Palestinian women recount ‘journey of horror’ at Gaza’s Rafah crossing | Gaza News

0

Palestinian women tell of harrowing experience at hands of Israeli military at reopened Rafah border crossing in Gaza.

Palestinian women have described a “journey of horror” as they passed through the Rafah border crossing on their way home to Gaza from Egypt, with the few allowed to enter the war-torn territory being separated from their children, handcuffed, blindfolded, and interrogated “under threat” for hours.

For the 12 Palestinian women and children allowed to enter Gaza through the Rafah crossing on Monday, the journey back home was “long and exhausting, marked by waiting, fear and uncertainty”, Al Jazeera’s Ibrahim Al Khalili said, reporting from Khan Younis in southern Gaza.

Recommended Stories

list of 4 itemsend of list

The small group of returnees was subjected to harsh security procedures by Israeli forces who hold the power at the Rafah crossing to determine “when and if” people will be allowed to return to their homes in the Palestinian territory, Al Khalili said.

“They took everything from us. Food, drinks, everything. Allowing us to keep only one bag,” said one of the returnees, speaking to Al Jazeera about her ordeal at the hands of the Israeli military on Monday.

“The Israeli army called my mother first and took her. Then they called me, and took me,” the woman said.

“They blindfolded me and covered my eyes. They interrogated me in the first tent, asking why I wanted to enter Gaza. I told them I wanted to see my children and return to my country. They tried to pressure me psychologically, wanted to separate me from my children and force me into exile,” she said.

“After questioning me there, they took me to a second tent and asked political questions, which had nothing to do with [the journey]… They told me I could be detained if I didn’t answer. After three hours of interrogation under threat, we finally went on the bus. The UN received us; then we headed to Nasser Hospital. Thank God we were reunited with our loved ones,” she added.

Another member of the group, Huda Abu Abed, 56, told the Reuters news agency that passing through the Rafah border “was a journey of horror, humiliation and oppression”.

Accounts of being blindfolded, handcuffed and interrogated for hours by Israeli forces were given to reporters by three women, Reuters said.

Some 50 Palestinians had been expected to enter the enclave on Monday, but by nightfall, only 12 – three women and nine children – had been allowed through the reopened crossing by Israeli authorities, Reuters said, citing Palestinian and Egyptian sources.

Worse still, of the 50 people waiting to leave Gaza on Monday, mostly for critical medical treatment, only five patients with seven relatives escorting them managed to clear the Israeli inspections and cross into Egypt.

On Tuesday, just 16 more Palestinian patients were allowed to cross into Egypt via Rafah, Al Jazeera’s Hind Khoudary said, reporting from Khan Younis.

The numbers being allowed to cross at Rafah are far below the 50 Palestinians who Israeli officials said would be allowed to travel in each direction via the crossing every day, Khoudary said.

“There is no explanation as to why crossings are being delayed at Rafah,” Khoudary said. “The process is taking an extremely long time.”

“There are about 20,000 people waiting [in Gaza] for urgent medical attention abroad,” she added.



Source link

Why one should focus on IT stocks, Vakrangee, IEX, Varroc, Yaan Enterprises, Kinetic Engineering, Bajaj Electricals, Nazara, YES Bank in today’s trade

0

Shares of Indian IT companies such as Infosys Ltd., wipro, Tata Consultancy Services, Persistent Systems, Coforgeamong others, will be in focus on Wednesday, as their counterparts in the US markets fell vertically amid fears that AI was creating more competition for software makers, following software updates revealed by Anthropic-driven AI.

The Reserve Bank of India (RBI) has approved appointment of SBI MD Vinay Tonse as the new MD, CEO of Yes Bank for three years, according to an exchange notice.

The Reserve Bank of India (RBI) has renewed authorization for Vakrangee Ltd to set up, own and operate White Label ATMs (WLA) in India. The validity has been extended till March 31, 2027.

Indian Energy Exchange (IEX) achieved its highest-ever monthly electricity trading volume of 13,050 MU in January, surging 19.6% year-on-year. The exchange also traded 23.91 lakh Renewable Energy Certificates (RECs) during the month. Price Crash Amid Supply Surge: Abundant generation from hydro, wind, solar, and coal plants flooded the exchange with liquidity, driving down prices:- DAM Price: ₹3.86/unit (-12.9% YoY); and RTM Price: ₹3.72/unit (-15.9% YoY) Lower prices enabled Discoms and C&I consumers to procure competitively priced power, replacing costlier sources.

