Topic
Malware & Threat Actors
New malware families, backdoors, and advanced threat groups tracked by intelligence teams.
41 articles in this topic
MuddyWater's False-Flag Playbook: Iranian APT Hides Espionage Behind Chaos Ransomware
Iranian APT MuddyWater deployed Chaos ransomware as a decoy while conducting espionage via Microsoft Teams social engineering. Saudi CISOs must rethink their IR playbooks.
Malware & Threat ActorsMuddyWater's Chaos Ransomware Deception: Iranian Espionage Targeting Banks Under False Flag
Iranian APT MuddyWater deploys Chaos ransomware branding to disguise espionage operations targeting banks and defense contractors. Rapid7 research reveals no encryption — only data theft and credential harvesting behind a ransomware smokescreen.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction
An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware
Rapid7 unmasks MuddyWater's Chaos ransomware campaign as Iranian state espionage. Critical lessons for Saudi financial sector CISOs on detecting false-flag operations.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware via Microsoft Teams
Iranian state-sponsored group MuddyWater weaponized Microsoft Teams screen-sharing to steal credentials and bypass MFA, planting Chaos ransomware artifacts as a decoy to hide espionage targeting banks and critical infrastructure.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Shell Flaw to Steal NTLM Credentials
Russian APT28 weaponizes an incomplete Windows Shell patch to silently harvest NTLM hashes — no clicks required. Here's what Saudi CISOs must do now.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today
A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.
Malware & Threat ActorsTCLBANKER Trojan Spreads via WhatsApp to Target 59 Financial Platforms
A new banking trojan called TCLBANKER hijacks WhatsApp and Outlook to spread across 3,000 contacts per victim, targeting 59 financial platforms with full-screen credential overlays.
Malware & Threat ActorsJDownloader Python RAT Supply Chain Attack: SAMA Bank Risk
Attackers compromised the official JDownloader website between May 6 and May 7, 2026, swapping legitimate Windows and Linux installers with a modular Python RAT. Here is what SAMA-regulated banks must do now.
RansomwareAnubis Ransomware Adds Wiper: Critical Risk to SAMA Banks
Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.
Cloud & IdentityMuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.
Malware & Threat ActorsGopherWhisper APT: Slack & Microsoft 365 C2 Risk to SAMA Banks
ESET unveils GopherWhisper — a China-aligned APT using Discord, Slack and Microsoft 365 Outlook as covert C2. SAMA-regulated banks face the same legitimate-service abuse risk and must rethink detection.