New North Korea-linked Android spyware KoSpy targets Korean and English-speaking users
KoSpy is distributed through fake utility applications, which masquerade as helpful tools.
KoSpy is distributed through fake utility applications, which masquerade as helpful tools.
The breach is believed to be part of a broader cyberespionage effort by China’s government targeting US critical infrastructure.
The group first gained access to a target network through a terminal server used for managing devices.
The vulnerability could be exploited by attackers to break out of WebKit's Web Content sandbox by using maliciously crafted web content.
One of zero-days, CVE-2025-24983, has been actively exploited by cybercriminals to install a backdoor called ‘PipeMagic.’
More than 6,000 devices have already been infected by Ballista.
If successfully exploited, the flaw could allow attackers to execute arbitrary code.
No security patches or firmware updates will be released because the product was discontinued more than ten years ago.
In the recent campaign, the group has been observed exploiting CVE-2024-43451.
Phantom Goblin primarily targets web browsers and developer tools.
Showing elements 861 - 870