Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

0

The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine.

Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It’s also tracked under the monikers FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC‑0057, Umbral Bison (formerly RepeatingUmbra), UNC1151, and White Lynx.

“FrostyNeighbor has been running continual cyber operations, changing and updating its toolset regularly, updating its compromise chain and methods to evade detection – targeting victims located in Eastern Europe,” ESET said in a report shared with The Hacker News.

Previous attacks mounted by the hacking crew have leveraged a malware family known as PicassoLoader, which then acts as a conduit for Cobalt Strike Beacon and njRAT. In late 2023, the threat actor was also observed weaponizing a vulnerability in WinRAR (CVE-2023-38831, CVSS score: 7.8) to deploy PicassoLoader and Cobalt Strike.

As recently as last year, Polish entities were at the receiving end of a phishing campaign orchestrated by Ghostwriter that exploited a cross-site flaw in Roundcube (CVE-2024-42009, CVSS score: 9.3) to run malicious JavaScript responsible for capturing email login credentials.

In at least some cases, the threat actors are said to have leveraged the harvested credentials to analyze mailbox contents, download the contact list, and abuse the compromised account to propagate more phishing messages, per a report from CERT Polska in June 2025. Towards the end of 2025, the group also began to incorporate an anti-analysis technique where lure documents relied on dynamic CAPTCHA checks to trigger the attack chain.

“FrostyNeighbor remains a persistent and adaptive threat actor, demonstrating a high level of operational maturity with the use of diverse lure documents, evolving lure and downloader variants, and new delivery mechanisms,” ESET researcher Damien Schaeffer said. “This newest compromise chain that we detected is a continuation of the group’s willingness to update and renew its arsenal, trying to evade detection to compromise its targets.”

The latest set of activities, observed since March 2026, involves using links in malicious PDFs sent via spear-phishing attachments to target government entities in Ukraine, ultimately resulting in the deployment of a JavaScript version of PicassoLoader to drop Cobalt Strike. The PDF decoy documents have been found to impersonate the Ukrainian telecommunications company Ukrtelecom.

The infection sequence incorporates a geofencing check, serving a benign PDF file to victims whose IP address does not correspond to Ukraine. The embedded link in the PDF document is used to deliver a RAR archive containing a JavaScript payload that displays a lure document to keep up the ruse, while simultaneously launching PicassoLoader in the background.

The downloader is also designed to profile and fingerprint the compromised host, based on which the operators may manually decide to send a third-stage JavaScript dropper for Cobalt Strike Beacon. The system fingerprint is transmitted to attacker-controlled infrastructure every 10 minutes, allowing the threat actor to assess whether the victim is of interest.

The activity primarily appears to center around military, defense sector, and governmental organizations in Ukraine, whereas the victimology in Poland and Lithuania is much broader, targeting industrial and manufacturing, healthcare and pharmaceuticals, logistics, and government sectors.

“FrostyNeighbor remains a persistent and adaptive threat actor, demonstrating a high level of operational maturity with the use of diverse lure documents, evolving lure and downloader variants, and new delivery mechanisms,” ESET said. “The payload is only delivered after server-side victim validation, combining automated checks of the requesting user agent and IP address with the manual validation by the operators.”

Gamaredon Delivers GammaDrop and GammaLoad in Ukraine Attacks

The disclosure comes as the Russia-affiliated Gamaredon hacking group has been tied to a spear-phishing campaign targeting Ukrainian state institutions since September 2025, with an aim to deliver GammaDrop and GammaLoad downloader malware through RAR archives that exploit CVE-2025-8088.

“These emails – spoofed or sent from compromised government accounts – deliver persistent, multi-stage VBScript downloaders that profile the infected system,” HarfangLab said. “There is little technical novelty here, but Gamaredon has never relied on sophistication. The group’s strength lies in its relentless operational tempo and scale.”

Russia Targeted by BO Team and Hive0117

The findings also follow a report from Kaspersky that the pro-Ukraine hacktivist group known as BO Team (aka Black Owl) may be working with Head Mare (aka PhantomCore) in attacks aimed at Russian organizations, citing overlapping infrastructure and tools. Attacks orchestrated by the BO Team in 2026 have employed spear-phishing to serve BrockenDoor and ZeronetKit, the latter of which is capable of also compromising Linux systems.

Also observed in these attacks is a previously undocumented Go-based backdoor referred to as ZeroSSH that can execute arbitrary commands using “cmd.exe” and establish a reverse SSH channel. As many as 20 organizations have been targeted by the BO Team in the first quarter of 2026.