Varroca leading global Tier-1 automotive supplier, today announced a new business win with a leading global electric vehicle (EV) OEM for the supply of AC-bi-directional wall chargers for electric vehicles. This partnership marks an important milestone in Varroc’s continued expansion within the electric mobility ecosystem.

Yaan Enterprises Ltd has received a purchase order from State Agri Horticultural Development Co-operative Society Limited – Thiruvananthapuram – for the supply of yellow maize approx. value of Rs 7.30 crore.

Kinetic Engineering Ltd. (KEL) has crossed 600 electric vehicles in sales to date, reflecting growing acceptance of its EV offerings across early markets. Kinetic Watts and Volts Ltd., the electric mobility arm of Kinetic Engineering Ltd. Currently operates 7 Kinetic EV dealerships, with 8 additional outlets scheduled to open by the end of February, reinforcing its phased, market-by-market expansion strategy.

Bajaj Electricals has launched Bajaj Secura Wires, marking its entry into the wires segment. Introduced under the company’s Lighting Solutions business, the new range expands Bajaj Electricals’ footprint across allied electrical categories, addressing the growing demand for safe, reliable, and high-performance wiring solutions for residential applications. The demand outlook for wires continues to be robust therefore providing an attractive opportunity for a new trusted player in the electrical industry.

The board of Nazara Technologies has approved an investment in nCore Games, developers of the made-in-India franchise ‘FAU-G’, as well as a primary capital infusion of up to Rs 15 crore into Rusk Media, a mobile-first, IP-led entertainment platform for Gen-Z and Gen-A audiences. These investments underscore Nazara’s role in supporting the Indian gaming ecosystem.

Aqylon Nexus Ltd, formerly Sri Adhikari Brothers Television Networkshas executed a Memorandum of Understanding with MBuzz Technologies, Middle East, a global technology solutions provider and an Nvidia AI Factory Partner, to explore potential collaboration opportunities in the areas of Artificial Intelligence (AI) solutions and AI-ready hyper-scale data center infrastructure.

Published on February 4, 2026

Pakistan Cricket: Pakistan has no business not playing matches against India, PCB is certain to take a U-turn!

0

Last Updated:

Pakistan Cricket Team T20 World Cup Boycott Controversy: Many cricket experts believe that the Pakistan Cricket Board will take a U-turn on the decision to play the T20 World Cup match against India. This claim is also being made in some reports. PCB has not given any official information to the International Cricket Council regarding the match boycott against India.

Pakistan doesn't have the capacity to not play matches against India, PCB is certain to take a U-turn!Zoom
pakistan cricket team

New Delhi. Only three days are left for the start of the T20 World Cup, but the drama of the Pakistan Cricket Board is not ending. Even though the Pakistan government has said that its team will boycott the match against India in the T20 World Cup to be held on February 15, but the PCB knows that doing so is going to ruin its position. PCB will not only suffer huge losses, ICC will also take some such decisions which will definitely ruin Pakistan cricket. ICC has also warned Pakistan to reconsider its decision otherwise be prepared for serious consequences. Regarding this whole matter, it is now being said that Pakistan Cricket Board will take a U-turn in the next few days. Cricketers experts believe this. This is also being said in many reports. It is not even worth saying that Pakistan does not take time to change its point of view.

About the Author

Shivam Upadhyay

Working as Sub Editor in Network 18 Group since November 2025. 3 years experience in journalism. Debuted in sports journalism with Zee News. Interested in writing about cricket as well as hockey and badminton. mother…read more

homecricket

Pakistan doesn’t have the capacity to not play matches against India, PCB is certain to take a U-turn!

Tories to use ancient mechanism to force release of Mandelson vetting papers after criminal investigation launched | Politics News

0

The Conservatives will today attempt to force the release of all information relating to Sir Keir Starmer’s appointment of Peter Mandelson as ambassador to the United States after new revelations about his ties to Jeffrey Epstein.

Party leader Kemi Badenoch has demanded No 10 explain the vetting process after she claimed that concerns were “waived away” so the PM could make a “political appointment of a man who is a close friend of a convicted paedophile”.

It comes after the Metropolitan Police announced they had launched a criminal investigation into misconduct in public office offences after files released by US authorities appeared to show Mandelson had passed internal discussions from the heart of UK government to Epstein after the global financial crash.

Mandelson was business secretary in Gordon Brown’s government at the time, was later made a life peer and last year was appointed the UK’s ambassador to the US.

‘Crazy’ for ministers to oppose Mandelson motion

He was sacked as ambassador in September, after new emails revealed he sent messages of support to Epstein even as the disgraced financier faced jail for sex offences in 2008.

His friendship with Epstein had already been known at the time of his appointment, but Number 10 argued it was not aware of its “depth and extent”.

 Peter Mandelson stepped down from the House of Lords on Tuesday. Pic: PA
Image: Peter Mandelson stepped down from the House of Lords on Tuesday. Pic: PA

The Conservatives will use their Opposition Day to table a humble address – an arcane mechanism that can compel the government of the day to produce certain documents.

The documents they will want to be published include due diligence work carried out by the Cabinet Office; emails between Mandelson and the PM’s chief of staff Morgan McSweeney on his association with Epstein; minutes of meetings held about the appointment and details of payments made to Mandelson on his departure from the ambassador role.

Mandelson ‘banished for good’ by Epstein files

Humble addresses, if passed, are binding on ministers.

Several Labour MPs have told Sky News they were prepared to vote with the Opposition on the humble address.

Left-wing MP Richard Burgon told Sky News’ chief political correspondent Jon Craig that it would be “crazy” if the government opposed the motion, as “we can’t have a situation where the government is dragged kicking and screaming to do the right thing”.

Mrs Badenoch said Labour MPs “need to do what they know is right” and argued it “is about the reputation of our parliament and our country”.

She said: “I hope MPs of all parties, and especially those in Labour, will join us in fighting for the truth, for full justice for Epstein’s victims and for openness and honesty with the British people.

“If the prime minister had a backbone, he’d allow his MPs to vote with their conscience and put their country before their party.”

No 10 added an amendment to the humble address calling for all documents to be published “except papers prejudicial to UK national security or international relations”, according to the Commons order paper.

Mandelson has stepped down from the House of Lords following the latest revelations.

He has previously said: “I was wrong to believe Epstein following his conviction [in 2008 for procuring a child for prostitution and of soliciting a prostitute] and to continue my association with him afterwards. I apologise unequivocally for doing so to the women and girls who suffered.”



Source link

First baby Asian elephant born at Smithsonian’s National Zoo after 25 years

0

NEWYou can now listen to Fox News articles!

Washington, D.C., has something to trumpet about overnight after welcoming a very small and very special new resident.

A baby Asian elephant was born in the early hours Monday at the Smithsonian’s National Zoo, a rare arrival marking the zoo’s first elephant birth in nearly 25 years, officials announced.

The 308-pound, 38.5-inch calf arrived at 1:15 a.m. inside the zoo’s Elephant Trails exhibit, with animal care and veterinary staff on hand to monitor the delivery and the newborn’s first moments.

The female calf spent those early hours tucked close to its mother, Nhi Linh, a 12-year-old first-time mom that zoo staff say is doing well as she bonds with her baby under the watch of keepers and veterinarians.

AMERICA’S NATIONAL BIRD LAYS SECOND EGG AT FAMED CALIFORNIA NEST AS NESTING SEASON CONTINUES

Asian Elephant calf taking first steps

An Asian elephant calf is suspended from ropes by staff members guiding her to walk shortly after being born at the Smithsonian’s National Zoo in Washington, D.C. (Smithsonian’s National Zoo via YouTube)

Zoo officials described the birth as a rare and joyful milestone not only for the National Zoo, but for Asian elephant conservation more broadly.

“After waiting nearly 25 years for an Asian elephant calf, this birth fills us with profound joy,” said Brandie Smith, the John and Adrienne Mars director of the National Zoo and Conservation Biology Institute.

“When you see the calf and those heartwarming interactions with the herd, I hope you’ll be inspired to help save this endangered species. What we learn from our elephants in D.C. directly strengthens our work to protect wild Asian elephants across Southeast Asia. I’m incredibly proud of our team, whose expertise made this moment possible for Nhi Linh and for all of us.” 

With fewer than 50,000 Asian elephants remaining in the wild, each birth under human care represents a meaningful step toward protecting the species, according to the Smithsonian.

