Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

Head Mare Hackers Exploit TrueConf Servers to Spread Backdoors Through Malicious Updates

  The Head Mare hacktivist group has been targeting unpatched True Conf video conferencing enterprise servers to replace legitimate client i...

All the recent news you need to know

FBI Disrupts QTFY Hacking Network Targeting U.S. Organizations




The U.S. Department of Justice (DoJ) and Federal Bureau of Investigation (FBI) have disrupted two hacking platforms operated by a China-linked threat group that were used to conduct reconnaissance, compromise vulnerable systems and conceal attacks against U.S. government agencies, critical infrastructure and other sensitive organizations.

The platforms, QScan and QTRouter, have been attributed to QTFY, a Chinese state-sponsored hacking group linked to Nanjing Xinjiuwei Network Technology Company. According to U.S. authorities, QTFY activity has targeted organizations including NASA, the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, National Institutes of Health and the U.S. Senate.

Lumen Black Lotus Labs, which tracked the infrastructure for more than 18 months, said QTFY activity dates back to at least May 2018. The researchers described the group as an infrastructure "quartermaster" that developed reusable systems for reconnaissance, exploitation and traffic obfuscation.


QScan automated reconnaissance and exploitation

QScan formed the reconnaissance component of the operation. The platform scanned internet-connected systems and IoT devices for vulnerabilities before automatically compromising susceptible devices and incorporating them into the QTRouter network.

The FBI said QScan was also used to identify vulnerabilities in victim networks. Its infrastructure included servers responsible for distributing scanning tasks to worker nodes and collecting completed results.

The scale of the operation allowed QTFY to conduct reconnaissance across large numbers of systems. Lumen identified scanning activity spanning more than 130 countries, with targets including government, defense, aerospace, healthcare, financial, energy and research organizations.


QTRouter concealed attackers' origins

Compromised devices identified through QScan were subsequently used by QTRouter as proxy nodes. The network combined hacked IoT devices with commercial proxy services and leased virtual private servers (VPSs), allowing malicious traffic to pass through multiple intermediary systems.

This architecture made an intrusion originating from China appear to come from an internet connection located elsewhere. In some cases, QTRouter could route traffic through systems geographically close to the targeted organization, making the activity appear more consistent with legitimate local traffic.

QTRouter operated on routers running customized OpenWrt software and used the Clash proxy framework to establish connections. Operators could select available nodes and chain them together, creating multiple layers between themselves and their targets.

The FBI said this combination of compromised IoT devices and legitimate commercial proxy infrastructure made malicious traffic difficult to distinguish from normal internet activity.


Attackers exploited new and older vulnerabilities

QTFY's attack chain involved both recently disclosed and long-standing vulnerabilities. The vulnerabilities identified by investigators included flaws in Ivanti Connect Secure, Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange Server, F5 BIG-IP, Kentico CMS, Apache Log4j, Atlassian Confluence, Check Point Quantum Gateway, CrushFTP and BeyondTrust Remote Support.

After obtaining initial access, QTFY actors used remote access trojans, web shells and legitimate credentials to maintain persistence.

The infrastructure could subsequently provide concealed access into victim networks through nearby compromised IoT devices. QTBotnet also allowed operators to control infected systems, execute commands and conduct distributed denial-of-service attacks.


Four-part infrastructure supported QTFY operations

Lumen identified QScan and QTRouter as part of a larger architecture that also included Fast Labyrinth and QTProxy.

Fast Labyrinth incorporated commercial proxy infrastructure into encrypted relay paths, while QTProxy managed operational nodes and allowed operators to configure routes toward selected targets.

The researchers compared the architecture to an operational relay box, or ORB, network. Such systems use compromised devices and leased infrastructure as rotating relay points, making traditional IP blocklists and location-based defenses less effective.

Lumen said the infrastructure demonstrated an increasingly industrialized model of China-linked cyber operations, in which reusable and shared services can provide reconnaissance and anonymity at global scale.


FBI seized domains used by the platforms

The disruption targeted domains hard-coded into QScan and QTRouter, including infrastructure used to distribute scanning tasks and administer proxy connections.

By seizing these domains through court-authorized action, U.S. authorities disrupted communication between the platforms and their operators, causing the systems to cease functioning.

Investigators also linked QTFY to Chinese cyber-brokering networks where exploits, malware and access to compromised organizations were allegedly traded. Nanjing Xinjiuwei was described by U.S. authorities as an enabling company with relationships across China's cyber ecosystem and connections to former People's Liberation Army personnel.

QTFY activity reportedly continued into June 2026, when actors targeted a U.S. election system.

The disruption demonstrates how China-linked threat actors are increasingly relying on distributed infrastructure rather than fixed attacker-controlled servers. While domain seizures can interrupt an operation, the reuse of compromised IoT devices, commercial proxies and leased servers means defenders will need to monitor behavior and network relationships rather than rely solely on static IP-based blocking.

Google’s New Codename System Aims to Clarify Hacker Group Tracking

 

Cybersecurity companies have spent years giving hacking groups their own names so researchers and defenders can talk about them clearly. But the system has become crowded and inconsistent, because different organizations often label the same group in different ways.

Google recently changed its own naming approach to make that mess easier to navigate . Instead of long strings like APT numbers, its new method uses a memorable first name and a second word that signals a country of origin, such as Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The goal is to make the labels easier to remember while still preserving useful context. 

Shane Huntley, who leads Google Threat Intelligence Group’s hunting work, said the change was needed because the number of threat groups has grown far beyond what researchers expected in the early 2010s. Google now tracks more than 5,000 activity clusters across several countries, which makes organization and communication much harder. Huntley also said the purpose of naming groups is practical: defenders need a baseline understanding of who is attacking, how they operate, and what they have done before.

That kind of background can help a company respond faster during a breach . If security teams recognize a known actor’s patterns, they can prepare defenses, narrow investigations, and respond with more confidence . The Lazarus Group, a North Korean state-backed hacking outfit, is one example of how earlier intelligence helps defenders identify likely goals and methods. The challenge is that not all threat actors behave the same way.

State-sponsored groups are often easier to follow because their targets and tactics are more consistent, while cybercriminal gangs may split apart, change members, or shift direction. Spyware makers and hackers-for-hire can also be difficult to track because they may work for many clients in many regions . Huntley argues that no company has perfect visibility, which is why naming systems will likely remain imperfect even if Google’s new scheme is simpler than before.

Fake Apple Support Agents Target Stolen-Device Owners in Credential Scam


Using AI-powered voice calls and phishing messages, a new phishing-as-a-service platform targets owners of recently stolen Apple devices to obtain device passcodes, Apple ID credentials and two-factor authentication codes. 

In response to SOCRadar Threat Research Unit (STRU) research, security researchers have identified AnonyMousKIT as a credit-based service designed to assist criminals in defeating Apple's Activation Lock. By using this platform, attackers can communicate with their victims via email, SMS, WhatsApp, recorded calls, and artificial intelligence-generated voice agents posing as Apple Support representatives. 

AnonyMousKIT also makes the contact appear legitimate by utilizing information tied to the stolen device. By providing a serial number or IMEI to the platform, attackers can identify the device's model and determine whether it is currently in Find My. Victims can be directed to Apple-branded pages with an animated map showing the location of the device reported. 

People whose devices have recently been lost or stolen are more likely to actively check for their whereabouts as a result of these campaigns. By providing accurate device information and describing the circumstances surrounding the theft, attackers can increase the likelihood that the communication is a genuine notification regarding recovery or support. 

In most cases, the campaign seeks a device's passcode, followed by Apple ID credentials and an Apple 2FA code. Apple's support guidance states that legitimate representatives do not request passwords, device passcodes, or 2FA codes. With anonymousMousKIT, customers are permitted to choose from a variety of methods for contacting victims through a credit-based model. 

Email campaigns cost 1.50 credits, recorded voice calls cost 1 credit, and artificial intelligence voice agents cost 2 credits. A single set of stolen-device details can also be used for SMS and WhatsApp, allowing attackers to take multiple approaches to the same victim from a single set. Researchers identified the operation as more than just a conventional phishing kit, describing it as similar to a subscription-based criminal service, with credit packages, pricing tiers, customer support, and mechanisms for replacing compromised infrastructure. 

A stolen iPhone can have a number of consequences in addition to unlocking it. An attacker may be able to access the information stored in the account, including iCloud backups and other credentials, if he or she obtains the associated Apple ID credentials and 2FA code. Additionally, SOCRadar found coding errors within the platform that exposed links between multiple domains and backend installations, providing researchers with additional insights into the operation's infrastructure. 

With the AI voice component, SOCRadar was able to locate 200 call records and 55 transcripts related to the commercial voice platform Vapi which provide a closer look at the social engineering process. The callers appeared as “Alice” from Apple Support, and were able to use five voice personas across English, Spanish and Brazilian Portuguese.

Call recordings were collected between August 31, 2025, and May 30, 2026. 179 of 200 calls were directed to Brazilian telephone numbers. The fake support agent confirms ownership of the device before requesting the four- or six-digit passcode of the device in the reviewed conversations. After repeating the digits for confirmation, the agent claims to have been contacted by an Apple Store regarding an Activation Lock issue. 

The conversation then moves to the recovery link that was supposedly sent via text message. As determined by the recovered records, the voice operation was relatively inexpensive to run, with all 200 calls requiring approximately $19.24 per call. However, the available data does not indicate how many victims actually surrendered their passcodes, Apple ID credentials or 2FA codes. 

Among the recorded calls, 100 ended when the recipients hung up, 48 timed out due to silence, 24 did not receive an answer, and 28 ended because of platform errors or busy signals. The researchers also discovered that the call records had been retrieved due to an accessibility flaw in the platform's codebase. 

Two file paths exposed through the shared code enabled unauthenticated access to files stored in the web root, enabling the recovery of call logs and transcripts. Since the vulnerability was inherited by deployments based on the same codebase, it provides valuable insight into the broader infrastructure supporting AnonyMousKIT.

AnonyMousKIT demonstrates a structured criminal supply chain rather than a standalone phishing campaign, according to SOCRadar. Developers of the platform build and sell it, customers license the platform through storefronts, and operators use those services to conduct phishing campaigns. In addition to outsourcing the credential-harvesting process, criminals can concentrate on resale of stolen devices while criminals with limited technical expertise can perform the credential-harvesting process.

Activation Lock represents an important threat to criminals who steal devices. Once Find My is activated, an iPhone remains associated with its owner's Apple ID even after a factory reset, which creates a broader threat. 

By obtaining the account credentials and verification codes, attackers are able to defeat a security mechanism that otherwise makes activating and reselling stolen devices difficult. At the conclusion of SOCRadar's investigation, AnonyMousKIT was still active, emphasizing the increasing use of automated services to target stolen devices. According to the operation, criminals have been able to steal credentials from lost or stolen iPhones by combining stolen data, phishing and artificial intelligence. 

Apple accounts that have been compromised can expose data far beyond the device itself, posing a significant security risk to those who receive them.

US Police Officers Face Arrests and Firing for Misusing Flock Camera Data

 


Police officers across the United States are facing arrests, firings and investigations for allegedly misusing Flock Safety's automated license plate reader system to track people for personal reasons, including romantic partners, former partners and colleagues.

Flock operates more than 120,000 cameras across over 6,000 US communities, with the system recording around 20 billion license plate scans each month. The cameras are designed to help law enforcement locate stolen vehicles, identify vehicles connected to investigations and assist in finding missing people. However, their growing deployment has raised concerns about how much vehicle-movement data police can access and whether agencies are adequately monitoring that access.

A Washington Post analysis found that at least 50 law enforcement officers had been accused or charged with using license plate readers for unauthorized purposes. Flock systems were involved in 46 of those cases, while 26 involved officers allegedly using the technology to monitor women, including current or former romantic partners. The Institute for Justice has separately documented dozens of similar cases nationwide, with many occurring since 2024.

One of the most prominent cases involved former Braselton, Georgia, Police Chief Michael Steffman. According to The Washington Post, Steffman used Flock searches to monitor the movements of his former girlfriend and her daughter roughly 600 times. He was arrested on stalking, harassment and license-plate-reader misuse charges but died before his case went to trial.

Georgia has continued to see cases involving alleged misuse. Habersham County Deputy Christian Brewer was fired and arrested after an internal audit reportedly found that he had used Flock data to track someone with whom he had a personal relationship. A second Habersham County investigator, Jonathan Thomas, was arrested this week following another internal investigation into alleged misuse of the system.

The problem is not limited to Georgia. In Texas, former Lufkin police officer Zachary Anthony Klein was indicted on 100 felony counts after allegedly conducting more than 45,000 Flock searches over approximately 200 days. One license plate was reportedly searched nearly 3,500 times. The department subsequently suspended its use of Flock while investigations continued.

The Institute for Justice's database has continued adding cases in 2026, including allegations involving officers in Florida, Illinois, Georgia, Texas and other states. The database records incidents involving stalking, unauthorized searches and other non-law-enforcement uses of automated license plate reader data.

Flock says its platform records every search and provides audit tools intended to identify unusual activity. The company has also introduced additional safeguards, including mandatory case codes, stronger audit mechanisms and a recommended reduction in data retention from 30 days to seven days.

Critics argue that logging searches is only useful if police departments actually review those records and investigate suspicious activity. In several documented cases, alleged misuse was discovered only after victims or outside investigators identified unusual searches.

The issue has now expanded beyond individual officers. At least 69 alleged misuse incidents have been identified nationwide, while communities are increasingly questioning whether extensive vehicle surveillance can be deployed without stronger controls over retention, access and data sharing.

Residents have also begun investigating the system themselves. Have I Been Flocked allows users to check whether their license plate appears in publicly obtained Flock search records. The service has reportedly compiled more than 242 million recorded searches from audit logs obtained through public-records requests.

As Flock's network continues expanding, the controversy is shifting from whether automated license plate readers can help police solve crimes to a more difficult question: who watches the people given access to the surveillance system?

