Topic

Malware & Threat Actors

New malware families, backdoors, and advanced threat groups tracked by intelligence teams.

41 articles in this topic

Malware & Threat Actors

MuddyWater's False-Flag Playbook: Iranian APT Hides Espionage Behind Chaos Ransomware

Iranian APT MuddyWater deployed Chaos ransomware as a decoy while conducting espionage via Microsoft Teams social engineering. Saudi CISOs must rethink their IR playbooks.

19 May 2026 5 min
Malware & Threat Actors

MuddyWater's Chaos Ransomware Deception: Iranian Espionage Targeting Banks Under False Flag

Iranian APT MuddyWater deploys Chaos ransomware branding to disguise espionage operations targeting banks and defense contractors. Rapid7 research reveals no encryption — only data theft and credential harvesting behind a ransomware smokescreen.

18 May 2026 5 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction

An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.

17 May 2026 6 min
Malware & Threat Actors

MuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware

Rapid7 unmasks MuddyWater's Chaos ransomware campaign as Iranian state espionage. Critical lessons for Saudi financial sector CISOs on detecting false-flag operations.

17 May 2026 5 min
Malware & Threat Actors

MuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware via Microsoft Teams

Iranian state-sponsored group MuddyWater weaponized Microsoft Teams screen-sharing to steal credentials and bypass MFA, planting Chaos ransomware artifacts as a decoy to hide espionage targeting banks and critical infrastructure.

16 May 2026 5 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Shell Flaw to Steal NTLM Credentials

Russian APT28 weaponizes an incomplete Windows Shell patch to silently harvest NTLM hashes — no clicks required. Here's what Saudi CISOs must do now.

15 May 2026 5 min
Vulnerabilities

CVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today

A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.

12 May 2026 4 min
Malware & Threat Actors

TCLBANKER Trojan Spreads via WhatsApp to Target 59 Financial Platforms

A new banking trojan called TCLBANKER hijacks WhatsApp and Outlook to spread across 3,000 contacts per victim, targeting 59 financial platforms with full-screen credential overlays.

11 May 2026 5 min
Malware & Threat Actors

JDownloader Python RAT Supply Chain Attack: SAMA Bank Risk

Attackers compromised the official JDownloader website between May 6 and May 7, 2026, swapping legitimate Windows and Linux installers with a modular Python RAT. Here is what SAMA-regulated banks must do now.

11 May 2026 4 min
Ransomware

Anubis Ransomware Adds Wiper: Critical Risk to SAMA Banks

Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.

10 May 2026 4 min
Cloud & Identity

MuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide

Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.

9 May 2026 4 min
Malware & Threat Actors

GopherWhisper APT: Slack & Microsoft 365 C2 Risk to SAMA Banks

ESET unveils GopherWhisper — a China-aligned APT using Discord, Slack and Microsoft 365 Outlook as covert C2. SAMA-regulated banks face the same legitimate-service abuse risk and must rethink detection.

8 May 2026 4 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality