Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Nintendo Switch Security Flaw Lets Nearby Attackers Exploit QR Codes Used to Share Screenshots

  Nintendo has issued an urgent security advisory for owners of the original Switch console, warning of a flaw that could allow an attacker ...

All the recent news you need to know

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

 

China-linked hackers took advantage of a vulnerability within Sogou Input Method, a widely used typing utility for Chinese characters on Windows, and managed to implant a backdoor onto their victims' computers, security company Gen Digital stated in research published Thursday. 

An initial crafted link would kick off the chain of events, giving the attackers end-to-end access to perform anything the logged in user would have access to. Tencent, which both owns and is developing Sogou, has alreadypatched the vulnerability in April 2026. The vulnerability was uncovered by Gen as they tracked a live ongoing breach by a group known as UNC3569, a China based hacker-for-hire. The group has been tracked since 2021 by Google Threat Intelligence to government, academic, technology, and financial targets, predominantly in Eastern and Southeast Asia. 

The planted backdoor (GRAYRABBIT), is a small program the group has been using for many years. As the first stage of gaining access to a machine, it is used to create a command shell remotely from the attacker, allowing for the uploading and downloading of files. More modules from the attacker's server could also be added into a system at any point via this command-line interface. Research produced in 2023 by Citizen Lab suggests that Sogou Input Method boasts over 455,000,000 monthly users on Windows, Android, and iOS respectively, and has captured approximately 70% of the Chinese input-method market. 

On Windows, this application functions by having several components send messages between one another utilizing its own custom link type, sgbiz:. Gen discovered that the program intended to process these links had an error. It failed to correctly screen command-line arguments from the user, meaning attackers can order Sogou's settings program to instead launch its skin store functionality, but directing it towards the attacker controlled website instead- the only functioning part of the application that opens the browsing window without checking which site you are visiting. 

This browser is already outdated; embedded within the Sogou package is version 80 of Chromium from March 2020. Neither the sandbox protection, nor the same-origin policy in this Chromium build were disabled in the codebase. This allowed a vulnerability released within the Java Script Engine in October 2021 (CVE-2021-38003, fixed in Chrome 95 October that year) to be taken advantage of once more by Chinese hackers. The exploit sends a downloader which can then fetch a few files from an Alibaba Cloud server situated in Hong Kong. 

One file was a DLL designed to spoof and hide inside a pirated copy of 7-Zip. Running processes would be scrutinized for analysis methods in a sandboxed environment prior to deployment of the GRAYRABBIT, which sends out requests for and receives information from a command server, encrypted by RC4 over port 443. Gen alerted Tencent on April 9 th 2026 (the vulnerability has been noted under the designation CVE-2026-51990), and Tencent provided a fix within twelve days in version 16.3.0.3498 (released April 21 st). 

It should be noted that the vulnerability present with the old Chromium build and compromised securities does not appear to have been amended. Users are instructed to update their version of Sogou Input Method without delay, and maintain an eye on the indicators of compromise on publication, which includes the malicious DLL, backdoor files, and applicable command and control websites.

MantaxOtax Android Malware Merges Ransomware and Spyware in New Indonesian Campaign

 

MantaxOtax is a newly identified Android malware that merges ransomware-style file encryption with aggressive spyware capabilities, enabling attackers to both lock users out of their devices and harvest sensitive personal data. Discovered by Zimperium's zLabs team and detailed in a September 9 technical write-up, the threat appears linked to Indonesian actors and spreads primarily via sideloaded APKs hosted on third-party file-sharing platforms. This dual-function design marks a significant escalation in mobile threats, combining financial extortion with deep surveillance to maximize victim impact. 

Once installed, MantaxOtax requests device administrator privileges, followed by permissions for SMS, contacts, audio, images, and Android Accessibility services, which grant it deep control over user interactions. It dynamically resolves its command-and-control (C2) domain from a GitHub repository, allowing operators to shift infrastructure without modifying the malware code. 

