Cyber Security Week in Review: October 24, 2025
In brief: Chinese hackers caught exploiting MS SharePoint flaws, Russian Coldriver APT shifts to new malware implants, and more.
In brief: Chinese hackers caught exploiting MS SharePoint flaws, Russian Coldriver APT shifts to new malware implants, and more.
More than 250 exploitation attempts have been detected targeting multiple stores, with the payloads including PHP webshells and phpinfo probes used to gather data.
The operation employed advanced techniques to deliver a custom WebSocket RAT for espionage and data theft.
The model may be a deliberate move to avoid drawing the attention of international law enforcement.
Exploitation is broader than was initially thought, with compromises spanning the Middle East, South America, the United States, Africa and Europe.
It remains unclear whether Chinese or Russian actors were behind the intrusion.
The malware uses invisible Unicode characters to hide malicious code in source files.
The attack was first detected in early July and is believed to have started with the exploitation of a Citrix NetScaler Gateway appliance.
The main suspect instructed the other two minors to map Wi-Fi networks across The Hague on multiple occasions.
Google said Norobot and Mayberobot are likely used for high-value targets who may already have been compromised.
Showing elements 531 - 540