China-linked hackers hijack Southeast Asian routers using custom Linux malware and DNS redirection
The campaign targets border routers and network infrastructure rather than traditional endpoints.
The campaign targets border routers and network infrastructure rather than traditional endpoints.
Ajax first disclosed the breach in March, revealing that attackers exploited vulnerabilities in its IT infrastructure to access personal data.
The coordinated operation disrupted all Glassworm’s communication channels, cutting operators off from infected systems.
The UK action largely targets the A7 network, which officials say is a critical tool for sanctions circumvention and facilitating payments connected to Russian oil exports.
The updated InvisibleFerret malware is now distributed as .pyd files on Windows and .so files on macOS.
The group developed and sold phishing and smishing tools that allowed other criminals to steal banking information from victims.
The flaw, tracked as CVE-2026-5426, impacts KnowledgeDeliver deployments that used default ASP.NET configuration settings before February 24, 2026.
Researchers traced the campaign to compromised versions of the open-source chatbot platform called Tiledesk.
This toolset may be reserved for high-value targets where long-term, stealthy access is the objective.
The attackers used a previously undocumented backdoor called MiniFast, replacing the group’s earlier MiniJunk malware framework.
Showing elements 191 - 200