Cyware Feed
unc3944-threat-group-uses-azure-built-in-tools-to-abuse-azure-vms

UNC3944 Threat Group Uses Azure Built-in Tools to Abuse Azure VMs

Financially-motivated UNC3944 gang was found using phishing and SIM swapping attacks to hijack Microsoft Azure admin accounts and gain access to virtual machines to steal data from victim organizations. The threat actor gains initial access to an Azure administrator’s account by using stolen credentials obtained through SMS phishing. Experts recommend organizations should restrict access to […]

Cyware Feed
mustang-panda-hijacks-tp-link-routers-of-european-foreign-affairs-entities

Mustang Panda Hijacks TP-Link Routers of European Foreign Affairs Entities

European foreign affairs organizations are being targeted by a Chinese state-sponsored Camaro Dragon hacking group with a custom malware variant. This group has been found infecting residential TP-Link routers with a specialized malware called Horse Shell. Attackers can execute arbitrary commands, steal files, and even leverage the malware as a SOCKS proxy to facilitate communication […]