Sign in

IntelFusions

@intelfusions.com
21 followers 41 following 167 posts

intelfusions.com | Cyber threat intelligence platform tracking threat actors, incidents, vulnerabilities & geopolitical cyber operations. Fast, primary-source analysis for defenders.

PostsRepliesMedia
IntelFusions @intelfusions.com · 2h
Attackers are gaming search results so that people looking for the KakaoTalk messenger download a booby-trapped installer. AhnLab says the malware has kept changing shape, most recently hiding its code inside a PNG image. #ValleyRAT #databreach #infosec
intelfusions.com
Fake KakaoTalk installers spread remote access malware
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 10h
Phishing emails are tricking staff into installing genuine IT remote-management software, which attackers then use to add a second remote-control tool and steal credentials. Microsoft has published hunting queries and blocking advice. #ConnectWise #databreach #infosec
intelfusions.com
Phishing lures install two IT admin tools for backup access
Cyber Incidents · IntelFusions threat intelligence
110
IntelFusions @intelfusions.com · 29/09/2026
A payload branded as Pakistani APT36 ransomware turned out to encrypt nothing. K7 Labs traced it to a pirated Windows activator that opened the door days earlier. #MeshCentral #ransomware #infosec
intelfusions.com
Fake APT36 ransomware locks screens but encrypts nothing
Ransomware · IntelFusions threat intelligence
010
IntelFusions @intelfusions.com · 29/09/2026
Microsoft has exposed NeedyMantis, a stealthy backdoor planted in telecoms, universities and government contractors after a break-in, hidden behind legitimate programs like Poedit and Vim. #Impacket #APT #infosec
intelfusions.com
China-linked hackers hide backdoor inside trusted apps
Nation-State · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 28/09/2026
An extortion crew called Emperador says it stole data from Brazil's federal tax authority, including gov.br logins. The claim is unconfirmed, but it is the crew's third Brazilian government listing since August. #Emperador #databreach #infosec
intelfusions.com
Brazil's tax agency appears on a young crew's leak site
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 28/09/2026
The Gentlemen ransomware crew has listed Charles & Keith, the Singapore shoe and handbag brand sold across Asia and beyond, as a victim on its leak site. The claim is unverified and the company has not commented publicly. #TheGentlemen #databreach #infosec
intelfusions.com
Singapore fashion brand Charles & Keith named on leak site
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 27/09/2026
Infostealer malware now walks off with cloud, code and AI keys, not just passwords. Wiz found AWS credentials make up nearly half of what the stealers take, and stolen session tokens let attackers skip MFA. #Amadey #databreach #infosec
intelfusions.com
AWS keys top the secrets infostealers steal, Wiz finds
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 27/09/2026
The MetaEncryptor ransomware crew has listed Astemo, the Japanese auto-parts supplier majority owned by Honda, on its leak site. The company has not confirmed any breach, but the listing extends a month-long run of ever larger names from the same crew. #MetaEncryptor #databreach #infosec
intelfusions.com
Honda-backed parts giant Astemo named on leak site
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 26/09/2026
A Firefox add-on posing as a PDF identity checker shipped with no malicious code at all, then downloaded instructions after install to hijack victims' Google accounts. Few people installed it, but the design is built to slip past store review. #databreach #infosec
intelfusions.com
Firefox add-on hid its malware until after you installed it
Cyber Incidents · IntelFusions threat intelligence
012
IntelFusions @intelfusions.com · 26/09/2026
Scammers bought Google search ads for Ledger through a verified advertiser account and led hardware wallet owners to a fake device check that asks for their recovery phrase. Anyone holding that phrase can empty the wallet without touching the device. #databreach #infosec
intelfusions.com
Fake Google ads steal Ledger wallet recovery phrases
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 25/09/2026
A new version of the MacSync stealer arrives as fake crypto and business apps, uses a public iCloud calendar to hide its next stage, and adds a backdoor that can swap out a Ledger wallet app. #databreach #infosec
intelfusions.com
Mac stealer now hides its loader in an iCloud calendar
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 25/09/2026
A phishing service called EvilTokens sold criminals an AI assistant that wrote the lure, picked the richest victims and stole login tokens instead of passwords. Microsoft has helped take its infrastructure down. #databreach #infosec
intelfusions.com
Microsoft disrupts AI phishing kit that hit 12,000 inboxes
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 24/09/2026
