Cybersecurity researchers have reported a wave of phishing campaigns delivering the DarkWatchman malware across a wide range of sectors in Russia and nearby regions. This JavaScript-based remote access trojan (RAT), first identified in 2021, is known for its stealthy, fileless execution and modular design that allows it to keylog, collect system info, and install secondary payloads. The group behind this activity, Hive0117, has been linked to past campaigns targeting telecom and industrial sectors in Eastern Europe. Most recently, Russian organizations across finance, tourism, manufacturing, and telecom were targeted using fake courier delivery emails containing password-protected archives that deployed an evolved version of DarkWatchman designed to evade detection. In a parallel campaign in Ukraine, a newly discovered malware dubbed “Sheriff” has been used in cyberattacks against defense sector entities. This Windows backdoor was hosted on the popular Ukrainian news portal ukr.net, likely through a breach, and is designed for stealthy long-term surveillance. Sheriff supports screenshot capture, command execution, and data exfiltration using Dropbox as a command-and-control (C2) channel. The malware includes a built-in “suicide” mechanism for self-deletion, further emphasizing the attacker’s goal of remaining undetected. Similarities between Sheriff and other sophisticated malware families such as CloudWizard, Kazuar, and Prikormka suggest potential links to known Russian threat groups. The scale of these cyberattacks reflects a significant increase in cyber incidents in Ukraine, with over 4,300 incidents reported in 2024 alone—a sharp rise from prior years. Although high-severity incidents declined, the overall activity remains intense, with attackers combining espionage, sabotage, and supply chain compromise tactics. Russian hackers appear to be heavily focused on collecting intelligence to support military operations, with particular attention paid to systems tied to defense and situational awareness infrastructure.
IBM released security patches for over 100 vulnerabilities across various products. The biggest sufferers of these patches were Storage Defender, for which patches were issued for ...
Fieldtex Products, a U.S.-based provider of contract sewing and medical supply fulfillment, has reported a data breach following an attack attributed to a well-known ransomware ope...
The Pierce County Library System (PCLS) has announced a major data breach affecting more than 340,000 individuals, including library patrons, employees, former employees, and some ...