Analysis
Akira (or Akira Ransomware) is fast becoming one of the fastest growing ransomware families, utilizing a double extortion tactic, a Ransomware-as-a-Service (RaaS) distribution model and unique payment options.
Report
Password-related cyberattacks through malware infections are at the top of the list of the most popular attacks. Nearly 31 percent of all security breaches analyzed by the Verizon DBIR team since 2013 have been related to stolen credentials.
New malware discovered
A new threat has emerged on the cybercrime scene that is specifically targeting ATMs in Europe and could therefore endanger the entire banking industry. The malware, known as “EU ATM Malware”, was recently offered for sale on a hacker forum.
10 international arrest warrants, 4 arrests
Investigators are talking about the biggest strike against cyber criminals: more than 100 servers have been confiscated and 1300 domains put out of operation in an operation in several countries worldwide.
Akamai study
Akamai Technologies, provider of web, cloud and security solutions, has presented its new “State of the Internet” report. This shows that the number of DDoS attacks is increasing most rapidly in the EMEA region (Europe, Middle East, Africa).
Incident response plan necessary
ClickFix is already being used by a number of nation-state actors such as APT 28 and Kimsuky. The distribution of stealer malware such as Lumma Stealer via the social engineering campaign is particularly popular.
Session tokens are also recorded
Security researchers from Sophos X-Ops have investigated the workings of Evilginx. The malware, which is based on the widely used open source web server nginx, poses a significant threat to IT security by enabling targeted adversary-in-the-middle attacks and can even bypass multi-factor authentication (MFA).
Germany affected
Security researchers from Kaspersky have discovered a particularly sophisticated variant of the Triada Trojan on imitation Android smartphones. More than 2,600 users worldwide, including in Germany, are affected.
The invisible danger
More and more free file converters on the Internet are turning out to be treacherous traps. The FBI warns of manipulated online tools that not only convert files, but also smuggle malware or even ransomware onto victims’ computers. Converters for documents, music files and file mergers are particularly affected.
Targeted phishing campaigns
Medusa ransomware has posed a growing threat to companies worldwide since the beginning of 2025. Check Point warns of the increasing activity of this hacker group.
New variants of SparrowDoor
After a long period of dormancy, the Chinese hacker group FamousSparrow is active again. According to the IT security company ESET, the group has become increasingly dangerous and has deployed new, sophisticated espionage tools.
Cybercrime 2024
Cybercriminals have adapted their methods in 2024 and are increasingly targeting mobile devices and the cryptocurrency sector.
Thousands of TP-Link Archer routers as target
Security researchers from the threat research team at Cato Networks have identified a new threat: the IoT botnet “Ballista”. This malware exploits a serious vulnerability in TP-Link Archer routers to spread unhindered across the internet.
Hackers infiltrate over 330 malicious apps into Google Play
Cyber criminals have managed to bypass Android’s security mechanisms and infect over 60 million users worldwide with malware. Experts from Bitdefender Labs discovered a large-scale malware campaign with over 330 infected apps.