“The nature of the interaction between the groups remains unclear, but the recorded intersections of tools and infrastructure indicate at least the potential coordination of actions against Russian organizations,” Kaspersky said.

In recent months, Russian enterprises have also been targeted by a financially motivated group called Hive0117to steal over 14 million rubles by breaking into accountants’ computers via phishing campaigns and disguising transfers as salary payments. The phishing emails were sent to more than 3,000 Russian organizations between February and March 2026, per F6.

Besides Russia, the activity has also targeted users from Lithuania, Estonia, Belarus, and Kazakhstan. The attacks employ invoice-themed lures to distribute RAR archives that contain malicious files to drop DarkWatchman, a remote access trojan attributed to the group.

“Using remote access to online banking systems via compromised accountants’ computers, they initiated payments to be credited to bank accounts listed in the registry,” F6 said. “Formerly, this looked like a payroll transfer, but the registry listed the bank accounts of mules. If such payment transactions did not go through anti-fraud systems, the attackers were able to withdraw significant amounts from the companies’ accounts.”



Source link

Met chief says British Jews ‘not safe’ in London after series of attacks | UK news

0

Counter-terrorism officers in London have launched 11 investigations and arrested 35 people after “a sustained period of attack” upon the Jewish community, the head of the UK’s biggest police force has disclosed.

In one of his most stark comments on antisemitism in the UK Mark Rowley, the Met commissioner, told MPs in a letter: “British Jews are not currently safe in their capital city.”

The investigations, in which 10 people have been charged, include the attack on 29 April in Golders Green, in which two British Jews were stabbed, an arson attack on an ambulance and nine other incidents.

The letter was disclosed as King Charles visited Golders Green, in north-west London, on Thursday and met victims of the stabbings last month in a show of support to the community.

King Charles, left, with chief rabbi Sir Ephraim Mirvis as he greets local residents during his visit to Golders Green in London. Photograph: Richard Pohle/AP

In a letter to the Commons home affairs select committee on Wednesday, Rowley wrote: “Over the last six weeks Jewish Londoners have been under a sustained period of attack.

“This has included the attack on a Hatzola ambulance on 23 March, nine other arson/attempted arson attacks, and most significantly the terrorist attack on 29 April in Golders Green, in which two British Jews were stabbed. British Jews are not currently safe in their capital city. This is unacceptable.

“In total, Counter Terrorism Policing is leading 11 investigations, including those relating to the arsons, the Golders Green terrorist attack, and a further investigation into several discarded items discovered in Kensington Gardens. Across these investigations, we have made 35 arrests. Ten individuals have been charged and one has been convicted to date.”

At the Jewish Care charity centre in Golders Green Charles met victims Shloime Rand, 34, and Moshe Ben Baila, 76, also known as Norman Shine, along with the chief rabbi of the United Hebrew Congregations of the Commonwealth, Ephraim Mirvis, and Rowley.

The chief rabbi told the king they “appreciate it enormously” that he had made the visit.

King Charles visited Golders Green, in north-west London, on Thursday ain a show of support to the community. Photograph: Anadolu/Getty Images

The king also spoke with members of the Jewish community police force Shomrim, who were involved in responding to the attacks on 29 April.

Shine, who was stabbed in the neck outside a bus stop during the attack, spoke about the “genuine warmth” he had felt from the king.

He said: “He was very concerned. The most inspiring thing was that he didn’t let go of my hand, I mean it was amazing, He is the king but I felt a genuine warmth and concern.”

He said that the visit felt “extremely important” for the whole Jewish community.

“We feel we have a genuine friend in the king,” he added.

After the meeting, Charles greeted the crowds gathered outside the charity centre on Golders Green Road and was presented with a loaf of traditional challah bread outside Grodz bakery on the high street. He also spoke to children from a local primary school.

The alleged Golders Green attacker Essa Suleiman, 45, has been remanded in custody accused of three counts of attempted murder.

Suleiman is accused of trying to kill his friend of 20 years Ishmail Hussein at his home in Southwark before stabbing the two people in the street on 29 April.

Suleiman was born in Somalia and came to the UK legally as a child in the 1990s. He was reported to Prevent, the UK government’s anti-extremism programme, in 2020 but the case was closed the same year.



Source link

‘It’s like stealing’: Palestinian family’s seized property listed on Booking.com | West Bank

0

Some of Mohammad al-Sbeih’s fondest childhood memories are of his small farm in the hills south of Bethlehem, where three generations of his family grew wheat and barley.