On Android 9 and earlier, it recursively scans external storage, encrypts files using AES with unique per-device keys fetched from C2, deletes originals, and leaves behind .enc files; on Android 10+, Scoped Storage limits encryption to the app's own directory. The malware also overwrites victims' images with ransom notes and opens a Firebase-based chat interface for extortion negotiations, which researchers found partially exposed due to a server misconfiguration. 

Beyond encryption, MantaxOtax operates as a full-featured spyware, collecting app inventories, hardware specs, location, browser history, notifications, contacts, call logs, and SMS—including one-time passwords (OTPs). It exfiltrates gallery content, linked Google accounts, WhatsApp profiles and messages (via Accessibility), and Telegram credentials and chat histories. By abusing Android's MediaProjection API, it captures screenshots, records MP4 screen videos, and streams near-real-time footage to attackers, storing media on the Catbox file host. It can also silently activate front or rear cameras to take photos without user knowledge, turning infected devices into always-on surveillance tools. 

Researchers observed multiple variants employing psychological pressure tactics: persistent screen locks, application blocking, and transparent overlays that hijack all touch input. Some versions bombard victims with repeating alert dialogs, full-screen video overlays, and image popups appearing every 600 milliseconds, while others use text-to-speech to audibly deliver attacker messages. A second iteration adopted WebSocket communications for more resilient C2 channels and added features like continuous screen locking and app blacklisting, making remediation harder for average users. These harassment techniques are designed to overwhelm victims into compliance, increasing the likelihood of ransom payment or credential surrender. 

Evidence including language markers and recovered victim files suggests MantaxOtax primarily targets Indonesian users. The misconfigured server also leaked what appears to be the operators' control panel, offering rare insight into their infrastructure. This campaign follows closely after the discovery of THost9, another Android trojan that clones banking apps into isolated work profiles to evade detection. Together, these threats underscore a growing trend of multi-stage mobile malware combining financial fraud, surveillance, and ransomware—highlighting the critical need for users to avoid sideloading apps, keep devices updated with the latest security patches, and use reputable mobile security solutions to detect and block such sophisticated threats before they cause harm.

Check Point Discloses Two Critical VPN Vulnerabilities Allowing RCE


Check Point has addressed two critical flaws in the way its management and firewall products manage VPN certificates. Both vulnerabilities have been assigned a CVSS score of 9.8 out of 10. This makes them one of the most serious flaws impacting the products. The vulnerabilities could permit an unauthorized remote threat actor to run malicious code on compromised devices.

The flaws, tracked as CVE-2026-85103 and CVE-2026-85102, are associated with the validation and processing of digital certificates utilized during VPN connections.

Technical information

The first flaw, CVE-2026-85103, is associated with a heap-based buffer overflow in the VPN certificate data processing. A threat actor may send particularly tailored certificate details to a compromised device and trigger memory corruption.

The second flaw, CVE-2026-85102, is associated with improper verification of certifications during VPN processes. A threat actor could exploit the flaw without getting genuine verification credentials under certain conditions. 

The flaws impact Check Point Security Gateways, while the impacted product range also consists of Security Management Server for the related flaw.

The vulnerabilities affect Check Point Security Gateways, while the affected product range also includes Security Management Server for the relevant flaw.

Potential risks

The flaws can have major risks to enterprises that use Check Point Security Gateways to give site-to-site VPN services or remote-access.

An unauthorized attack may be problematic as the threat actor may not need genuine VPN credentials before trying to abuse the vulnerable component. In case of successful exploitation, remote code execution (RCE) could let a threat actor infect the impacted security infrastructure and may use it as a starting point for more compromise inside an enterprise.

But, Check Point has signalled that it has no proof that these flaws have been abused in the wild. Thus, the incident should be looked at as a critical patching issue and not an active exploitation campaign of the flaws.

Addressing the flaws

The security updates offered by Check Point should be applied to organizations immediately. Admins should check Check Point’s security advisory for the particular product variants and related fixes.

Organizations should also keep an eye for Security Gateway systems and VPN for suspicious activity, unusual certificate-related requests, or suspicious connections.

As both flaws have a CVSS score of 9.8, security teams should prioritize restoration, especially for internet-facing VPN infrastructure. 

