Fake VS Code Extension ‘ClawdBot Agent’ Found Installing Remote Access Trojan on Developer Machines
Executive Summary In late January, a malicious Visual Studio Code extension named ClawdBot Agent was identified actively…
continue reading..
Silent Intrusion: ShadowPad Malware Found Embedded in Trusted Security Software Across Southeast Asian Telecoms
ShadowPad Malware Activity Targeting Telecommunications Providers Incident Overview – January 27 In late January, a targeted intrusion…
continue reading..
Ransomware Follows the Click: Amnesia RAT Spreads Through Phishing Attacks Targeting Russian Users
Amnesia RAT Phishing Campaign Leading to Ransomware Deployment Date Identified: January 26Threat Type: Multi-stage phishing attack →…
continue reading..
New ‘Vect’ Ransomware Emerges, Hits Education and Manufacturing Networks Across Two Continents
Vect Ransomware Date Observed: January 2026Threat Type: Ransomware-as-a-Service (RaaS)Targeted Sectors: Education, ManufacturingAffected Regions: Brazil, South AfricaThreat Status:…
continue reading..
New Ransomware Group “BravoX” Goes Live, Launches Affiliate-Driven Extortion Campaign
BravoX Ransomware-as-a-Service (RaaS) Initial Public Operations Observed: January 26 Executive Summary BravoX is a newly operational ransomware…
continue reading..
Operation Nomad Leopard: How a Single Email Opened the Door to Silent Government Espionage
Executive Summary Operation Nomad Leopard is a targeted cyber-espionage campaign focused on Afghan government personnel. The attack…
continue reading..
The Invisible Breach: How WSL2 Became a Silent Backdoor on Windows Systems
WSL2 Abuse for Stealthy Post-Compromise Activity Executive Summary A security investigation identified the abuse of Windows Subsystem…
continue reading..
Trusted Tools, Weaponized: How Zendesk Support Systems Were Turned into a Global Spam Cannon
Expanded Overview This activity represents a systematic abuse of customer support tooling as a spam delivery platform,…
continue reading..
When Search Becomes the Attack Vector: APT37’s Abuse of Google Ads for Silent Espionage
Incident Overview APT37 (also known as Reaper) is a threat group linked to North Korea that has…
continue reading..