“It was a hard plot to farm as it was on a hillside with terraces, but it was so beautiful,” Sbeih remembers.

Now, however, the houses and roads of an Israeli settlement, Neve Daniel, are built where the Sbeih family once grew food, and the expansive view towards the sea is the chief selling point of a rental property being advertised on Booking.com.

The description on the global travel site says: “Guests can relax in the garden or on the terrace, enjoying the fresh air and scenic surroundings.” It adds the Neve Daniel house has a picnic area and is “ideal for outdoor gatherings”.

The geolocation of this home in the settlement of Neve Daniel in the West Bank offered for rent on Booking.com matches the location of the Sbeih family land. Photograph: Quique Kierszenbaum

A new report by Ekō, a US-based advocacy group focused on corporate accountability, lists 41 Booking.com listings in 14 illegal Israeli settlements across the occupied West Bank in two main clusters, along the Jordan valley including the Dead Sea, and in the settlement ring that has been built around East Jerusalem, including two inside Jerusalem’s old city, on territory captured by Israel in 1967 and annexed in 1980.

The settlements involve the transfer of a civilian population into occupied territory, which is a violation of the fourth Geneva convention, and the Rome statute (the founding document of the international criminal court) which deems such colonisation a war crime.

The main operating arm of Booking.com is headquartered in the Netherlands, where a criminal complaint by the European Legal Support Center, a pressure group supporting Palestinian rights, is under review by Dutch prosecutors.

The geolocation of this home offered for rent matches the location of the Sbeih family land. Photograph: Quique Kierszenbaum

The complaint argues that settlement-linked bookings may constitute money laundering under Dutch law on the grounds that the underlying commercial activity is connected to illegal settlements.

The International court of justice (ICJ) issued an advisory opinion in July 2004, at the request of the UN general assembly, confirming the illegality of the settlement and stating that governments and organisations were obliged to not recognise the legality of Israeli settlement in occupied Palestinian territories.

Israel is a signatory to the Geneva conventions, but argues that they do not apply to the West Bank because they were not part of another sovereign territory before the 1967 war, which resulted in Israeli occupation, because Jordanian rule in the territory was not internationally recognised. Israel also argued that the ICJ did not have jurisdiction.

Airbnb, a US firm, also lists properties for rent in the settlements. A Guardian investigation in February 2025 found 760 rooms in hotels, apartments and houses listed by the two companies. Airbnb said it would stop advertising rentals in settlements in 2018, but reversed the decision a few months later after a legal challenge from hosts, potential hosts and guests.

In 2022, Booking.com introduced labelling for settlements which advises would-be guests to consult government advisories “to make an informed decision about your stay in this area, which may be considered conflict-affected”.

The warning is in small print and does not appear on the webpage for individual houses, but only in response to a search under the name of the settlement where they are located.

map

A Booking.com spokesperson said: “Our mission is to make it easier for everyone to experience the world and as such we believe it’s not our place to decide where someone can or cannot travel.

“We continue to monitor the situation closely, including the potential for changing laws and rigorously apply the principles and processes outlined in our human rights statement, as we do in all disputed or conflict-affected areas in the world.”

In its section on “conflict-affected areas”, the company’s human rights statement says: “Where we determine that we may be directly linked to negative human rights impacts through the activities of our listings, we will take appropriate action.”

Ekō has previously conducted a range of campaigns on corporate social responsibility, including highlighting the rule of online sites selling gelatin produced from slaughtered donkeys, and fundraising for initiatives to remove plastic waste from the oceans.

The Ekō report, titled “Booking.com: experience Israel’s illegal occupation” said: “Every day Booking.com fails to act is another day it profits from the theft of Palestinian land and props up a government implicated in atrocity crimes.”

Sbeih is not optimistic about the prospect of redress. His family have been losing legal battles in Israeli courts ever since its five hectares (12 acres) of farmland was seized in 1982.

Sbeih said: “We brought all our documents to the court, the title deeds and a certificate from an agricultural expert confirming that the land was being used,. The other side brought nothing, not a single paper.”

Properties being constructed in the Neve Daniel settlement in 2023. Photograph: Abir Sultan/EPA

The land seizure was upheld on the grounds that the area was vital for national security, a common pattern in the land seizures in the West Bank over several decades.

The hillside stood empty and unused for two decades after that court decision. Each time the family tried to visit from their home in al-Khader on the outskirts of Bethlehem, the military turned them back.