CERT Polska found Facebook ads warning Polish users that their PDF app had expired. The link led to ordinary looking apps on Google Play that could sign the phone up to premium SMS services costing 30.75 zloty a message. #databreach #infosec
intelfusions.com
Fake PDF alerts on Facebook signed Poles up to paid SMS
Cyber Incidents · IntelFusions threat intelligence
001
IntelFusions @intelfusions.com · 24/09/2026
DarkMe used to reach victims through zero-day exploits in WinRAR and Windows SmartScreen. Huntress caught the same trojan arriving the dull way instead, as a link to what looked like a photo and was actually a Windows program. #Evilnum #databreach #infosec
intelfusions.com
A spy trojan swaps zero-days for a plain phishing email
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 23/09/2026
A new Android banking trojan called RemControl arrives inside a dropper that starts a local VPN and routes Google Play Protect into a dead end, so the scanner cannot check the app being installed. Group-IB counted more than 30 targeted banking apps across Europe… #MEDUSA #databreach #infosec
intelfusions.com
Android trojan cuts off Play Protect with a fake VPN
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 23/09/2026
Wordfence analysed a WordPress plugin that creates a hidden admin account, edits the user count so nothing looks wrong, rewrites itself when deleted, and reads its command server address off a smart contract. #databreach #infosec
intelfusions.com
WordPress malware hides its C2 on the Ethereum blockchain
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 22/09/2026
A crew AhnLab tracks as Larva-25012 is installing bandwidth-sharing software on PCs it compromised months ago, disguising it as Microsoft Copilot and Windows security services. Victims lose their internet connection to somebody else's profit, and nothing ever looks broken. #databreach #infosec
intelfusions.com
Proxyware hides as a Copilot service on hijacked PCs
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 22/09/2026
Six separate ransomware crews posted eight Argentine organisations to their leak sites in the week to 20 September, including the country's Ministry of Education. It is the highest weekly total we have recorded for Argentina, and no single crew is driving it. #Qilin #databreach #infosec
intelfusions.com
Argentina had its busiest week yet on ransomware leak sites
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 21/09/2026
Four extortion crews have posted claims against port and maritime companies in the past month, including a Philippine government ports agency and a Malaysian container port. None of them has confirmed a breach. #Akira #ransomware #infosec
intelfusions.com
Extortion crews turn on ports and fuel terminals
Ransomware · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 21/09/2026
Russian companies almost never appear on ransomware leak sites. One small crew lists them more than any other country, and it marks the victims who paid with a code instead of a name. #AuditTeam #ransomware #infosec
intelfusions.com
Extortion crew hits Russian firms and flags who paid
Ransomware · IntelFusions threat intelligence
010
IntelFusions @intelfusions.com · 20/09/2026
An extortion crew posted what looked like four US financial firms in a single day. Illinois regulators and FDIC records show three of them are the same bank group, a warning about reading leak-site victim counts at face value. #Storm #ransomware #infosec
intelfusions.com
Three banks on a leak site are one banking group
Ransomware · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 20/09/2026
AhnLab's monthly review of state-sponsored activity found the same thing across North Korean, Chinese and Russian operations in August: the infrastructure was somebody else's, and all of it was allowed through the firewall. #CLAIMLOADER #APT #infosec
intelfusions.com
State hackers lean on GitHub, Telegram and Discord
Nation-State · IntelFusions threat intelligence
001
IntelFusions @intelfusions.com · 19/09/2026
A leak site nobody had seen a week ago is advertising ten victims at once, among them Argentina's education ministry and Venezuela's largest internet provider. The claims are unverified, and the crew is selling stolen records rather than locking files. #N0n #ransomware #infosec
intelfusions.com
New extortion crew opens with a ministry and an ISP
Ransomware · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 19/09/2026
A phishing site posing as Italy's tax agency offers a holiday bonus and rebuilds the national SPID login flow to look convincing. It was the standout item in a week of 191 malicious campaigns aimed at Italy. #AsyncRAT #databreach #infosec
intelfusions.com
Fake tax bonus site copies Italy's SPID login screen
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 18/09/2026
A fake stock trading app used in Korean investment scams has started installing ransomware on the same people it was built to defraud. AhnLab calls the Rust encryptor KRSID. #ransomware #infosec
intelfusions.com
Fake trading app drops ransomware on scam victims
Ransomware · IntelFusions threat intelligence