Asian elephants face mounting threats from habitat loss, disease and human-elephant conflict, making successful live births increasingly important. The Smithsonian has been studying and conserving Asian elephants for more than 50 years, both at the National Zoo and across elephant-range countries in Asia.

CHIMPANZEE ESCAPES FROM INDIANAPOLIS ZOO ENCLOSURE, TRIGGERING EMERGENCY LOCKDOWN

Baby Asian Elephant calf at Smithsonian National Zoo

Smithsonian animal care and veterinary staff with the Asian elephant calf that was born, Monday, at the Smithsonian’s National Zoo. (Roshan Patel, Smithsonian’s National Zoo and Conservation Biology Institute )

The calf’s arrival follows a 21-month pregnancy, which is the longest gestation period of any land animal, according to the Smithsonian. Zoo officials said the birth was part of a carefully planned breeding recommendation through the Association of Zoos and Aquariums Species Survival Plan, a nationwide program designed to maintain healthy, genetically diverse animal populations in zoos.

Nhi Linh, the calf’s mother, was born Aug. 10, 2013, at the Rotterdam Zoo in the Netherlands and joined the National Zoo herd in November 2022. She stands about 7½ feet tall, weighs roughly 6,700 pounds, and is described by keepers as energetic and “go with the flow.”

Asian elephant calf born at Smithsonian National Zoo

Smithsonian animal care and veterinary staff with the Asian elephant calf that was born Monday. (Roshan Patel, Smithsonian’s National Zoo and Conservation Biology Institute )

The proud papa, Spike, is a familiar presence at the zoo’s Elephant Trails. Born July 2, 1981, at Zoo Miami, Spike arrived at the National Zoo in 2018. At around 10 feet tall and 13,000 pounds, he is one of the largest animals on the grounds and is a calm and gentle presence within the herd according to staff. 

Spike had sired three elephant calves at other zoos, but none survived.

The zoo released photos showing the newborn calf nestled beside Nhi Linh, with animal care teams nearby in the hours after the birth. Officials said the calf’s health, social development and weather conditions will determine when visitors will be able to see the baby elephant in person.

For now, keepers are focused on giving mother and calf time to bond while closely monitoring the newborn’s progress. Updates will be shared through the zoo’s website and social media accounts.

Baby Asian Elephant at Smithsonian Zoo

Smithsonian animal care and veterinary staff with the Asian elephant calf that was born this week at the Smithsonian’s National Zoo in Washington, D.C. (Roshan Patel, Smithsonian’s National Zoo and Conservation Biology Institute )

Animal lovers can also take part in naming the newest arrival. The Smithsonian’s National Zoo has opened a public naming vote, with a $5 donation counting as a vote and proceeds supporting Asian elephant care and conservation efforts. 

Voting closes at noon Feb. 13, with results updated daily.

The name options include Linh Mai, meaning “spirit blossom”; Thảo Nhi, meaning “gentle and beloved”; Tú Anh, meaning “bright and intelligent”; and Tuyết, meaning “snow,” a nod to the winter storm that hit the D.C. area shortly before the birth.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Admission to the Smithsonian’s National Zoo is free, and no special ticket is required to visit Elephant Trails when it is open. Zoo officials encourage visitors to check online for updates on when the calf will make its public debut.

The tiny elephant’s arrival is being celebrated as a once-in-a-generation moment as a new life takes its first wobbly steps.



Source link

Trump adviser Stephen Miran quits White House role to stay on at Fed | Trump administration

0

Federal Reserve governor Stephen Miran has resigned from his position as chair of the White House’s council of economic advisers, fulfilling a pledge he made to the Senate as his assignment at the central bank becomes longer-lasting.

Miran had been on unpaid leave from his CEA post since Donald Trump appointed him last year to fill an unexpected vacancy on the Fed’s board of governors to a term that expired on 31 January. The arrangement drew the ire of Democratic senators, who said it would make a presidential puppet of the Fed’s newest policymaker.

Miran said he had been legally advised there was no need to quit his CEA post as the Fed job was only for a few months.

“I promised the Senate that if I should stay on the board past January, I would formally depart the council,” Miran said in his resignation letter dated Tuesday and reviewed by Reuters. “I believe it is important to stay true to my word while I continue to perform the job at the Federal Reserve to which you and the Senate appointed me.”

