惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
阮一峰的网络日志
阮一峰的网络日志
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
J
Java Code Geeks
罗磊的独立博客
S
SegmentFault 最新的问题
V
V2EX
V
Visual Studio Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
博客园 - 三生石上(FineUI控件)
Stack Overflow Blog
Stack Overflow Blog
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
D
Docker
Google DeepMind News
Google DeepMind News
Blog — PlanetScale
Blog — PlanetScale
M
Microsoft Research Blog - Microsoft Research
Martin Fowler
Martin Fowler
S
Secure Thoughts
B
Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog
C
Cisco Blogs
C
CERT Recently Published Vulnerability Notes
T
True Tiger Recordings
GbyAI
GbyAI
P
Proofpoint News Feed
P
Privacy International News Feed
Jina AI
Jina AI
The Cloudflare Blog
I
Intezer
AWS News Blog
AWS News Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
S
Security Archives - TechRepublic
NISL@THU
NISL@THU
The Register - Security
The Register - Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
P
Palo Alto Networks Blog
S
Schneier on Security
L
LINUX DO - 热门话题
C
CXSECURITY Database RSS Feed - CXSecurity.com
Security Latest
Security Latest
C
Cybersecurity and Infrastructure Security Agency CISA

Hackread – Cybersecurity News, Data Breaches, AI and More

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds Europol Seizes First VPN Used by Ransomware Gangs, Arrests Administrator Android Malware Spotted Subscribing Victims to Paid Services Without Consent Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks Understanding Trend Structure: Higher Highs and Lower Lows Explained GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension Verizon DBIR: AI Helped Hackers Exploit Vulnerabilities in 31% of Recent Breaches Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks AI Agent Security: Automating Workflow Without Creating Prompt Injection or Data Leak Risks How Parts Inventory Management Software Fixes Inventory Challenges Pwn2Own Berlin 2026 Closes With $1.3 Million in Zero-Day Payouts Criminal IP Returns to Infosecurity Europe 2026 with Advanced AI-Driven TI & ASM Two-Thirds of Nonhuman Accounts Are Unseen and Unmanaged, According to Orchid Security's Identity Gap Hosting Service Standards That Define High-Performing Agencies Hackers Actively Exploit ‘Nginx Rift’ Vulnerability Affecting NGINX, F5 Products 10 Top OSINT Tools Every Investigator Should Know in 2026 New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords 10 Tips for Phrasing Employee Feedback in Reviews Government Backed Hackers Abuse Cloudflare in Malaysian Espionage Campaign Continuous Detection, Continuous Response: Mate Security Redefines the Modern SOC The Gentlemen Ransomware Gang Hit by Internal Breach, Operations Exposed Closing the Gap: The Regulatory and Structural Maturation of Digital Assets Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases Grafana Says It Rejected Ransom Demand After Source Code Theft AI Voice Cloning: The Technology Behind It, Who's Building It, and Where It's Headed Critical ‘Claw Chain’ Vulnerabilities Put Thousands of OpenClaw AI Servers at Risk The Next Cybersecurity Challenge May Be Verifying AI Agents Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4 CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS How Fintech APIs Are Modernizing Business Cash Flow Management China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages Slovakian Admin of Dark Web Kingdom Market Jailed for 16 Years in US Why Canadian Telecom Providers Are Prime Targets for Cyberattacks Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended Fake Claude Code Installer Targets Developers With Browser Credential Stealer Pwn2Own Berlin 2026 Hits Capacity as Rejected Hackers Release 0-Days Top Video Downloaders in 2026: Why Wondershare UniConverter Remains a Strong Choice Operation HumanitarianBait Uses Fake Aid Documents to Deploy Python Spyware Google Says Hackers Used AI to Develop a Zero-Day Exploit Romanian Man Faces Up to 30 Years in US Prison Over Vishing Scams 9-Year-Old Dirty Frag Vulnerability Enables Root Access on Linux Systems Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program Hackers Exploit Vercel GenAI to Mass-Produce Convincing Phishing Sites Two US Men Sentenced for Helping North Korean Hackers Infiltrate US Firms Hackers Trick DigiCert Into Issuing Certificates Used to Sign Malware Hackers Hijack JDownloader Site to Deliver Malware Through Installers Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data ShinyHunters Defaces Canvas LMS Portal, Hundreds of Universities Affected Hackers Use Fake Claude AI Site to Infect Users With New Beagle Malware Researcher Shows Edge Browser Stores Saved Passwords in Plaintext Google Chrome Accused of Silently Installing 4GB AI Model on User Devices Why Outdated Maintenance Software Is a Growing Ransomware Risk Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams Best OSINT Tools for Investigations and Threat Intelligence in 2026 Google Fixes CVSS 10 Gemini CLI Vulnerability Enabling GitHub Issue-Based RCE ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users Building Strategic Advantage With Integrated Planning The "Juice" Factor: Designing Game Feel Application Security Strategies Are Changing as AI-generated Code Floods the SDLC Massive “Low and Slow” DDoS Attack Hits Platform With 2.45 Billion in 5 Hours LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations Anti-ICE Site GTFO ICE Accused of Exposing Data of 17,000+ Activists FEMITBOT Network Abuses Telegram Mini Apps for Crypto Scams and Android Malware Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities Cyber-Secure Philanthropy: Tech Infrastructure for Global Donations 7 Key Features That Make Secure Browsers Safer Paying Ransom Won’t Help as VECT 2.0 Ransomware Destroys Data Irreversibly Google AppSheet Exploited in 30,000-User Facebook Phishing Operation 2 US Cybersecurity Experts Jailed for Aiding ALPHV (BlackCat) Ransomware 45,000 Attacks, 5,300+ Backdoors Tied to China-Linked Cybercrime Operation Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations Critical cPanel Vulnerability Lets Attackers Bypass Login, Gain Root Access Best Diagram Software in 2026, Why EdrawMax Works for Everyday Use Private Chats, Photos of Celebs Exposed in Suspected Stalkerware Leak Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards Managed vs Self-Managed Cloud Hosting: Choosing the Best Option for Your Business 9-Year-Old Linux Kernel Vulnerability “Copy Fail” Enables Full Root Access Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds New AI-Powered Bluekit Phishing Kit Targets Major Platforms with MFA Bypass Attacks Polymarket Rejects Data Breach Claims as Hacker Alleges 300K Records Stolen Brinker Introduces a Novel Approach to Deepfake Detection US-Estonian Suspect Arrested Over Alleged Scattered Spider Cyberattacks Cursor AI IDE Vulnerability Allows Code Execution Via Hidden Git Hooks Top AI-Powered Vendor Risk Management Platforms for SaaS Companies in 2026 New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords Decoding Q1 2026's $152.9 Billion Crypto Custody ConcentrationDecoding Q1 2026's $152.9 Billion Pack2TheRoot: 12-Year-Old Linux PackageKit Flaw Enables Full Compromise Stablecoins: Always-On Money Needs Always-On Controls New Linux FIRESTARTER Backdoor Targets Cisco Firepower Devices Why Unofficial Download Sources Are Still a Security Risk in 2026 The Role of Aggregated Liquidity in Modern Crypto Markets 82 Chrome Extensions Found Selling User Data, 6.5 Million Users Affected
FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit
Deeba Ahmed · 2026-05-14 · via Hackread – Cybersecurity News, Data Breaches, AI and More

Bitdefender Labs reveals how the China-linked FamousSparrow hacking group targeted an Azerbaijani energy firm using ProxyNotShell, Deed RAT, and Terndoor malware across three persistent waves.

A new research report from Bitdefender Labs reveals a hacking campaign against an oil and gas firm in Azerbaijan, which was carried out in phases between December 2025 and February 2026. Researchers have attributed it to the China-aligned group FamousSparrow. The notable aspect of their research is the group’s sudden change in strategic interest, with the South Caucasus energy infrastructure becoming its latest target.

The Attack Cycle

According to research details shared by Bitdefender’s Martin Zugec, the campaign involved three distinct waves of activity, the first of which began on 25 December 2025. In this wave, the hackers used a vulnerability called ProxyNotShell to gain access to the company’s Microsoft Exchange server. To stay undetected, the group used a clever logic gate trick and managed to deliver the malware.

This involved DLL sideloading, where hackers tricked a legitimate program (LMIGuardianSvc.exe) into running a malicious file (lmiguardiandll.dll). This step activated the SNAPPYBEE (aka Deed RAT) backdoor, granting the attackers remote control.

Even when the firm attempted to clean its systems, the hackers exploited the same unpatched initial access vector three times in two months.  This proves that removing malware is temporary if the original exploitation path remains open.

Gaining Deep Access

The second wave, detected in January 2026, introduced a tool called Terndoor. To bypass antivirus software, the hackers used the Mofu loader, an obfuscated stager that hid the malware’s instructions in the computer’s memory. Once activated, Terndoor installed a driver named vmflt.sys.

The hackers created a new service in the Windows registry (HKLM\SYSTEM\ControlSet001\Services\vmflt) to establish a Rootkit and obtain deep, ‘god-mode’ control over the system. They then used the Impacket toolkit and Remote Desktop Protocol (RDP) to steal admin passwords. This helped them move laterally across the entire network.

Attack flow explained (Source: Bitdefender)

Attackers’ Evolving Tactics

In late February, researchers recorded a third wave where the group deployed an updated version of Deed RAT. They shifted their files to a C:\Recovery folder and used the address sentineloneprocom for communication.

This domain was likely chosen to mimic legitimate security traffic, making the malicious data look like a routine software update. This version hid inside standard Windows processes like SearchIndexer.exe and dwm.exe, using AES-CBC and RC4 encryption to lock away its configuration.

The three waves (Source: Bitdefender)

“Beyond the delivery mechanism, the operation is characterized by the deployment of two distinct backdoor families, Deed RAT and Terndoor, which were utilized across three separate waves of activity. This technical variety is matched by a strategic persistence, evidenced by the attackers’ repeated return to the same vulnerable Microsoft Exchange server entry point despite multiple remediation attempts,” researchers noted in the blog post shared with Hackread.com.

The key takeaway from this research is that determined hackers don’t just hit and run- they adapt and return. Bitdefender suggests that patching public-facing software like Exchange is the only way to stop this cycle, alongside consistent monitoring for API hooking, a technique where hackers intercept internal system conversations to maintain control.

(Photo by Zbynek Burival on Unsplash)