation.

Three Russian Nationals and Two Companies Indicted

A federal grand jury returned the indictment in December 2024 against:

  • Alexander Alexandrovich Volosovik, 43, of St. Petersburg, Russia
  • Kirill Andreevich Zatolokin, 34, of St. Petersburg, Russia
  • Yulia Vladimirovna Pankova, 29, of St. Petersburg, Russia
  • Media Land LLC
  • ML.Cloud LLC

The defendants face charges including conspiracy to commit computer fraud, wire fraud, money laundering, and aiding cybercriminal activities.

Russian cybercrime indictment

Assistant Attorney General A. Tysen Duva said the defendants allegedly operated criminal infrastructure from overseas that supported attacks against U.S. critical institutions and placed the public at risk.

Bulletproof Hosting Allegedly Enabled Cybercrime Operations

According to court documents, Media Land, owned by Volosovik, and ML.Cloud, owned by Pankova, provided internet infrastructure and server hosting services designed to help cybercriminals evade law enforcement.

Authorities allege the companies operated from St. Petersburg while maintaining infrastructure in multiple countries, including China, Finland, the Netherlands, and the United States.

The businesses allegedly offered bulletproof hosting services that enabled criminal clients to deploy malware and ransomware, extort victims for money and cryptocurrency, register fraudulent domains, operate criminal marketplaces, and launch phishing and brute-force attacks.

Investigators said the companies also provided technical support to cybercriminal customers, allowing malicious campaigns to continue while avoiding detection.

Victims Spanned Critical Sectors Across 21 States

Officials said the operation targeted dozens of organizations across 21 U.S. states as well as multiple countries.

Victims included:

  • Banks
  • Schools
  • Government entities
  • Hospitals
  • Media companies

Communities affected in Ohio included Akron, Brookfield, Canton, Cleveland, Elyria, Medina, Findlay, Solon, and Valley View.

Russian cybercrime indictment

Additional affected states included California, Florida, Georgia, Illinois, Louisiana, Maryland, Massachusetts, Michigan, Minnesota, New Hampshire, New York, North Carolina, Pennsylvania, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and Delaware.

International victims were identified in Australia, Canada, the European Union, the United Arab Emirates, and the United Kingdom.

FBI Cyber Division Assistant Director Brett Leatherman said Media Land enabled malicious activity that caused tens of millions of dollars in losses while impacting victims across multiple countries.

Russian Cybercrime Indictment Prompts $10 Million Reward Offer

The U.S. Department of State's Rewards for Justice program announced a reward of up to $10 million for actionable information regarding foreign government-linked associates of the indicted individuals, their malicious cyber activities, or foreign government-linked use of Media Land or ML.Cloud.

The program also noted that relocation assistance may be available for qualifying information.

International Sanctions Expand Pressure

The indictment follows coordinated international action against the alleged operators. In November 2025, the U.S. Department of the Treasury's Office of Foreign Assets Control, together with authorities from the United Kingdom and Australia, sanctioned Media Land for facilitating global ransomware operations, distributed denial-of-service attacks, and other malicious cyber activities.

The sanctions also targeted Volosovik, Zatolokin, and Pankova individually, along with Media Land subsidiaries Media Land Technology (MLT), Data Center Kirishi (DC Kirishi), and sister company ML Cloud.

On July 13, the European Union also announced sanctions against the companies and key individuals as part of broader efforts to disrupt cybercrime infrastructure.

International Agencies Back the Investigation

The investigation was led by the FBI Cleveland Division with support from the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Foreign Assets Control.

Authorities also received assistance from the National Police of the Netherlands, the Public Prosecutor's Office of the Netherlands, the United Kingdom's National Crime Agency, the United Kingdom Foreign Commonwealth and Development Office, the Australian Department of Foreign Affairs and Trade, and the Australian Federal Police.

Officials from CISA and partner agencies said disrupting bulletproof hosting providers remains essential because these services form a critical part of the cybercriminal ecosystem by enabling ransomware, phishing, malware, and other malicious operations while helping threat actors remain anonymous.

Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects

Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers.

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation

A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination.

The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42.

  • ✇Schneier on Security
  • Critical Zcash Vulnerability Found and Fixed Bruce Schneier
    If you’re a user—owner?—of this cryptocurrency, this is important: On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired Hornby specifically to look for this kind of issue. He found one fast enough to be embarrassing. The Orchard pool is the newest and most advanced shielded transaction system in the cryptocurrency Zcash. Introduced in 2022, it allows users to send and receive ZEC while keeping tr
     

Critical Zcash Vulnerability Found and Fixed

8 de Junho de 2026, 14:06

If you’re a user—owner?—of this cryptocurrency, this is important:

On May 29, the security researcher Taylor Hornby found a critical vulnerability in Zcash Orchard privacy pool using Claude Opus 4.8. The Zcash team hired Hornby specifically to look for this kind of issue. He found one fast enough to be embarrassing.

The Orchard pool is the newest and most advanced shielded transaction system in the cryptocurrency Zcash. Introduced in 2022, it allows users to send and receive ZEC while keeping transaction details private. It uses zero-knowledge proofs to validate transactions without revealing amounts or participants. The bug: a specific check that was supposed to validate transaction inputs wasn’t actually enforcing the rules it appeared to enforce. An attacker could have exploited the flaw to feed false inputs into that check and generate ZEC from nothing, with the zero-knowledge proof system blessing the fraudulent transaction as valid.

It’s fixed; that’s the good news. The bad news is that there’s no way of knowing if anyone exploited the vulnerability to steal money. And this fragility is the fundamental problem that makes blockchain such a bad idea.

