Visualização normal

Antes de ontemStream principal
  • ✇Firewall Daily – The Cyber Express
  • Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns Samiksha Jain
    The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge. According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity
     

Hackers Target Social Media Accounts to Steal Explicit Content, FBI Warns

13 de Agosto de 2026, 03:10

sexual exploitation actors

The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.

According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.

The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.

How Sexual Exploitation Actors Access Accounts

The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.

Password and PIN Targeting

In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.

When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.

Social Media Customer Service Impersonation

Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.

The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.

Phishing Emails

The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.

These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.

Stolen Content Can Lead to Further Attacks

Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.

The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.

FBI Shares Steps to Protect Accounts

The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.

It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.

Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.

Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.

People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.
  • ✇Firewall Daily – The Cyber Express
  • South Korea Military Faces Highest Cyberattack Volume Since 2021 Ashish Khaitan
    Cyberattacks on South Korea military reached their highest level in five years in 2025, highlighting growing cybersecurity risks as the Ministry of National Defense struggles to retain trained cyber specialists. The rise in attacks, coupled with phishing emails and concerns over North Korea’s expanding cyber capabilities, has intensified calls for stronger defense measures.  According to data submitted by the Ministry of National Defense to Rep. Yu Yong-weon of the main opposition People Powe
     

South Korea Military Faces Highest Cyberattack Volume Since 2021

Cyberattacks on South Korea military

Cyberattacks on South Korea military reached their highest level in five years in 2025, highlighting growing cybersecurity risks as the Ministry of National Defense struggles to retain trained cyber specialists. The rise in attacks, coupled with phishing emails and concerns over North Korea’s expanding cyber capabilities, has intensified calls for stronger defense measures.  According to data submitted by the Ministry of National Defense to Rep. Yu Yong-weon of the main opposition People Power Party and a member of the National Assembly’s National Defense Committee, cyberattacks on South Korea military systems declined from 11,700 cases in 2021 to 9,115 in 2022 before increasing to 13,599 in 2023 and 14,419 in 2024. Last year, the number surged to 18,951, representing a 108 percent increase from 2022 and a 31 percent rise compared with 2024, making it the highest annual total in the past five years. 

Cyberattacks on South Korea Military

Most cyberattacks on South Korea military networks involved attempts to gain administrator privileges and compromise military websites, accounting for 18,792 incidents in 2025. Meanwhile, phishing emails disguised as messages from trusted senders rose sharply from just 16 cases in 2023 to 127 last year, indicating that cyberattack methods have become increasingly diverse. “Recent signs indicate that North Korea has begun using AI in its hacking operations, including malware development and attempts to infiltrate organizations through fake job applications, which allude to its cyber capabilities’ increasing sophistication,” the Cyber Operations Command said in materials submitted to Yu’s office.  The concerns come as North Korea is expected to strengthen cyber operations by expanding its Reconnaissance General Bureau, while South Korea’s Defense Counterintelligence Command has been effectively dismantled. 

Ministry of National Defense Faces Cyber Workforce Challenges 

Despite rising cyberattacks on South Korea military infrastructure, the Ministry of National Defense continues to face difficulties retaining cybersecurity personnel. Since 2012, the ministry has operated a cyber officer cadet program that provides approximately 40 million won (US$26,700) in tuition support to students in designated university departments. Graduates are commissioned as officers and assigned to units including the Cyber Operations Command and the 777 Command, where they conduct cyber threat analysis, cybersecurity operations, and digital forensics.  However, data obtained by Yu’s office shows that 89 of the 104 cyber specialist officers commissioned between 2016 and 2019—around 85 percent—left in the military after completing their mandatory seven-year service. Last year, only seven of 24 graduates accepted commissions. Although those declining military service members must repay their financial assistance, some have chosen that option instead, largely due to stronger demand, higher salaries, and better working conditions in the private AI and cybersecurity sectors. 

Growing North Korean Cyber Threat 

North Korean leader Kim Jong-un recently ordered the expansion of the Reconnaissance General Bureau, the country's primary intelligence agency responsible for overseas intelligence gathering, operations targeting South Korea, and cyber activities. During an expanded meeting of the Central Military Commission of the ruling Workers’ Party, reported by the state-run Rodong Sinmun, officials proposed expanding the bureau’s responsibilities and strengthening its reconnaissance and intelligence capabilities.  Created by reorganizing the former Reconnaissance Bureau under the Korean People’s Army General Staff, the agency is believed by South Korean military intelligence to oversee around 8,400 hackers. Analysts expect that number to increase following Kim’s directive.  “At a time when North Korea is rapidly advancing its cyberattack capabilities, we cannot allow a system in which cyber specialists simply leave the military after fulfilling their mandatory service,” Rep. Yu said. “We need a systematic personnel management system that covers the recruitment, training and long-term retention of cyber experts.” 
  • ✇Firewall Daily – The Cyber Express
  • JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign Samiksha Jain
    A newly identified cyber campaign involving JanaWare ransomware is targeting users in Turkey, with researchers linking the activity to a customized version of the Adwind Remote Access Trojan (RAT). The findings come from an analysis by researchers at Acronis’ Threat Research Unit (TRU), who identified the threat cluster during an investigation into suspicious Java-based malware samples. According to the researchers, the JanaWare ransomware operation appears to have been active since at least
     