010
IntelFusions @intelfusions.com · 18/09/2026
Revolut customers started receiving fake account texts within days of the bank admitting it handed personal records to an impostor. The phishing page fakes Revolut's own video identity check before asking for a password. #databreach #infosec
intelfusions.com
Revolut customers phished two days after breach news
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 17/09/2026
A ransomware crew that spent August naming small suppliers has started listing some of Asia's largest industrial firms. The claims are unverified, which is exactly why the pattern is the part worth watching. #MetaEncryptor #ransomware #infosec
intelfusions.com
Ransomware crew moves from small firms to industrial giants
Ransomware · IntelFusions threat intelligence
010
IntelFusions @intelfusions.com · 17/09/2026
An espionage group that spent years working targets in Asia has turned up inside Russian companies. It logged in with stolen VPN credentials, then used a Microsoft tunnelling service and two years-old bugs to take the domain. #Impacket #APT #infosec
intelfusions.com
NightEagle spies pivot from Asia to Russian networks
Nation-State · IntelFusions threat intelligence
010
IntelFusions @intelfusions.com · 16/09/2026
For about 48 hours, ads from HBO Max's verified Reddit account offered fake AI tools and Mac utilities. The pages behind them served no installer at all, just a command the victim was asked to paste into their own terminal. #AmateraStealer #databreach #infosec
intelfusions.com
HBO Max's verified Reddit account pushed 108 malware ads
Cyber Incidents · IntelFusions threat intelligence
010
IntelFusions @intelfusions.com · 16/09/2026
A Chinese-speaking fraud crew bought at least 100 Telegram usernames and a set of anonymous virtual numbers, then moved its shop from one Telegram escrow marketplace to another. Recorded Future says the model is spreading. #databreach #infosec
intelfusions.com
Fraud vendor buys 100 Telegram names to stay untraceable
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 15/09/2026
More than 700 Hong Kong residents have reported credit card charges they say they never made, with losses of about HK$14.7 million. HKCERT says there is no sign yet that any bank or payment platform was breached. #databreach #infosec
intelfusions.com
HK$14.7 million lost in Hong Kong card fraud wave
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 15/09/2026
Revolut says its staff answered fraudulent requests for customer information that arrived from a genuine government agency's email domain, handing over passport scans, verification selfies and full transaction histories. Nothing was hacked. The address simply looked official. #databreach #infosec
intelfusions.com
Fake data requests pried passports out of Revolut
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 14/09/2026
Three hacktivist crews spent August claiming attacks that knocked Japanese government and company websites offline. Underneath the noise, Japanese hosting providers and insurers were dealing with actual intrusions. #NoName05716 #databreach #infosec
intelfusions.com
Japan takes a month of hacktivist DDoS and real breaches
Cyber Incidents · IntelFusions threat intelligence
011
IntelFusions @intelfusions.com · 14/09/2026
A ransomware crew calling itself Vexy appeared on 3 September and has already named 13 victims, and unlike most new gangs it has almost entirely skipped North America. Its targets cluster in India and Latin America, and three of them are companies that host… #VexyRansomware #ransomware #infosec
intelfusions.com
New ransomware crew Vexy targets India and Latin America
Ransomware · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 13/09/2026
Italy's government CERT counted 170 malicious campaigns aimed at the country in a single week. The one worth pulling out targets businesses: a cloned company register page asking for the firm's tax code and bank details. #XLoader #databreach #infosec
intelfusions.com
Fake business register site hunts Italian company IBANs
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 13/09/2026
Colombia's national response team detonated a Linux ransomware sample it calls Linux Locker and found that it destroys local backups as well as encrypting files. It started encrypting without contacting any server first, so there is no outbound beacon to catch. #ransomware #infosec
intelfusions.com
Colombia warns of Linux ransomware that kills backups
Ransomware · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 12/09/2026
Someone posing as a CoinDesk marketing executive messaged security researchers after DEF CON with a link to a real Google Doc. Opening it while signed in was enough to report the reader's IP address, location and whether they run a crypto wallet. #AsyncRAT #databreach #infosec
intelfusions.com
A shared Google Doc can spy on you before you click
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 11/09/2026