Trump on Friday announced plans to nominate former Fed governor Kevin Warsh as the next chair of the central bank to succeed Jerome Powell. While this would fill the Fed board seat currently occupied by Miran, the law allows him to serve until a successor is confirmed by the Senate.

The White House had no immediate comment on whether Pierre Yared, now the CEA’s acting chair, would be named to the top post permanently.

Miran’s resignation was first reported by Barron’s.

Miran has argued for sharply lower interest rates at every Fed meeting since he joined the central bank last September. Trump has made no secret of his desire for the Fed to reduce interest rates, and indeed made support for easier monetary policy one of his criteria for a new Fed chief.

Powell, whose leadership term ends in May, disclosed in January that the Department of Justice had launched a criminal investigation into statements he made to the Senate about Fed building renovations. Powell has described the investigation as part of a broader effort by the administration to exert control over the Fed.

The department last year also opened an investigation into Fed governor Lisa Cook for alleged misstatements on her mortgage application. She denies wrongdoing and is suing to stop Trump’s attempt to fire her in a case that is before the supreme court.

A majority of the Senate banking committee – including all its Democratic members and one of its Republican members – have decried the justice department’s investigation of Powell as political intimidation and have said they oppose moving forward on Warsh’s nomination.



Source link

At least 15 dead after migrant boast collides with Greek coastguard | World News

0


At least 15 people have been killed in a collision between a speedboat carrying migrants and a coastguard vessel off the coast of Greece, authorities have said.

The bodies of 11 men and three women were recovered from the sea near the eastern Aegean island of Chios, while a woman later died in hospital, according to coastguard officials.

A search and rescue operation is under way in the area, involving patrol boats, divers and a helicopter.

The coastguard said 25 migrants, including 11 children, had been rescued and taken to a hospital on Chios, along with two coastguard officers injured in the incident on Tuesday.

It was not immediately clear how many people had been on the speedboat, the coastguard said.

Video footage from a local news outlet showed at least one person being carried in a blanket from a coastguard boat into a waiting coastguard vehicle, as others appear to lead two children toward the car.

It remains unclear how the collision occurred.

The head of Greece‘s public hospital workers’ union, Michalis Giannakos, said staff at the hospital in Chios were preparing for a sudden influx of injured people.

Speaking on Greek television, Mr Giannakos said several of those injured required surgery.

Read more from Sky News:
‘Aggressive’ Iranian drone downed by US
Teenage boy swims for four hours to save family

It comes less than three years after hundreds of people are believed to have died when a fishing boat carrying migrants from Africa and the Middle East sank off the coast of Greece in 2023.

Greek officials said the vessel capsized about 50 miles from the southern coastal town of Pylos after the boat got into difficulties when its engine stopped and it began veering from side to side.

According to the UN’s migration agency, more than 33,000 migrants died or went missing in the Mediterranean Sea between 2014 and the end of 2025 – making it the deadliest migration corridor in the world.



Source link

Holy Innocents Catholic School vandalized, statues smashed in attack

0

NEWYou can now listen to Fox News articles!

The leader of a California Catholic school which was desecrated after a break-in is urging the community to “make many acts of reparation for this offense against God and Our Lady.”  

Images of the destruction at Holy Innocents Catholic School in Long Beach, which was discovered Monday morning, show smashed statues, images of Mary and other religious figures destroyed and a photograph of the pope knocked to the floor. 

In a letter obtained by Fox News Digital Tuesday and sent to school parents, Fr. G. Peter Irving, pastor and head of the school, and Cyril Cruz, the school’s principal, wrote, “We ask everyone to make many acts of reparation for this offense against God and Our Lady.”

MISSISSIPPI SYNAGOGUE BURNED IN ARSON ATTACK, SUSPECT IN CUSTODY

A Catholic school was vandalized in California.

A Catholic school was vandalized in California. (KTTV)

Cruz told EWTN News that “Our statue of the Virgin Mary was smashed, and the tabernacle was removed and thrown to the floor in an apparent attempt to force it open. The atrium lovingly prepared by the Carmelite Sisters for our scholars was completely destroyed.”

In their letter, Irving and Cruz announced that security would be heightened following the attack. 

“Out of an abundance of caution, we have requested increased security patrols, especially after school hours and weekends,” they wrote. “The hall was the only building affected. Classes will continue as scheduled. We hope to resume Mass in the hall as soon as we are able.”