39 Child Tracking Brands Linked to One Chinese Server, Exposing 45 Security Vulnerabilities

 

GPS trackers for children may put the tracked individuals and the people tracking them in danger, according to an investigation presented at the Black Hat security conference. Vangelis Stykas, CTO of Kumio, and Felipe Solferini, principal AI security engineer, discovered that 39 different consumer brands of parental monitoring devices share the same server in China where the data stored on them are processed. 

The researchers named the producers of the technologies, which the mentioned companies used in their devices, SeTracker, SinoTrack and TKStar. They found 45 different vulnerabilities that could allow unauthorized access to children’s smart devices enabling eavesdropping, video surveillance, and total remote control of the system where valuable information is stored. The researchers stated that to perform all these actions, a hacker would need only a free account on any of these platforms. 

The scientists also found that parental monitoring devices of different brands did not have the necessary authorization restrictions, which allowed accessing their systems freely. These devices could collect and store much more personal information than monitoring their location. Some of them have the functionality to record the screen, as well as control the camera and microphone. Thus, the location of the tracked device, photographs and video, the child’s screen, the applications and websites he visits, and his personal information can be known to unauthorized people. 

At the beginning of the demonstration, the researchers showed how they managed to run a script on a children’s smartwatch, which, among other things, dialed a phone number and transmitted an audio signal without any notification on the displayed screen that the call had begun. The scientists emphasized that the experiment was carried out ethically, and they used devices provided to them for the investigation. Stykas and Solferini also discovered that attacks on the system could have been made two years before the investigation began. 

This indicates that, in principle, someone could have been able to track the child’s location and personal data without his knowledge. The researchers contacted the companies more than 30 times, but received no response. One unknown dealer, however, responded to the scientists, noting that he was helping them investigate and would forward the information to the manufacturer. Researchers have concluded that parental monitoring devices pose a serious danger to privacy and safety by possessing many vulnerabilities. 

The investigation demonstrated that the same server is used for different brands, and the lack of protection allows hackers to gain full control of the system and track all the child’s activities. The report also suggests giving up these devices, and for those parents who want to control their children’s devices, the scientists recommended using the built-in tools of the giants: Apple Screen Time, Google Family Link, and Microsoft Family Safety.

LightSpy Spyware Expands Global Reach, Targeting Devices Across More Than a Dozen Countries

 

Cybersecurity researchers have uncovered new evidence suggesting that the Chinese-linked LightSpy spyware operation has expanded significantly, with infections and infrastructure now spanning more than a dozen countries, including the United States and several European nations.

A report from cybersecurity firm Arctic Wolf describes LightSpy as an increasingly sophisticated commercial surveillance platform whose capabilities appear to be offered to governments, military organisations and private companies. First identified in 2018 and previously linked to Chinese state-backed hacking activity, the spyware is now believed to be controlled by a single threat actor that provides the platform to multiple customers.

The researchers identified at least 117 servers associated with LightSpy across multiple countries. The infrastructure indicates that the operation has developed a much wider global footprint than earlier investigations had revealed.

LightSpy has also evolved beyond targeting individual operating systems. Its modular architecture reportedly allows it to compromise smartphones, Apple devices, Windows computers and Linux servers, while newer versions have introduced the ability to target internet routers.

The router capability represents a particularly concerning development because compromising network equipment could allow attackers to observe or potentially access several devices connected to the same network. Arctic Wolf said some of the compromised routers are associated with NATO member countries, although it did not disclose the specific organisations involved.

The latest versions of LightSpy reportedly offer extensive surveillance capabilities. Once installed, the spyware can collect sensitive information such as precise location data, chat conversations, stored passwords and screen recordings. It can also remotely delete files and potentially make compromised devices unusable, giving operators capabilities that extend beyond surveillance to data destruction.

According to Arctic Wolf, LightSpy's development reflects a wider commercialisation of advanced spyware. Capabilities once primarily associated with intelligence agencies and state-sponsored cyber operations are increasingly being packaged and sold to a broader customer base.

The researchers said LightSpy appears to be marketed as a commercial product, featuring customised branding, demonstrations and billing mechanisms designed for prospective customers. This suggests the operation may function as a structured surveillance business rather than being limited to a single espionage campaign.

Researchers also uncovered a potential link to a Chinese contractor through an operational mistake. According to Arctic Wolf, one of the spyware operators accessed the malware's administration panel and used their real name and office address while ordering Kentucky Fried Chicken. Investigators believe the incident provided an unusual clue that helped connect the infrastructure to its operators.

Despite the findings, several questions surrounding LightSpy remain unanswered. Arctic Wolf said the identities of the platform's customers, the total number of victims and the precise relationship between its operators and the Chinese government have not been publicly established.

The findings nevertheless underscore the growing sophistication and international reach of commercial spyware. As surveillance technologies become increasingly commercialised, advanced cyber capabilities are becoming accessible to a broader range of customers, extending the potential threat well beyond traditional state intelligence operations.

Featured