US Disrupts Xinbi Guarantee Marketplace Linked to Cyber Scams

 

A Telegram-based marketplace known as Xinbi Guarantee has been sued by U.S. authorities for providing services to scam centers engaged in cyber fraud and money laundering. This operation involved seizing Telegram channels and cryptocurrency wallets connected to the marketplace, as well as freezing digital assets worth more than $52 million. 

A U.S. Department of Justice announcement was made in conjunction with a broader operation led by the Scam Center Strike Force. Authorities also deployed teams to Madagascar to support the disruption of 13 scam compounds that were allegedly operated by Chinese organized crime groups. According to the Justice Department, approximately $52 million in cryptocurrency tied to scam-related money laundering has been restrained in a single day.

The strike force has therefore restrained about $938 million in total assets. The Xinbi Guarantee platform became a major marketplace for the cybercrime ecosystem after other similar services, such as HuiOne Guarantee and Tudou Guarantee, were discontinued. Through the use of Telegram, the platform enabled scam operators to connect with vendors providing services required for large-scale fraud schemes. 

As reported by the marketplace, services offered include the creation of fraudulent investment sites, the laundering of proceeds from wire fraud, and recruitment of individuals for scam compounds in Southeast Asia. Additionally, Xinbi served as an intermediary, holding payments until vendors completed the requested services. Using blockchain analytics, Elliptic identified and frozen wallets holding $52.8 million in Tether's USDT stablecoin in coordination with the United States Secret Service. 

According to Xinbi's estimates, it has processed approximately $30 billion in transactions since its emergence around 2022, ranking among the top illicit marketplaces to date. Also linked to U.S. sanctions are entities involved in this marketplace. 

A US Treasury official indicated that Xinbi's infrastructure had been used by North Korean hackers and sanctioned groups related to the Prince Group. Two cryptocurrency wallets containing approximately $12 million were seized from Xinbi that were used to receive vendor payments directly. In addition, two companies accused of supporting Xinbi's operations were sanctioned. 

SafeW Technology of Singapore was sanctioned based on its role as a provider of encrypted communications, whereas Anwen Technologies of Cambodia was sanctioned for its association with XinbiPay, also known as NewPay, an application for digital wallets. 

It was discovered by blockchain intelligence firm TRM Labs that Xinbi's network offers a wide range of services, including stolen personal information, counterfeit identification documents, artificial intelligence-driven deep fake tools, satellite internet equipment and over-the-counter cryptocurrency exchanges. These services provided scam groups with the technical and financial resources necessary for large-scale fraud campaigns.

According to TRM Labs, Xinbi may have handled more than $36 billion in transactions, higher than the U.S. government estimate of over $24 billion. As a result of the decline in HuiOne Guarantee and Tudou Guarantee, daily inflows almost doubled between May and December 2025, according to the firm's analysis. 

Elliptic reported Xinbi appeared offline in response to the latest action, and Telegram removed its main channels and banned the platform's usernames, thereby negatively affecting the marketplace's online presence. This disruption poses a direct threat to a marketplace that relies on communication channels, vendor connections, and cryptocurrency payments for its operation. 

A larger U.S. effort is being made to disrupt the infrastructure underlying Southeast Asia's scam economy. The Scam Center Strike Force has expanded its activities beyond financial seizures, with teams sent to Madagascar to assist with the closure of 13 scam compounds allegedly operated by Chinese criminal groups. 

In addition to drawing attention to the financial threat, the U.S. government has also emphasized its scale. During 2024, Americans lost at least $10 billion to scams originating from Southeast Asia, according to a March report published by the U.S.-China Economic and Security Review Commission; losses are expected to increase in 2025. The commission noted that criminal groups are maintaining their operations in spite of enforcement efforts by using advanced technology and cryptocurrency. 

Separate investigations conducted by the House Select Committee on China have indicated that scam compounds in Cambodia and Myanmar are part of a larger criminal ecosystem which includes money laundering, cyber fraud, and human trafficking. 

The findings show that online scam operations are increasingly supported by interconnected financial, technological, and physical infrastructures rather than isolated fraud groups. An action against Xinbi Guarantee demonstrates the growing focus on dismantling the financial, technological, and communication infrastructure that supports large-scale cyberfraud schemes.

