Skip to content
Threat Feed

Tag

Cybercrime

4 briefs RSS
high threat

UAT-10147 Deploys SPECTRE Cross-Platform Backdoor

The threat actor UAT-10147 is deploying a sophisticated cross-platform backdoor named SPECTRE, featuring kernel-level rootkits, BYOVD defense evasion, and AI-assisted development artifacts to target IIS and Linux infrastructure.

Internet Information Services UAT-10147 backdoor cross-platform rootkit byovd e-commerce-fraud cybercrime agentic-ai web-exploitation +1
2r 6t 2i updated
high threat

Russian-Speaking Hacker 'bandcampro' Leverages Google Gemini CLI for Botnet Operations

A Russian-speaking threat actor known as 'bandcampro' is using Google's open-source Gemini CLI to manage and control a botnet of eight compromised dental clinic computers, facilitating activities such as password cracking, C2 infrastructure migration, and planning cryptocurrency fraud.

OpenDental bandcampro ai-assisted botnet cybercrime command-and-control powershell credential-access
1r 5t
high advisory

US Sanctions First VPN Service and Administrator for Aiding Ransomware Groups

The U.S. Treasury Department sanctioned First VPN Service (1VPNS) and its administrator, Dmytro Rashevskyi, for facilitating ransomware attacks by providing anonymity and evasion capabilities to cybercriminals, and also sanctioned Yegeniy Vladimirovich Silayev for selling 'cryptors' that make malware harder to detect, impacting critical infrastructure.

First VPN Service +2 sanctions vpn ransomware cybercrime defense-evasion
2t 2i
high advisory

Threat Activity Enablers (TAEs) Facilitating Cybercrime

Threat Activity Enablers (TAEs) are infrastructure providers and networks that support malicious cyber activity, including ransomware, botnets, and state-sponsored operations, by providing resilient and obfuscated infrastructure.

threat-infrastructure cybercrime hosting-provider
2r 1t