DRIVER RAMS CAR REPEATEDLY INTO DOORS OF NYC JEWISH SITE, SUSPECT DETAINED

Woman holding rosary beads

Fr. G. Peter Irving, pastor and head of the school, and Cyril Cruz, the school’s principal, wrote, “We ask everyone to make many acts of reparation for this offence against God and Our Lady.” (Dan Kitwood/Getty Images)

The school leaders also asked parents to pray for the perpetrator.

“Please join us in prayer for those who committed this act so that they may turn away from darkness and embrace the loving grace of our Lord,” they wrote. “We particularly ask for the intercession of our Blessed Mother for our school, our families, and our community.”

MISSISSIPPI SYNAGOGUE ARSON SUSPECT’S DAD TURNS HIM IN AFTER LAUGHING CONFESSION, FBI SAYS

U.S. Justice Department logo is seen at Justice Department headquarters in Washington

The Justice Department is launching an investigation. (Kevin Lamarque/Reuters/File Photo)

On Monday, the Justice Department’s Civil Rights Division announced it was launching an investigation into the incident. 

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Fox News’ Landon Mion contributed to this report. 



Source link

Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group

0

A China-linked threat actor known as Lotus Blossom has been attributed with medium confidence to the recently discovered compromise of the infrastructure hosting Notepad++.

The attack enabled the state-sponsored hacking group to deliver a previously undocumented backdoor codenamed Chrysalis to users of the open-source editor, according to new findings from Rapid7.

The development comes shortly after Notepad++ maintainer Don Ho said that a compromise at the hosting provider level allowed threat actors to hijack update traffic starting June 2025 and selectively redirect such requests from certain users to malicious servers to serve a tampered update by exploiting insufficient update verification controls that existed in older versions of the utility.

The weakness was plugged in December 2025 with the release of version 8.8.9. It has since emerged that the hosting provider for the software was breached to perform targeted traffic redirections until December 2, 2025, when the attacker’s access was terminated. Notepad++ has since migrated to a new hosting provider with stronger security and rotated all credentials.

Rapid7’s analysis of the incident has uncovered no evidence or artifacts to suggest that the site’s plugin or updater-related mechanisms were exploited to distribute malware.

“The only confirmed behavior is that execution of ‘notepad++.exe’ and subsequently ‘GUP.exe’ preceded the execution of a suspicious process ‘update.exe’ which was downloaded from 95.179.213.0,” security researcher Ivan Feigl said.

“Update.exe” is a Nullsoft Scriptable Install System (NSIS) installer that contains multiple files –

  • An NSIS installation script
  • BluetoothService.exe, a renamed version of Bitdefender Submission Wizard that’s used for DLL side-loading (a technique widely used by Chinese hacking groups)
  • BluetoothService, encrypted shellcode (aka Chrysalis)
  • log.dll, a malicious DLL that’s sideloaded to decrypt and execute the shellcode

Chrysalis is a bespoke, feature-rich implant that gathers system information and contacts an external server (“api.skycloudcenter[.]com”) to likely receive additional commands for execution on the infected host.

The command-and-control (C2) server is currently offline. However, a deeper examination of the obfuscated artifact has revealed that it’s capable of processing incoming HTTP responses to spawn an interactive shell, create processes, perform file operations, upload/download files, and uninstall itself.

“Overall, the sample looks like something that has been actively developed over time,” Rapid7 said, adding it also identified a file named “conf.c” that’s designed to retrieve a Cobalt Strike beacon by means of a custom loader that embeds Metasploit block API shellcode.

One such loader, “ConsoleApplication2.exe” is noteworthy for its use of Microsoft Warbird, an undocumented internal code protection and obfuscation framework, to execute shellcode. The threat actor has been found to copy and modify an already existing proof-of-concept (PoC) published by German cybersecurity company Cirosec in September 2024.

Rapid7’s attribution of Chrysalis to Lotus Blossom (aka Billbug, Bronze Elgin, Lotus Panda, Raspberry Typhoon, Spring Dragon, and Thrip) based on similarities with prior campaigns undertaken by the threat actor, including one documented by Broadcom-owned Symantec in April 2025 that involved the use of legitimate executables from Trend Micro and Bitdefender to sideload malicious DLLs.