Eventually, the family plot was swallowed by the Neve Daniel settlement, which spread from its original location on a Jewish-owned farm. Sbeih used to be able to take his children and grandchildren to a vantage point from where he could point out the family lands, but that is no longer possible under movement restrictions imposed at the outbreak of the Gaza war in October 2023.

Despite all the years of disappointments, he still cried when Ekō researchers first showed him the map of the Booking.com rental last month. “I thought it should be my children and grandchildren in that beautiful spot. It was meant to be theirs,” Sbeih said. “I know that this is a big company and, most probably, they have a lot of investments around the world, and this is a small thing. But when you steal $10, it’s like stealing a million dollars, and you have to be judged in the same way.”



Source link

Ella Langley crushes online troll with just four words, reminds the internet she doesn’t miss


You best not miss if you come at the throne.

Ella Langley continues to prove day after day that she’s on an unstoppable run in the country music world.

Her latest album is dominating the genre; she currently holds the top-two spots on the Billboard Hot 100 and has been dropping enough viral content to keep fans entertained.

The bigger the platform, the bigger the critics.

COUNTRY MUSIC STAR CELEBRATES BIRTHDAY WITH SPICY SWIMSUIT PHOTO

Ella Langley is a country music superstar

Ella Langley attends the 2025 BMI Country Awards at BMI on November 18, 2025 in Nashville, Tennessee. ((Photo by Emma McIntyre/Getty Images for BMI))

Ella Langley crushes internet troll.

Langley shared a video this week on TikTok of her shredding on a guitar, and the video, as you’d expect, gained immediate traction and attention.

All things considered, it’s about as vanilla as it can possibly get, but don’t let the haters know!

COUNTRY MUSIC STAR STIRS UP FANS WITH SEE-THROUGH WHITE OUTFIT

A troll hopped in the comments claiming “Ella isn’t even playing the guitar.”

She didn’t like that one bit, and needed just four words to respond.

“How’s your moms basement,” the “Nicotine” singer fired back.

Ella Langley crushed a TikTok troll.

Ella Langley clapped back at a fan on TikTok. (Ella Langley/TikTok Comments)

Now, I’m willing to overlook Ella’s grammatical error in her response because that’s not the point. The point is she fired back an internet killshot, and just needed four words to do it.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

There’s something very odd about internet trolls to me that I will never understand. Everyone is tough behind a computer screen. Not so much in person.

Imagine taking a shot at one of the most successful entertainers in the country …. over whether they’re actually playing a guitar.

Some people need a reality check, and Langley is here to hand it out.

Ella Langley standing at the 59th Annual CMA Awards in Nashville, Tennessee

Ella Langley attends the 59th Annual CMA Awards at Music City Center in Nashville, Tenn., on Nov. 19, 2025. (Emma McIntyre/Getty Images)

What do you think of Langley firing back? Let me know at David.Hookstead@outkick.com.



Source link

Access Denied

0

Access Denied You don’t have permission to access “http://hindi.news18.com/videos/cricket/virat-kohli-scores-a-century-against-kolkata-emotional-statement-in-ipl-2026-10477540.html” on this server.

Reference #18.94adc17.1778770473.1494012

https://errors.edgesuite.net/18.94adc17.1778770473.1494012

UK begins antitrust inquiry into Microsoft’s business software ecosystem

0


OSes

Brit regulator has ‘heard’ customers can’t always ‘effectively combine software from Microsoft with that of other providers’

The UK’s Competition and Markets Authority (CMA) is taking a closer look at Microsoft’s business software empire, launching a strategic market status investigation into the company’s ecosystem.

The probe, which is the fourth since the UK’s digital markets competition regime came into force last year, will determine whether Microsoft should be designated as having strategic market status, which would allow the CMA to implement interventions to support competition.

In March, the CMA announced that the investigation was coming. The regulator was concerned that Microsoft’s software licensing practices were reducing competition in the cloud.

In today’s announcement, the CMA said it had “heard that UK customers may not always be able to effectively combine software from Microsoft with that of other providers, limiting their ability to get access to the best products at the most competitive prices.”

Microsoft is no stranger to regulatory friction. In 2025, it described calls from AWS and Google for the UK competition regulator to “intervene and constrain the price” it charges customers to run wares on those rivals’ cloud plaforms as “extraordinary and unprecedented.”

Two year prior, Google branded Microsoft’s cloud software licensing a “tax” paid by customers as a penalty for not running Microsoft software on Azure infrastructure. It claims that Microsoft charges up to four times more, for example, to run Windows Server on GCP. AWS has previously moaned about this too. 