As the large underground marketplaces have been dismantled, the buyers have not gone away. Rapid7 says they have moved to smaller specialist shops and Telegram channels that sell everything a novice fraudster needs. #databreach #infosec
intelfusions.com
Fraud shops scatter to Telegram after big takedowns
Cyber Incidents · IntelFusions threat intelligence
001
IntelFusions @intelfusions.com · 11/09/2026
Proofpoint researchers found four separate espionage groups reaching for the same exploit chain against Chrome on Windows within days of each other. All three flaws it used had only just been patched. #APT #infosec
intelfusions.com
Four espionage groups shared one Chrome exploit kit
Nation-State · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 10/09/2026
Zscaler researchers found a new Windows backdoor that ransomware crews appear to be using to get their first foothold on a network. It is packed with anti-analysis tricks, and also with mistakes that break its own features. #ransomware #infosec
intelfusions.com
Ransomware's new backdoor is riddled with its own bugs
Ransomware · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 10/09/2026
German researchers have mapped almost 119,000 domains running cloned copies of real online stores. The fake checkout pages take the card number and the one-time code the bank sends, and forward both to the criminals while the shopper is still typing. #databreach #infosec
intelfusions.com
118,000 fake shops steal cards and bank one-time codes
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 09/09/2026
Two infections dull enough to be ignored led Unit 42 to a pay-per-install operation that has been selling access to compromised machines for at least two years, funnelled through gaming YouTube channels and poisoned search results. #databreach #infosec
intelfusions.com
YouTube gaming channels fed a two-year malware market
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 09/09/2026
An India-linked espionage group is running lookalike domains that impersonate Pakistan's main port authority, its state telecoms manufacturer and its ordnance factories. The lures are Word files that quietly pull down remote access tools. #Sidewinder #APT #infosec
intelfusions.com
SideWinder spoofs Pakistan's port and arms agencies
Nation-State · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 08/09/2026
Companies cleaning up after the Shai-Hulud supply chain worm often use their own software internally, so restoring a rebuilt system can bring the malware straight back. Sygnia's responders say the fix is to rebuild pipelines from trusted sources, not just delete… #ShaiHulud #databreach #infosec
intelfusions.com
Shai-Hulud victims risk reinfecting their own systems
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 08/09/2026
A phishing platform sold to affiliates has collected more than 4,000 live Microsoft 365 session cookies. Its login pages switch off hardware security keys so victims fall back to a weaker check the attackers can steal. #evilginx2 #databreach #infosec
intelfusions.com
Phishing service switches off security keys to beat MFA
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 07/09/2026
Two research teams have mapped how North Korea actually organises its hacking operations, and the familiar name Lazarus turns out to cover at least six separate clusters. The report also tracks a 2026 shake-up that renamed the country's two main intelligence agencies. #LazarusGroup #APT #infosec
intelfusions.com
North Korea's hacking machine is bigger than Lazarus
Nation-State · IntelFusions threat intelligence
002
IntelFusions @intelfusions.com · 07/09/2026
Researchers found that apps shipped through SuperBox streaming devices can quietly sign a household connection up to a residential proxy network, letting strangers route traffic through the home. Cleaning the device is not as simple as a factory reset. #databreach #infosec
intelfusions.com
Free streaming boxes may rent out your home internet
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 06/09/2026
A provincial court in Argentina, a university teaching hospital in Chile and McDonald's Ecuador were all named on extortion leak sites in the same week. Two of the crews behind the claims did not exist a month ago. #Emperador #databreach #infosec
intelfusions.com
A court and a hospital land on South America's leak sites
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 06/09/2026
A clone of Perak's Park@Perak parking portal loads a zero-click iOS exploit chain that steals messages, photos, passwords and crypto wallets. MyCERT says the campaign is active. #databreach #infosec
intelfusions.com
Fake Malaysian parking site hacks iPhones with no tap
Cyber Incidents · IntelFusions threat intelligence
000
IntelFusions @intelfusions.com · 05/09/2026
Seven Dutch organizations landed on ransomware leak sites in a single week, four of them on LockBit's, against a normal rate of fewer than two. The claims are unverified, but the shift is real. #LockBit #databreach #infosec
intelfusions.com
LockBit leads a four-fold jump in Dutch leak-site listings
Cyber Incidents · IntelFusions threat intelligence
000