Topic
Malware & Threat Actors
New malware families, backdoors, and advanced threat groups tracked by intelligence teams.
41 articles in this topic
DAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk
Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.
VulnerabilitiesCVE-2026-32202: APT28's Zero-Click Windows Shell Threat to SAMA Banks
A zero-click Windows Shell vulnerability (CVE-2026-32202) is being weaponized by Russian APT28 to silently harvest NTLMv2 credentials. Saudi banks face an urgent patching window before May 12.
Malware & Threat ActorsMuddyWater's Teams Attack: Iranian APT Threat to SAMA Banks
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams screen-share to harvest credentials and bypass MFA, while masking espionage as Chaos ransomware. Implications for SAMA-regulated banks.
VulnerabilitiesCVE-2026-32202 Zero-Click NTLM Leak: APT28 Threat to SAMA Banks
Microsoft and CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell flaw leaking NTLM hashes. SAMA banks face urgent endpoint and SMB-egress risk.
Malware & Threat ActorsAnatsa Trojan Hits 831 Banking Apps: SAMA Mobile Banking Defense
Zscaler ThreatLabz uncovered Anatsa's expansion to 831 financial apps with stealthier evasion. SAMA banks must reinforce mobile defense under CSCC mandates.
Malware & Threat ActorsInitial Access Brokers Hit GCC Finance: SAMA Bank Defense Playbook
Threat actor "Crimson" listed super-admin access to a GCC finance department in late April 2026. Here is what SAMA-regulated banks must do to defend against initial access brokers before ransomware affiliates buy in.
RansomwareScreenConnect CVE-2024-1708: Medusa Ransomware Threat to SAMA Banks
CISA added ConnectWise ScreenConnect CVE-2024-1708 to the KEV catalog on April 28, 2026, after China-linked Storm-1175 and North Korean Kimsuky weaponized the path-traversal flaw to deploy Medusa ransomware and ToddlerShark malware against managed service providers and their downstream customers.
Breaches & Data LeaksREF6598 & PHANTOMPULSE: How Hackers Are Weaponizing Obsidian's Plugin Ecosystem to Breach Financial Sector Employees
A sophisticated threat actor is abusing the Obsidian note-taking app's community plugin ecosystem to silently install a new RAT on financial employees' machines — no CVE, no exploit, just trusted software turned weapon.
VulnerabilitiesCVE-2026-39987: Hackers Exploit Marimo AI Notebook to Deploy Blockchain Backdoor via Hugging Face
A CVSS 9.3 RCE flaw in the Marimo AI notebook tool was weaponized within 10 hours of disclosure, delivering NKAbuse — a Go-based backdoor using blockchain C2 — via a typosquatted Hugging Face Space. Saudi financial institutions adopting AI tooling must act now.
Malware & Threat ActorsPHANTOMPULSE RAT: When Your Note-Taking App Becomes a Weapon Against Financial Sector Employees
A new attack campaign (REF6598) weaponizes the Obsidian note-taking app to deliver PHANTOMPULSE RAT against financial sector employees — bypassing EDR entirely by abusing legitimate software. Saudi CISOs must understand this threat now.
Breaches & Data LeaksNorth Korean Hackers Drain $285M from Drift Protocol in 12 Minutes: What Saudi Financial Institutions Must Know
North Korean hackers drained $285M from Drift Protocol in just 12 minutes on April 1, 2026 using fake CVT tokens as collateral. Saudi CISOs must understand what this means for digital asset risk under SAMA's evolving framework.
Malware & Threat ActorsCPUID Supply Chain Attack: How STX RAT Hijacked CPU-Z and HWMonitor — A Warning for Saudi Financial IT Teams
On April 9–10, 2026, attackers hijacked CPUID's official download servers to distribute STX RAT via trojanized CPU-Z and HWMonitor installers. Here's what Saudi financial institutions need to know.