As well as assessing whether Microsoft is using its position to limit customer choice, the CMA investigation “includes looking at how AI competitors are able to integrate with Microsoft’s business software, giving customers access to AI software across suppliers to best suit their needs.”

Microsoft is pushing Copilot AI into as many Microsoft 365 subscriptions as it can, even creating a new tier, E7, aimed specifically at AI services. 

In a statement, Nicky Stewart, senior advisor to the Open Cloud Coalition – a trade association Microsoft previously dismissed as a Google lobby group – said: 

“This investigation needs to be both rapid and conclusive. It must address Microsoft’s unfair licensing practices once and for all, giving the UK cloud market a level playing field and the confidence to innovate and invest for the long term.”

Reg readers should not expect results anytime soon. It took 21 months for the CMA to publish the results of an investigation into the UK cloud services market, in which it said Microsoft and AWS were using their dominance to harm UK cloud customers. It claimed Microsoft, for example, could have charged UK enterprise customers £500 million more annually to run its wares in AWS and Google clouds than they’d have paid to run them in Azure. 

A key concern from that investigation – whether Microsoft’s software licensing practices were reducing competition in cloud services – has informed this one.

This latest inquiry must be completed within nine months, and a decision on designating Microsoft with SMS is scheduled to be reached by February 2027.

For its part, a Microsoft spokesperson told The Register, “We are committed to working quickly and constructively with the CMA to facilitate its review of the business software market.”

The investigation will be wide-ranging, encompassing productivity applications, operating systems, databases, and security software.

Sarah Cardell, Chief Executive of the CMA, said, “Our aim is to understand how these markets are developing, Microsoft’s position within them and to consider what, if any, targeted action may be needed to ensure UK organizations can benefit from choice, innovation and competitive prices.” 

Authorities in the US, Europe, Brazil, South Africa and Japan are also closely monitoring Microsoft’s licensing policies. ®



Source link

Iran says ships entering strait of Hormuz must cooperate after vessel seized | Iran

0

The Iranian foreign minister, Abbas Araghchi, has said ships entering the strait of Hormuz must cooperate with the Iranian navy as reports emerged of a ship being seized outside a United Arab Emirate port and taken towards Iranian waters.

The UK Maritime Trading Organisation said the docked ship was seized by “unauthorised personnel” while it was anchored off the coast of the United Arab Emirates port of Fujairah near the southern entry to the strait of Hormuz.

Araghchi, who was in India for a meeting of the Brics group of nations, described Iran as invincible and said: “In our view, the strait of Hormuz is open to all commercial ships, but they must cooperate with our naval forces.”

During the meeting, he also told the UAE delegate that cooperation with Israel would not protect the Gulf state. The Israeli prime minister, Benjamin Netanyahu, has said he made a secret trip to the UAE at the height of the war to meet the president, a claim that has been denied by the UAE.

Iran has largely closed the strait of Hormuz, which previously carried about a quarter of the world’s seaborne supply of oil and gas, since the start of the US-Israeli bombing campaign. Last month the US imposed a counterblockade of Iranian ports. Thousands of ships remain stranded.

Araghchi told the Brics meeting: “We have not created any obstacles, it is America that has created the blockade, and I hope this situation will end with the lifting of this illegal blockade imposed by America.”

He added: “As nations and governments around the world are discovering today, regional instability is a lose-lose situation for all parties, including the aggressors themselves … It should be clear to everyone now that Iran is invincible and will emerge stronger and more united whenever it is put under pressure.”

Araghchi called on Brics nations to condemn what he described as violations of international law by the US and Israel. “What was once considered unthinkable and deeply shameful is now either ignored or openly accepted in western capitals: horrific genocides, shocking violations of state sovereignty, and outright piracy on the high seas,” he said.

“These crimes, and the west’s silence in the face of them, are only possible when there is a sense of impunity. This false sense of superiority and immunity must be shattered by all of us.”

A communique in support of Iran is not expected from the Brics group, not least because of the presence of the UAE.

Iran is also trying to fend off a large rebuff at the UN where more than 110 nations are co-sponsoring a security council resolution tabled jointly by Bahrain and the US condemning the Iranian blockade.

A previous resolution was vetoed jointly by Russia and China on 7 April. The new draft is due to be discussed by the security council as early as Thursday.

