Topic
Malware & Threat Actors
New malware families, backdoors, and advanced threat groups tracked by intelligence teams.
41 articles in this topic
Adobe's BPO Backdoor: How 'Mr. Raccoon' Stole 13M Support Tickets — and What Saudi Financial Institutions Must Learn About Vendor Risk
A threat actor called "Mr. Raccoon" compromised an Indian BPO contractor via RAT malware, exfiltrating 13M Adobe support tickets, 15K employee records, and unpublished HackerOne vulnerability reports — a masterclass in third-party risk gone wrong.
Malware & Threat ActorsCVE-2026-40175: Axios Gets Hit Twice — North Korean Backdoor Then a 9.9 CVSS Flaw That Hands Attackers Your AWS Keys
Axios npm suffered a North Korean supply chain backdoor in March, then a 9.9 CVSS flaw a week later. Saudi open banking teams running Node.js on AWS need to act before threat actors chain both.
Malware & Threat ActorsCPUID Supply Chain Breach: How STX RAT Hijacked CPU-Z & HWMonitor — A Wake-Up Call for Saudi Data Centers
On April 9, 2026, attackers quietly replaced CPUID's legitimate CPU-Z and HWMonitor downloads with trojanized packages delivering STX RAT — a full-featured remote access trojan. If your data center team downloaded hardware monitoring tools that week, read this now.
Breaches & Data LeaksMr. Raccoon's Adobe Breach: How One BPO Contractor Exposed 13M Support Tickets
A single malware-infected BPO contractor handed threat actor "Mr. Raccoon" 13 million Adobe support tickets. Here is what Saudi financial institutions relying on outsourced IT support must do right now.
Malware & Threat ActorsNorth Korea Stole $285M in 12 Minutes: The DPRK Infiltration Playbook Every Saudi CISO Must Study
North Korean hackers UNC4736 spent six months posing as a legitimate trading firm before draining $285M in 12 minutes. Saudi CISOs must understand this playbook—it maps directly to SAMA CSCC third-party and insider-threat domains.
Malware & Threat ActorsSpyrtacus WhatsApp Clone: Italian Spyware Vendor Weaponized a Fake App to Surveil 200 Targets
Meta warned 200 users that a counterfeit WhatsApp app built by Italian surveillance firm Asigint had been silently harvesting their data. Here's what Saudi CISOs need to know about mobile spyware threats targeting financial institutions.
Malware & Threat ActorsFake Claude Code Leak on GitHub Delivers Vidar Stealer — Why Saudi Bank Dev Teams Must Vet Every Download
A fake Claude Code repository on GitHub is delivering Vidar infostealer and GhostSocks proxy malware to developers who download it. Here's what Saudi bank security teams need to know — and do — right now.
Malware & Threat ActorsWhatsApp Spyrtacus Alert: How Government-Grade Spyware Is Targeting Mobile Apps Saudi Banks Use Every Day
Meta's WhatsApp has flagged a government-grade spyware campaign using a counterfeit iOS app to harvest messages, calls, and recordings from targets' devices. For Saudi financial institutions relying on WhatsApp for business communications, the compliance and security implications are immediate.
Malware & Threat ActorsHandala Wiped 200,000 Stryker Devices in Minutes — The Intune Attack Vector Saudi Banks Cannot Ignore
On March 11, 2026, Iran-linked Handala triggered simultaneous factory resets on 200,000+ corporate devices at Stryker using Microsoft Intune. If your bank runs Azure AD, this attack vector is already in your environment.
Malware & Threat ActorsDPRK Steals $285M via Drift Protocol: What Saudi Financial Firms Must Know
North Korean threat actors linked to the Lazarus Group stole $285M from Drift Protocol using a legitimate Solana feature as a weapon — here's what this means for Saudi financial institutions.
Malware & Threat ActorsOperation NoVoice: Android Rootkit on Google Play Threatens Mobile Banking Security
McAfee uncovers Operation NoVoice — a rootkit infecting 2.3M Android devices via Google Play that survives factory resets and clones WhatsApp sessions. Critical implications for Saudi financial institutions.
Supply Chain & Third PartyAxios NPM Supply Chain Attack: North Korean Hackers Weaponize JavaScript's Most Popular HTTP Client
North Korean threat actors hijacked the Axios npm package — 100 million weekly downloads — to deploy a cross-platform RAT. Here's what Saudi financial institutions need to know and do right now.