Chinese hackers maintained access to critical network for a decade
The attackers deployed a modified GS-Netcat reverse shell disguised as a legitimate system component for remote access.
Shadowserver reported that attackers had already compromised and backdoored some of publicly accessible Sentry gateways.
The attackers deployed a modified GS-Netcat reverse shell disguised as a legitimate system component for remote access.
In brief: Windows Netlogon, Oracle, PAN-OS bugs exploited in the wild, Gamaredon APT targets Ukrainian government, and more.
TA4922 now conducts more unique campaigns than any other cybercrime actor, says Proofpoint.
The framework's code and payloads were developed using AI agents powered by Cursor and Claude Opus.
The malware spreads through fake Minecraft mods, cheats, clients, and other tools.
The attackers tricked the AI into linking their own email addresses to targeted accounts.