Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.

The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in… Continue reading Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Posted in Uncategorized

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week’s trouble came dressed as something useful.

A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and norma… Continue reading ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Posted in Uncategorized

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.

The implant never opens an out… Continue reading Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Posted in Uncategorized

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loa… Continue reading China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Posted in Uncategorized