OverlayPhantom Android Banking Trojan Targets 180+ Financial Apps Across 10 Countries

OverlayPhantom

A newly discovered Android banking trojan known as OverlayPhantom is raising concerns among cybersecurity researchers after evidence revealed that the malware is actively targeting banking, financial, and cryptocurrency users across multiple Western countries.  The malware campaign, uncovered by Cyble Research and Intelligence Labs (CRIL), demonstrates how modern threat actor groups are combining social engineering, remote device control, phishing overlays, and real-time surveillance capabilities into a single malicious framework.  According to researchers, OverlayPhantom has been active since May 2025 and is currently targeting more than 180 applications across 10 countries, including the United States, Australia, Germany, France, Belgium, Finland, the Netherlands, Italy, Spain, and the United Kingdom. The Android banking trojan is being distributed via malicious URLs that impersonate trusted applications, attempting to trick users into installing infected APK files. 

OverlayPhantom Uses Trusted Brands to Infect Victims 

The initial OverlayPhantom sample was discovered on a malicious domain distributing a fake version of ID Austria, the Austrian government’s official digital identity application. Researchers noted that the use of a government-themed lure increased the effectiveness of the malware campaign because victims are more likely to trust requests tied to identity verification or public services. A second sample linked to the same threat actor impersonated TikTok and appeared to focus on users in Spain. The shift from a government application to a mainstream social media platform suggested that the operators behind OverlayPhantom are deliberately broadening their infection strategies to target both institutional trust and consumer familiarity. CRIL researchers stated that the Android banking trojan employs a two-stage infection process. Victims initially download a dropper application that displays what appears to be a legitimate Google Play update screen. The fake update interface is designed to reduce suspicion and persuade users to continue the installation process. The malware also includes a guided tutorial that instructs victims on how to enable Android Accessibility Service permissions — a critical step that grants the threat actor elevated access to the infected device.

Android Banking Trojan Abuses Accessibility Services

Once installed, OverlayPhantom disguises itself as “Google Play Services,” making the malicious application harder for users to detect or remove. Researchers said the Android banking trojan abuses Android’s Accessibility Service to monitor user activity, intercept inputs, simulate gestures, and maintain persistent device control.  The malware establishes communication with its command-and-control (C&C) infrastructure through the IP address hxxps://199.217[.]99[.]122 using three separate ports dedicated to different tasks: 
  • Port 9092 handles device status reporting
  • Port 9091 is used for command-and-control communication
  • Port 9090 supports screen streaming functionality
Researchers found that OverlayPhantom can execute more than 30 remote commands issued by the threat actor. These commands allow attackers to perform taps, swipes, long presses, open recent apps, manipulate clipboard contents, increase or lower volume, lock screens, display fake notifications, and even launch fraudulent overlay windows designed to capture passwords or PINs. The Android banking trojan also supports commands such as startStreamJpeg and stopStreamJpeg, enabling remote screen streaming sessions.

OverlayPhantom Conducts Advanced Overlay Attacks 

One of the most dangerous features of OverlayPhantom is its use of embedded HTML phishing overlays. The malware continuously monitors which applications are running in the foreground and compares them against a hardcoded target list embedded within the APK. When a targeted banking or cryptocurrency application is opened, the Android banking trojan launches a counterfeit login page through an embedded WebView. Researchers said these phishing interfaces are carefully designed to visually match legitimate financial applications, making them difficult for victims to distinguish from the real apps. From the user’s perspective, the fake login screen appears authentic. However, any credentials entered into the overlay are immediately harvested and transmitted back to the threat actor’s infrastructure. CRIL researchers noted that OverlayPhantom specifically targets banking, finance, and cryptocurrency platforms, reflecting a financially motivated operation focused on large-scale fraud.

Real-Time Screen Streaming Expands Threat Actor Capabilities 

OverlayPhantom also includes a built-in real-time screen streaming mechanism powered by Android’s MediaProjection API. When activated, the malware captures screen activity through a VirtualDisplay instance named “jpeg-stream” and continuously transmits compressed JPEG images back to the C&C server over port 9090.  The captured output is resized to a fixed width of 540 pixels while preserving the original aspect ratio of the victim’s device. Researchers explained that JPEG compression helps reduce bandwidth usage while still giving the threat actor near real-time visibility into user activity.  The malware also contains resilience mechanisms to maintain streaming sessions. If the connection drops or no image frames are available, OverlayPhantom pauses briefly before attempting reconnection. Once retry limits are exceeded, the malware disables the streaming session to avoid endless reconnection loops. According to researchers, the operator can terminate screen streaming at any moment by issuing the stopStreamJpeg command.

Researchers Warn OverlayPhantom Threat May Expand 

Cybersecurity researchers described OverlayPhantom as a “mature and methodically engineered Android banking trojan” due to its combination of phishing overlays, Accessibility Service abuse, multi-port communication infrastructure, and remote device manipulation features. While many of the individual techniques used by the malware are not entirely new, researchers warned that the coordinated integration of government impersonation, consumer application lures, credential theft overlays, and real-time surveillance capabilities makes this threat actor particularly dangerous. The report concluded that the operational scale of OverlayPhantom — including its targeting of more than 180 applications across multiple countries — indicates that the Android banking trojan campaign may continue expanding in scope and sophistication in the coming months. Security experts advised organizations and individuals in affected regions to treat OverlayPhantom as a high-priority threat due to its ability to silently harvest credentials, monitor device activity, and facilitate financial fraud without obvious signs of compromise.

Closing the Gap: The Regulatory and Structural Maturation of Digital Assets

Digital assets are reshaping global finance as institutions adopt regulated crypto infrastructure, stablecoins, and tokenized assets.

Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

15 de Maio de 2026, 07:00

Unit 42 analyzes the evolution of Gremlin stealer. This variant uses advanced obfuscation, crypto clipping and session hijacking to compromise data.

The post Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files appeared first on Unit 42.

❌
❌