Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Campaigns

20 articles

GBHackers Campaigns Linux May 25

Kazuar Malware Becomes Modular Spyware for Secret Blizzard Ops

A major evolution in the Kazuar malware family, a long-standing cyber espionage tool linked to the Russian state-sponsored threat group Secret Blizzard, also...

T1598

GBHackers →

GBHackers Campaigns May 25

Hackers Compromise 34 npm, PyPI, and Crates Packages in Major Supply Chain Attack

Hackers have launched a large-scale software supply chain attack targeting developers across npm, PyPI, and Crates.io, compromising at least 34 open-source p...

T1041 T1195 1 IOC

GBHackers →

BleepingComputer Campaigns GitHub May 23

Laravel Lang packages hijacked to deploy credential-stealing malware

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after a...

T1195

BleepingComputer →

The Hacker News Campaigns Oracle GitHub Linux May 23

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved f...

T1195

The Hacker News →

The Hacker News Campaigns May 23

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to del...

T1195

The Hacker News →

Security Affairs Campaigns May 23

Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets

Ghostwriter targeted Ukrainian government agencies with phishing emails delivering malware and Cobalt Strike payloads. The Belarus-nexus APT group Ghostwrite...

T1566

Security Affairs →

GBHackers Campaigns Google May 23

Hackers Use SEO Poisoning to Fake Gemini CLI, Claude Installers

Financially motivated threat actors are running an active campaign that impersonates Google’s Gemini CLI and Anthropic’s Claude Code, using SEO poisoning to ...

GBHackers →

The Hacker News Campaigns May 22

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures...

T1566

The Hacker News →

SC Media Campaigns Google May 22

Trapdoor ad fraud campaign used hundreds of Android apps

The Trapdoor campaign initially distributed seemingly legitimate utility apps, such as PDF readers, through the Google Play Store.

SC Media →

Unit 42 Campaigns May 22

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tr...

Unit 42 →

The Hacker News Campaigns GitHub May 22

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub reposit...

T1041

The Hacker News →

Infosecurity Magazine Campaigns May 22

Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning

The infostealer payload in this campaign collect a vast amount of data, from collaboration authentication keys to cryptocurrency wallets

Infosecurity Magazine →

Help Net Security Campaigns May 22

Suspected KimWolf botnet admin arrested over DDoS-for-hire operation

U.S.

Help Net Security →

GBHackers Campaigns May 22

Hackers Use Six-Layer Persistence on FreePBX Systems

Hackers are actively exploiting FreePBX systems using a highly resilient six-layer persistence mechanism. The campaign has been attributed with high confiden...

T1190

GBHackers →

GBHackers Campaigns May 22

Hackers Weaponize NF-e Invoice Lures to Deploy Banana RAT

Hackers are actively using Brazil’s electronic invoice system (NF-e) as a lure to distribute a sophisticated banking trojan known as Banana RAT. The campaign...

T1598

GBHackers →

Help Net Security Campaigns Microsoft May 22

Microsoft 365 users targeted by new phishing threat that bypasses MFA

Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning. First observed in Ap...

T1566

Help Net Security →

GBHackers Campaigns Google May 22

Android Malware Secretly Signs Users Up for Premium Services

Android users are being targeted by a large-scale malware campaign that silently subscribes victims to premium mobile services without their knowledge. The m...

GBHackers →

The Hacker News Campaigns May 22

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

The U.S.

The Hacker News →

GBHackers Campaigns GitHub May 22

Megalodon Malware Rapidly Infects Over 5,500 GitHub Repositories

A newly identified malware campaign dubbed “Megalodon” has compromised more than 5,500 GitHub repositories, raising serious concerns about the security of op...

GBHackers →

GBHackers Campaigns May 22

Hackers Abuse Hugging Face to Deliver npm Malware

A newly uncovered supply chain attack targeting the npm ecosystem has been linked to North Korean (DPRK)-aligned threat actors. The campaign centers around a...

T1041 T1195

GBHackers →

«Previous page 1 ... 6 7 8 9 10 ... 18 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA