惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
GbyAI
GbyAI
V
Vulnerabilities – Threatpost
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
Recorded Future
Recorded Future
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
博客园 - 司徒正美
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
美团技术团队
博客园 - Franky
Blog — PlanetScale
Blog — PlanetScale
B
Blog RSS Feed
V
Visual Studio Blog
Martin Fowler
Martin Fowler
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
博客园_首页
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 叶小钗
AWS News Blog
AWS News Blog
Project Zero
Project Zero
T
Threat Research - Cisco Blogs
V
V2EX
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Latest news
Latest news
N
News and Events Feed by Topic
The Last Watchdog
The Last Watchdog
T
Threatpost
L
Lohrmann on Cybersecurity
小众软件
小众软件
IT之家
IT之家
MongoDB | Blog
MongoDB | Blog
博客园 - 聂微东
Engineering at Meta
Engineering at Meta
爱范儿
爱范儿
Google Online Security Blog
Google Online Security Blog
Forbes - Security
Forbes - Security
Attack and Defense Labs
Attack and Defense Labs
The Register - Security
The Register - Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
H
Help Net Security
Security Latest
Security Latest
Recent Announcements
Recent Announcements
C
Check Point Blog
B
Blog
Google DeepMind News
Google DeepMind News
K
Kaspersky official blog
I
InfoQ

Proofpoint News Feed

Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective | Proofpoint US The Hacker News Hackers find a new trick to collect Microsoft Entra user data without raising red flags Suspected Chinese snoops caught breaking into universities New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense | Proofpoint US OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Suspected North Korean actors use fake ‘coding assignments’ to steal crypto China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era | Proofpoint US Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude | Proofpoint US Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America | Proofpoint US The spy who logged me in. - YouTube Proofpoint Establishes Innovation Precedent for Source-Agnostic Modern Enterprise Investigations | Proofpoint US The Most Powerful Women Of The Channel 2026: Power 100 AI Security Gaps Create New MSSP Opportunity: Proofpoint Claude Mythos Fears Startle Japan's Financial Services Sector Proofpoint Research Reveals Half of Global Organizations Experienced AI Incidents Despite Having AI Security Controls in Place | Proofpoint US AI-Era Threats Spread Beyond Email Into SaaS, Collaboration Apps, and AI Assistants Clear market trend for software providers to help with AI: Proofpoint CEO - YouTube Cargo thieving hackers running sophisticated remote access campaigns, researchers find - YouTube FIFA World Cup 2026: More than One-Third of Official Partners Expose the Public to the Risk of Email Fraud | Proofpoint US Microsoft 365 mailbox rules abused for exfiltration, persistence AI Security Risks: Proofpoint CSO Ryan Kalember, Live at RSAC 2026 Axios Future of Cybersecurity: Russians suspected of using iPhone spyware 15 Top Cybersecurity CEOs On The Future Of AI Agents: RSAC 2026 How AI Agents Are Redefining the Insider Risk Threat Model 5 Ways To Protect Enterprise Value During A Merger Or Acquisition CUBE Events 20 Coolest AI And Security Products At RSAC 2026 Proofpoint Redefines Email and Data Security for the Agentic Workspace | Proofpoint US Proofpoint Pursues FedRAMP High Authorization Process for Collaboration Security | Proofpoint US Proofpoint Unveils Industry’s Newest Intent-Based AI Security Solution to Protect Enterprise AI Agents | Proofpoint US
Freight Hacker Wields Code-Signing Service to Evade Defenses
2026-04-16 · via Proofpoint News Feed
Prolific Threat Actor Focused on Using Malware to Facilitate Cargo Theft (euroinfosec) • April 16, 2026    
Freight Hacker Wields Code-Signing Service to Evade Defenses
Image: NetVideo/Shutterstock

Cybercriminals don't hold up cargo trucks with a shotgun; they hack transport and logistics firms.

See Also: 5X Faster : Transforming Email Security Operations

Many attacks that target the sector attempt to trick victims into installing malware that deploys remote management and monitoring tools, which attackers use to remotely control a victim's system and steal credentials, enabling freight diversion and cargo theft, said cybersecurity firm Proofpoint.

In research published Thursday, firm researchers said the largest logistics-targeting threat actor they tracked recently deployed a stealthy new tactic to sneak RMM software onto a victim's system. Proofpoint first detailed in November 2025 how hackers use RMM, using illicit access to bid on authentic shipments and intercept cargo, often reselling it online or shipping it overseas with help from organized crime groups.

The discovery is thanks to the researchers taking a recent sample of malware and detonating it inside their deception platform, run using software built by Deception Pro, which creates a real-looking but synthetic Active Directory environment.

The threat actor took the bait, believing the infection to be real, which allowed the researchers to monitor malicious activity, including the attacker repeatedly returning to try out new strategies - likely alongside other environments they'd compromised - for more than a month.

Major new findings included the threat actor, likely a small group of individuals, wielding 13 different PowerShell scripts designed to enumerate local accounts, extract browsing history, exfiltrate useful data to attacker-controlled bots on Telegram, as well as "identify hard-coded URLs associated with banking, payments, logistics, fleet services and accounting platforms," including tax-prep software.

The attacker also installed a number of different types of RMM software onto the decoy system, including SimpleHelp RMM, Pulseway RMM and four different instances of Connectwise ScreenConnect, revealing a heavy focus "on remote administration and redundancy," the report says.

"The breadth of these targets strongly aligns with financially motivated theft, fraud and cargo diversion operations tied to transportation workflows," not least because of attackers searching for credentials tied to "fuel card services, fleet payment platforms and freight brokerage systems," the report says.

The threat actor deployed all of the scripts through hands-on-keyboard activity, rather than as automated follow-ups to an endpoint being infected.

The first thing attackers attempted to do in the decoy environment wasn't to steal credentials for logistics platforms. Instead, they looked for PayPal use in the browser and also searched for bank account details, cryptocurrency wallets and other valuable data.

"They not only have an expertise in the transportation sector and how to compromise carriers, bid on loads and steal freight, but they also are doing the common thing that most cybercriminals will do, which is look for anything they can monetize, on any machine that they compromise," Ole Villadsen, staff threat researcher at Proofpoint, told Information Security Media Group.

The threat actor's campaign began on Feb. 27, when they sent firms in the industry a phishing message with a malicious attachment in the form of a Visual Basic Script, Proofpoint said. If executed, the VBS was designed to download and execute a second-stage PowerShell payload as well as to display "a decoy broker-carrier agreement" to make it look like nothing was amiss, researchers said.

The second stage script built a download URL for a Windows installer file for ScreenConnect - in the form of an .msi file - tied to attacker-controlled infrastructure hosted at amtechcomputers[.]net, then submitted the MSI file download to a third-party service hosted at signer[.]bulbcentral[.]com.

This third-party service turned out to be a code-signing service, which is something the researchers - and a variety of other researchers they queried - had never seen before. By using this service, attackers "re-signed ScreenConnect installers and components with a valid - but fraudulent - code-signing certificate," says Proofpoint's report.

Who's providing this signing service isn't clear. Villadsen said it's probably distributed by word of mouth.

In theory, an operating system should flag any piece of software signed using an invalid digital certificate. But because the attacker's installers and components aren't being downloaded by the user, but handled by a script, this activity doesn't always seem to get flagged. When it does, "the warnings are less common and less severe," Villadsen said.

One thing this campaign reinforces is that "actors love ScreenConnect, that's their favorite RRM by far." From late 2024 through early 2025, it was the most-used such tool by attackers in the wild, Villadsen said (see: Attackers Wield Signed ConnectWise Installers as Malware).

This led last June to a certificate authority revoking one of Connectwise ScreenConnect's signing certificates for violating its trust standards. In response, ConnectWise redesigned the architecture of its installer and migrated to new certificates. Since then, customers using on-premises versions of its software have been required to sign their own clients.

As a result, if criminals now attempt to directly install an illicit copy of ScreenConnect's software on a target's system, they risk operating systems, browsers and endpoint security tools intercepting such activity and warning users that they've found a fake certificate.

By using the signing-as-a-service capability, attackers have found a way to help route around ScreenConnect's crackdown.

Villadsen said this reflects in part by how active as well as innovative this financially focused threat actor is. "We see them every week, if not every day, doing operations," he said, compared to other groups that might have a cadence set to doing activities every few days or even weeks.

Multiple threat actors focus on logistics firms in North America and Europe, contributing to what researchers estimate to be $35 billion in annual, global losses to cargo theft.

Security researchers at startup Have I Been Squatted and threat intelligence firm Ctrl-Alt-Intel in February detailed a phishing-as-a-service platform designed to target the sector that resulted in the theft of over 1,600 unique login credentials.

The researchers said the phishing platform appeared to have been developed by a Russian-speaking coder and marketed on Russian cybercrime forums (see: Phishing Platform Targeting Trucking and Logistics Disrupted).

Villadsen said the threat actor his group tracked appears to have no crossover with operators of the phishing platform. Proofpoint tracks a dozen different threat groups targeting the sector, typically either by hitting victims with payloads that lead to RMM tools or by spoofing legitimate logistics platforms and using phishing campaigns to steal valid credentials.