Topic

Malware & Threat Actors

New malware families, backdoors, and advanced threat groups tracked by intelligence teams.

41 articles in this topic

Malware & Threat Actors

DAEMON Tools Supply Chain Backdoor: SAMA Bank Endpoint Risk

Kaspersky uncovered a trojanized DAEMON Tools installer distributing a Chinese-linked backdoor through the vendor's official domain since April 8, 2026 — a direct test of SAMA CSCC software supply chain controls.

7 May 2026 4 min
Vulnerabilities

CVE-2026-32202: APT28's Zero-Click Windows Shell Threat to SAMA Banks

A zero-click Windows Shell vulnerability (CVE-2026-32202) is being weaponized by Russian APT28 to silently harvest NTLMv2 credentials. Saudi banks face an urgent patching window before May 12.

7 May 2026 4 min
Malware & Threat Actors

MuddyWater's Teams Attack: Iranian APT Threat to SAMA Banks

Iranian state-sponsored MuddyWater is exploiting Microsoft Teams screen-share to harvest credentials and bypass MFA, while masking espionage as Chaos ransomware. Implications for SAMA-regulated banks.

6 May 2026 4 min
Vulnerabilities

CVE-2026-32202 Zero-Click NTLM Leak: APT28 Threat to SAMA Banks

Microsoft and CISA confirmed active exploitation of CVE-2026-32202, a zero-click Windows Shell flaw leaking NTLM hashes. SAMA banks face urgent endpoint and SMB-egress risk.

5 May 2026 4 min
Malware & Threat Actors

Anatsa Trojan Hits 831 Banking Apps: SAMA Mobile Banking Defense

Zscaler ThreatLabz uncovered Anatsa's expansion to 831 financial apps with stealthier evasion. SAMA banks must reinforce mobile defense under CSCC mandates.

4 May 2026 4 min
Malware & Threat Actors

Initial Access Brokers Hit GCC Finance: SAMA Bank Defense Playbook

Threat actor "Crimson" listed super-admin access to a GCC finance department in late April 2026. Here is what SAMA-regulated banks must do to defend against initial access brokers before ransomware affiliates buy in.

4 May 2026 4 min
Ransomware

ScreenConnect CVE-2024-1708: Medusa Ransomware Threat to SAMA Banks

CISA added ConnectWise ScreenConnect CVE-2024-1708 to the KEV catalog on April 28, 2026, after China-linked Storm-1175 and North Korean Kimsuky weaponized the path-traversal flaw to deploy Medusa ransomware and ToddlerShark malware against managed service providers and their downstream customers.

3 May 2026 4 min
Breaches & Data Leaks

REF6598 & PHANTOMPULSE: How Hackers Are Weaponizing Obsidian's Plugin Ecosystem to Breach Financial Sector Employees

A sophisticated threat actor is abusing the Obsidian note-taking app's community plugin ecosystem to silently install a new RAT on financial employees' machines — no CVE, no exploit, just trusted software turned weapon.

19 Apr 2026 6 min
Vulnerabilities

CVE-2026-39987: Hackers Exploit Marimo AI Notebook to Deploy Blockchain Backdoor via Hugging Face

A CVSS 9.3 RCE flaw in the Marimo AI notebook tool was weaponized within 10 hours of disclosure, delivering NKAbuse — a Go-based backdoor using blockchain C2 — via a typosquatted Hugging Face Space. Saudi financial institutions adopting AI tooling must act now.

18 Apr 2026 5 min
Malware & Threat Actors

PHANTOMPULSE RAT: When Your Note-Taking App Becomes a Weapon Against Financial Sector Employees

A new attack campaign (REF6598) weaponizes the Obsidian note-taking app to deliver PHANTOMPULSE RAT against financial sector employees — bypassing EDR entirely by abusing legitimate software. Saudi CISOs must understand this threat now.

18 Apr 2026 5 min
Breaches & Data Leaks

North Korean Hackers Drain $285M from Drift Protocol in 12 Minutes: What Saudi Financial Institutions Must Know

North Korean hackers drained $285M from Drift Protocol in just 12 minutes on April 1, 2026 using fake CVT tokens as collateral. Saudi CISOs must understand what this means for digital asset risk under SAMA's evolving framework.

16 Apr 2026 5 min
Malware & Threat Actors

CPUID Supply Chain Attack: How STX RAT Hijacked CPU-Z and HWMonitor — A Warning for Saudi Financial IT Teams

On April 9–10, 2026, attackers hijacked CPUID's official download servers to distribute STX RAT via trojanized CPU-Z and HWMonitor installers. Here's what Saudi financial institutions need to know.

15 Apr 2026 6 min

Start a conversation

What are you working through?

Describe where you stand, and a specialist will reply with a clear next step — not a generic pitch.

  • A free first consultation
  • A reply within one business day
  • Full confidentiality