Iran says it has reached a deal with China that has already allowed a large number of oil tankers bound for China to go through the strait of Hormuz since Wednesday night, and this has been made possible by China agreeing to limited charging, undercutting US opposition to such moves. The development suggests China has accepted Iran’s assertion that the shipping rules in the strait have changed, with reports suggesting the cost will be in region of $1 per barrel.

The initial draft text vetoed on 7 April, proposed by Bahrain, invoked chapter VII of the UN charter, setting out the security council’s powers to maintain peace, and would have authorised “member states, acting nationally or through voluntary multinational naval partnerships, to use all necessary means in and around the strait of Hormuz to secure transit passage and repress, neutralise and deter attempts to close, obstruct, or otherwise interfere with international navigation through the strait”.

It was watered down at French insistence to remove reference to chapter VII authorisation – ultimately endorsing only defensive measures – and was vetoed by Russia and China, two permanent members of the security council.

The latest resolution demands Iran cease its attacks on shipping, remove illegal mines, drop the proposed imposition of tolls in the strait of Hormuz, disclose mine locations and cooperate on a humanitarian corridor.

The resolution contains no specific threat of force but is still regarded by Russia as unbalanced as it contains no criticism of the original US-Israeli attack on Iran.

A joint letter from six Gulf States to the UN, not signed by Oman, calls on Iran to refrain from enacting or implementing any rules, procedures, fees, threats of mine laying or discriminatory measures that would restrict or impede international navigation.

Oman has been in talks with the UN to see if a new administrative regime can be introduced in the strait that will include payment for services.



Source link

404 | Fox News





Source link

Major tech manufacturer Foxconn confirms cyberattack hit North American factories

0

Foxconn, one of the world’s largest manufacturers of electronics sold by major tech vendors, is recovering from a cyberattack that disrupted some of the company’s factories in North America.

Nitrogen, a ransomware group that’s known for targeting organizations in the manufacturing, construction and technology sectors, claimed responsibility for the attack on its data leak site and said it stole 8 terabytes of data spanning more than 11 million files. 

The threat group posted screenshots of some of the allegedly stolen data and claimed it compromised “confidential instructions, projects and drawings from Intel, Apple, Google, Dell, Nvidia and many other projects.” 

Foxconn is famously known as the primary assembler of Apple iPhones. Apple and the other companies allegedly impacted by the attack did not respond to a request for comment.

A spokesperson for Foxconn confirmed some of its factories in North America suffered a cyberattack, and said its cybersecurity team immediately responded to the breach by implementing additional “measures to ensure the continuity of production and delivery.”

The spokesperson did not answer questions about when the attack occurred or what systems or data was impacted, but noted that “affected factories are currently resuming normal production” as of Tuesday. 

Nitrogen was first observed in 2023, using ALPHV, one of the most prevalent ransomware variants at that time, Cynthia Kaiser, senior vice president at Halcyon’s Ransomware Research Center, told CyberScoop. The group started using stolen code from Conti, another formerly prolific ransomware variant, in 2024 to build its own custom attack tools to hit Windows and VMware server environments, she added.

The threat group has most recently focused on companies in the manufacturing and technology sectors. “However, the most recent cases of claims by Nitrogen do not include a working file listing on the leak site and include mostly older images of files,” Kaiser said. “This raises questions about whether Nitrogen is inflating data-theft claims in an attempt to pressure victims into paying higher ransoms.”

Foxconn hasn’t described the nature of the attack or confirmed the existence of a ransom demand. 

Ismael Valenzuela, vice president of threat research and intelligence at Arctic Wolf Labs, said Nitrogen follows a “consistent playbook, stealing data before encrypting systems so they have leverage on multiple fronts, combining operational disruption with the threat of sensitive information being exposed.”

The threat group’s tactics indicate it’s not opportunistic, but rather “operating with a defined model, focusing on organizations that are easier to access but still critical enough to drive pressure and payment,” Valenzuela added. 

Foxconn, also known as Hon Hai Precision Industry with headquarters in Taiwan, is among the world’s largest companies with $259 billion in revenue last year, the company said. Foxconn’s North American footprint includes multiple factories in Mexico, Wisconsin, Ohio, Texas, Virginia and Indiana.

Matt Kapko

Written by Matt Kapko

Matt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University.



Source link

BRICS meeting overshadowed by war on Iran | US-Israel war on Iran

0

The US-Israeli war on Iran is overshadowing the BRICS meeting as foreign ministers of member countries meet to discuss the fallout from the conflict. Iran’s foreign minister urged the bloc, which now includes the UAE, to condemn the US and Israel for attacks on his country’s territory.



Source link