Microsoft Tracks Cloud Intrusion Campaign Using Passkey Phishing and Graph API Abuse

 

Microsoft Security Research published a report on September 9, 2026, detailing active cloud-based intrusions spanning multiple accounts, in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. 

According to Microsoft, the activity begins with identity-focused social engineering and impersonation infrastructure, then progresses through authentication persistence and cloud reconnaissance before culminating in targeted data access consistent with data collection and potential exfiltration. Microsoft Threat Intelligence assesses that the initial access techniques observed in this campaign are used by a range of threat actors, including Storm-3121, Storm-3032, and others. 

The attack typically begins with what appears to be a routine call or message to a user's personal phone number from someone posing as the organization's IT helpdesk. Microsoft found that a "passkey" narrative is frequently used as a pretext, guiding victims through adversary-in-the-middle phishing or device-code authentication flows designed to hijack their session. 

Once initial access is achieved, the actor's first priority is converting a temporary compromise into a persistent foothold. This is typically done by enrolling a new multi-factor authentication (MFA) method under the attacker's control, such as registering a new phone number, an authenticator app, or a software-based one-time password token. With MFA persistence established, the actor moves into an extensive internal reconnaissance phase, using Microsoft Graph to inventory users, groups, permissions, resources, and accessible content across the compromised tenant. 

Following reconnaissance, the actor transitions into large-scale data collection across Microsoft 365 workloads. Microsoft observed significant volumes of FileAccessed and FileDownloaded events across SharePoint and OneDrive, indicating systematic retrieval of cloud-hosted documents and organizational data. Microsoft recommends that defenders investigate this attack sequence across identity, Microsoft Graph, SharePoint, OneDrive, and Exchange signals. For confirmed compromises, organizations should revoke active sessions and remove any unauthorized authentication methods added by the attacker. 

Microsoft further advises enforcing phishing-resistant MFA through Conditional Access policies, along with Conditional Access rules requiring a managed, compliant device for access to Exchange, SharePoint, and Graph-privileged applications. Microsoft has published a list of indicators of compromise associated with the campaign. These include domains tied to fraudulent passkey support and setup lures, such as passkeyhelpdesk[.]com, secure-passkey[.]com, setupmypasskey[.]com, and add-passkey[.]com. Additional domains are linked to identity-provider sessions and key synchronization infrastructure, including oktasession[.]com, keysyncos[.]com, oskeysync[.]com, oskeysetup[.]com, oskeyregister[.]com, syncmykey[.]com, myconnectkey[.]com, and oskeyconnect[.]com. Other identified domains, validationsetupac[.]com and portalsetuphub[.]com, are associated with account validation and portal setup lures respectively. 

Microsoft's report underscores the growing sophistication of identity-based attacks that blend social engineering with legitimate cloud APIs, making early detection across authentication and Graph activity critical for organizations defending Microsoft 365 environments.

Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection

 

A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud detection and make stolen transactions look like they came from a clean device. Group-IB says the campaign combines Gigabud with a weaponized app-cloning tool called Vwork, which it links to the GoldFactory group. 

Gigabud is not a new threat, but this latest version shows how mobile banking fraud is becoming more sophisticated. The malware reportedly uses Android’s Work Profile feature to isolate a cloned banking app from the user’s personal profile, which can break the connection between a malware alert and the later payment activity. 

According to the report, Vwork exposes cloning functions through an interface that other apps on the device can call, making it easier for Gigabud to automate the attack. The trojan includes commands to provision the profile, clone a target app, and report back what was copied, while requiring a token from an external authorization server before cloning begins.

The fraud chain was confirmed on devices in Indonesia, where Group-IB observed about 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026, with estimated losses of roughly $960,939. The samples were also found targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye. 

To reduce risk, Group-IB recommends that banks watch for warning signs such as a work profile appearing on a phone the customer never configured, matching app markers across profiles, and suspicious accessibility access on apps that should not need it. For users, the safest habit is to install apps only from official stores and avoid suspicious links delivered through phishing sites, messengers, or social media.

Featured