Posts

Showing posts from October, 2025

Dutch government takes control of China-owned chip firm

Image
  The Dutch government has taken control of Nexperia, a Chinese-owned chipmaker based in the Netherlands, in a bid to safeguard the European supply of semiconductors for cars and other electronic goods and protect Europe's economic security. The Hague said it took the decision due to "serious governance shortcomings" and to prevent the chips from becoming unavailable in an emergency. Nexperia's owner Wingtech said on Monday that it would take actions to protect its rights and would seek government support. The development threatens to raise tensions between the European Union and China, which have increased in recent months over trade and Beijing's relationship with Russia. In December 2024, the US government placed Wingtech on its so-called "entity list", identifying the company as a national security concern. Under the regulations, US companies are barred from exporting American-made goods to businesses on the list unless they have special approval. In...

Hackers Turn Velociraptor DFIR Tool Into Weapon in LockBit Ransomware Attacks

Image
Threat actors are abusing Velociraptor, an open-source digital forensics and incident response (DFIR) tool, in connection with ransomware attacks likely orchestrated by  Storm-2603  (aka CL-CRI-1040 or Gold Salem), which is known for deploying the Warlock and LockBit ransomware. The threat actor's use of the security utility was  documented  by Sophos last month. It's assessed that the attackers weaponized the on-premises SharePoint vulnerabilities known as ToolShell to obtain initial access and deliver an outdated version of Velociraptor (version 0.73.4.0) that's susceptible to a privilege escalation vulnerability ( CVE-2025-6264 ) to enable arbitrary command execution and endpoint takeover, per  Cisco Talos . In the attack in mid-August 2025, the threat actors are said to have made attempts to escalate privileges by creating domain admin accounts and moving laterally within the compromised environment, as well as leveraging the access to run tools like Smbexec...

Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns

Image
Cybersecurity researchers are calling attention to a new campaign that delivers the   Astaroth   banking trojan that employs GitHub as a backbone for its operations to stay resilient in the face of infrastructure takedowns. "Instead of relying solely on traditional command-and-control (C2) servers that can be taken down, these attackers are leveraging GitHub repositories to host malware configurations," McAfee Labs researchers Harshil Patel and Prabudh Chakravorty  said  in a report. "When law enforcement or security researchers shut down their C2 infrastructure, Astaroth simply pulls fresh configurations from GitHub and keeps running." The activity, per the cybersecurity company, is primarily focused on Brazil, although the banking malware is known to target various countries in Latin America, including Mexico, Uruguay, Argentina, Paraguay, Chile, Bolivia, Peru, Ecuador, Colombia, Venezuela, and Panama. This is not the first time Astaroth campaigns have trained the...

New Rust-Based Malware "ChaosBot" Uses Discord Channels to Control Victims' PCs

Image
  Cybersecurity researchers have disclosed details of a new Rust-based backdoor called   ChaosBot   that can allow operators to conduct reconnaissance and execute arbitrary commands on compromised hosts. "Threat actors leveraged compromised credentials that mapped to both Cisco VPN and an over-privileged Active Directory account named, 'serviceaccount,'" eSentire  said  in a technical report published last week. "Using the compromised account, they leveraged WMI to execute remote commands across systems in the network, facilitating the deployment and execution of ChaosBot." The Canadian cybersecurity company said it first detected the malware in late September 2025 within a financial services customer's environment. ChaosBot  is noteworthy for its abuse of Discord for command-and-control (C2). It gets its name from a Discord profile maintained by the threat actor behind it, who goes by the online moniker "chaos_00019" and is responsible for iss...

Microsoft Locks Down IE Mode After Hackers Turned Legacy Feature Into Backdoor

Image
Microsoft said it has revamped the Internet Explorer (IE) mode in its Edge browser after receiving "credible reports" in August 2025 that unknown threat actors were abusing the   backward compatibility feature   to gain unauthorized access to users' devices. "Threat actors were leveraging basic social engineering techniques alongside unpatched (0-day) exploits in Internet Explorer's JavaScript engine (Chakra) to gain access to victim devices," the Microsoft Browser Vulnerability Research team  said  in a report published last week. In the attack chain documented by the Windows maker, the threat actors have been found to trick unsuspecting users into visiting an seemingly legitimate website and then employ a  flyout  on the page to instruct them into reloading the page in IE mode. Once the page is reloaded, the attackers are said to have weaponized an unspecified exploit in the Chakra engine to obtain remote code execution. The infection sequence culminates ...

Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors

Image
  Malware campaigns distributing the   RondoDox   botnet have expanded their targeting focus to exploit more than 50 vulnerabilities across over 30 vendors. The activity,  described  as akin to an "exploit shotgun" approach, has singled out a wide range of internet-exposed infrastructure, including routers, digital video recorders (DVRs), network video recorders (NVRs), CCTV systems, web servers, and various other network devices, according to Trend Micro. The cybersecurity company said it detected a RondoDox intrusion attempt on June 15, 2025, when the attackers exploited  CVE-2023-1389 , a security flaw in TP-Link Archer routers that has  come under active exploitation  repeatedly since it was first disclosed in late 2022. RondoDox was  first documented  by Fortinet FortiGuard Labs back in July 2025, detailing attacks aimed at TBK digital video recorders (DVRs) and Four-Faith routers to enlist them in a botnet for carrying out distribu...