JanaWare Ransomware Targets Turkish Users Through Adwind RAT Campaign

JanaWare Ransomware Targets Turkish Users

A newly identified cyber campaign involving JanaWare ransomware is targeting users in Turkey, with researchers linking the activity to a customized version of the Adwind Remote Access Trojan (RAT). The findings come from an analysis by researchers at Acronis’ Threat Research Unit (TRU), who identified the threat cluster during an investigation into suspicious Java-based malware samples. According to the researchers, the JanaWare ransomware operation appears to have been active since at least 2020. Evidence from malware samples and infrastructure indicates that the campaign has continued into late 2025, suggesting sustained activity with limited visibility. The attack relies on a modified Adwind RAT that includes polymorphic capabilities. This allows the malware to change its structure across infections, making detection more difficult. Combined with code obfuscation, these techniques have likely contributed to the campaign remaining relatively unnoticed. Unlike large ransomware groups that focus on high-value enterprise targets, JanaWare ransomware appears to follow a different strategy. Observed ransom demands range between $200 and $400, pointing to a model that prioritizes volume over large individual payouts.

Phishing Identified as Primary Infection Vector

The JanaWare ransomware campaign primarily spreads through phishing emails. Victims are lured into clicking malicious links, which lead to the download of a Java archive file. In many observed cases, the payload is hosted on cloud storage platforms. Telemetry data reviewed by researchers shows a consistent attack chain. A phishing email is opened in Microsoft Outlook, followed by a browser session that downloads the malicious file. The file is then executed using Java, triggering the infection. [caption id="attachment_111347" align="aligncenter" width="761"]JanaWare Ransomware Image Source: Acronis’ Threat Research Unit (TRU)[/caption] User reports on public cybersecurity forums also describe similar incidents, supporting the assessment that phishing is the main entry point.

Geofencing Restricts Janaware Ransomware Attacks to Turkey

A key feature of the JanaWare ransomware is its use of geofencing. The malware is designed to execute only on systems that meet specific regional criteria linked to Turkey. It checks system language, locale settings, and external IP geolocation before proceeding. If the system does not match Turkish parameters, the malicious activity is halted. Researchers note that this approach likely serves both operational and defensive purposes. It allows attackers to focus on a specific region while reducing exposure to global security monitoring and automated analysis systems.

Obfuscation and Polymorphism Hinder Detection

The JanaWare ransomware incorporates multiple techniques to evade detection. Researchers identified the use of known obfuscation tools such as Stringer and Allatori, alongside custom methods that complicate analysis. The malware also includes a self-modifying component that alters its file structure during deployment. By adding random data to its Java archive, each instance generates a unique file hash, limiting the effectiveness of signature-based detection. In addition, the malware contains embedded configuration parameters that control its behavior. These include command-and-control server details, communication ports, and authentication values used during initial connections.

Security Controls Disabled Before Encryption Stage

Before encrypting files, the malware attempts to weaken system defenses. It executes commands to disable Microsoft Defender, suppress security alerts, and remove recovery mechanisms such as Volume Shadow Copies. It also interferes with Windows Update and scans for installed antivirus software. These steps reduce the likelihood of detection or recovery once the ransomware payload is activated. The encryption process is carried out by a secondary module delivered after the initial compromise. This module uses AES encryption and communicates with command-and-control infrastructure over the Tor network.

Turkish-Language Ransom Notes Signal Targeted Approach

After encryption, the malware drops ransom notes across affected systems. These notes are written in Turkish and instruct victims to contact the attackers through encrypted communication channels such as qTox or Tor-based websites. Researchers say the consistent use of Turkish-language content, combined with geofencing, indicates a deliberate focus on users in Turkey rather than a broad, global campaign. The JanaWare ransomware campaign highlights how targeted, lower-profile operations can persist over long periods without drawing significant attention. By focusing on home users and small businesses, and keeping ransom demands relatively low, the attackers appear to maintain a steady but less visible operation. Researchers caution that such localized campaigns may continue to operate alongside larger ransomware groups, adding another layer to the evolving threat landscape.
❌
❌