“While the group continues to rely on proven techniques like DLL side-loading and service persistence, their multi-layered shellcode loader and integration of undocumented system calls (NtQuerySystemInformation) mark a clear shift toward more resilient and stealth tradecraft,” the company said.

“What stands out is the mix of tools: the deployment of custom malware (Chrysalis) alongside commodity frameworks like Metasploit and Cobalt Strike, together with the rapid adaptation of public research (specifically the abuse of Microsoft Warbird). This demonstrates that Billbug is actively updating its playbook to stay ahead of modern detection.”

Kaspersky Observes 3 Infection Chains

Kaspersky, in its own breakdown of the Notepad++ incident, said it observed three different infection chains that were designed to target about a dozen machines belonging to individuals located in Vietnam, El Salvador, and Australia, a government organization located in the Philippines, a financial organization located in El Salvador, and an IT service provider organization located in Vietnam.

“Over the course of four months, from July to October 2025, attackers who have compromised Notepad++ have been constantly rotating C2 server addresses used for distributing malicious updates, the downloaders used for implant delivery, as well as the final payloads,” security researchers Georgy Kucherin and Anton Kargin said.

The company said it did not detect any payloads being deployed starting from November 2025. The details of the three infection sequences are below –

Chain #1 (Between late July and early August 2025)

Attackers were found to deploy a malicious Notepad++ update hosted at “45.76.155[.]202/update/update.exe,” which was then launched by the legitimate Notepad++ updater process WinGUp (“gup.exe”). The executable, an NSIS installer, was used to send system information to a temp[.]sh URL by executing a series of shell commands (whoami and tasklist). This behavior was described by a user named “soft-parsley” on the Notepad++ community forums in October 2025.

Like in the case of “update.exe” documented by Rapid7, the “update.exe” used in this chain leveraged DLL side-loading by abusing a legitimate binary associated with ProShow software (“ProShow.exe”) to deploy two shellcodes: one that’s not meant to be executed and functioned as a distraction mechanism, while the second shellcode decrypted a Metasploit downloader payload that retrieves a Cobalt Strike beacon shellcode from a remote URL.

Chain #2 (Between the middle and the end of September 2025)

The malicious update continued to be delivered via “45.76.155[.]202/update/update.exe,” while the “update.exe” NSIS installer featured slight tweaks to collect more system information (whoami, tasklist, and netstat) and deliver a completely different set of payloads, including a Lua script that’s engineered to execute shellcode. The launched shellcode was a Metasploit downloader that drops a Cobalt Strike beacon.

A subsequently observed “update.exe” variant towards the end of September 2025 also harvested the results of the systeminfo shell command alongside whoami, tasklist, and netstat. Another version of the binary changed the system information upload URL to self-dns.it[.]com/list, along with the URL used by the Metasploit downloader and Cobalt Strike Beacon C2 server.

Chain #3 (October 2025)

This infection chain altered the NSIS installer distribution URL to “45.32.144[.]255/update/update.exe” and initiated the same sequence of events described by Rapid7 above. What’s common to all three sets of attacks is the fact that the Beacons are loaded through a Metasploit downloader shellcode.

Then, starting mid-October 2025, the attackers began to propagate the installer via three different URLs to launch a combination of both #2 and #3 execution chains –

  • 95.179.213[.]0/update/update.exe
  • 95.179.213[.]0/update/install.exe
  • 95.179.213[.]0/update/AutoUpdater.exe

The compromise of Notepad++’s update infrastructure is the latest example of how the software ecosystem has increasingly become the target of supply chain attacks in recent years. In breaching the mechanism used to distribute updates, it enabled the attackers to selectively break into machines of high-profile organizations across the world, the Russian cybersecurity vendor noted.

“The variety of infection chains makes detection of the Notepad++ supply chain attack quite a difficult and at the same time creative task,” Kaspersky said. “The attackers made an effort to avoid losing access to this infection vector — they were spreading the malicious implants in a targeted manner, and they were skilled enough to drastically change the infection chains about once a month.”



Source link

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.gadgets360.com/mobiles/oppo-reno-14-5g-price-in-india-discount-upto-rs-6000-smartphone-cheapest-flipkart-deals-today-news-10942229” on this server.

Reference #18.8eaf0660.1770172869.1ba4d092

https://errors.edgesuite.net/18.8eaf0660.1770172869.1ba4d092