SEO poisoning campaign targeting mobile devices in payroll fraud scheme
The campaign involves fake login pages that mimic employee payroll portals.
The campaign involves fake login pages that mimic employee payroll portals.
The operations are believed to be part of a broader effort to collect intelligence supporting Russian state interests.
The operatives traveled between cities and parked vehicles near potential military sites with dashcams secretly recording for 8 to 12 hours at a time.
LEV builds on the Exploit Prediction Scoring System (EPSS).
The breach occurred on December 26, 2024, but went undetected until May 11, 2025.
The group has been using sophisticated callback phishing and social engineering tactics to infiltrate corporate networks.
The campaign uses a stealthy, memory-resident loader dubbed Catena, which stages payloads entirely in memory.
In brief: Several major malware operations disrupted, hackers exploit Ivanti and Cityworks zero-days, and more.
The cyber offensive reportedly struck dozens of entities, spanning both government and private sectors.
The attacks have been ongoing since at least January 2025.
Showing elements 721 - 730