Topic
Malware & Threat Actors
New malware families, backdoors, and advanced threat groups tracked by intelligence teams.
41 articles in this topic
MuddyWater's False-Flag Playbook: Iranian APT Hides Espionage Behind Chaos Ransomware
Iranian APT MuddyWater deployed Chaos ransomware as a decoy while conducting espionage via Microsoft Teams social engineering. Saudi CISOs must rethink their IR playbooks.
Malware & Threat ActorsMuddyWater's Chaos Ransomware Deception: Iranian Espionage Targeting Banks Under False Flag
Iranian APT MuddyWater deploys Chaos ransomware branding to disguise espionage operations targeting banks and defense contractors. Rapid7 research reveals no encryption — only data theft and credential harvesting behind a ransomware smokescreen.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal Credentials Without User Interaction
An incomplete Microsoft patch left a zero-click credential theft vector wide open — and APT28 is already exploiting it. Here's what Saudi financial institutions need to do right now.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware
Rapid7 unmasks MuddyWater's Chaos ransomware campaign as Iranian state espionage. Critical lessons for Saudi financial sector CISOs on detecting false-flag operations.
Malware & Threat ActorsMuddyWater's False Flag: Iranian APT Hides Espionage Behind Chaos Ransomware via Microsoft Teams
Iranian state-sponsored group MuddyWater weaponized Microsoft Teams screen-sharing to steal credentials and bypass MFA, planting Chaos ransomware artifacts as a decoy to hide espionage targeting banks and critical infrastructure.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Shell Flaw to Steal NTLM Credentials
Russian APT28 weaponizes an incomplete Windows Shell patch to silently harvest NTLM hashes — no clicks required. Here's what Saudi CISOs must do now.
VulnerabilitiesCVE-2026-32202: APT28 Exploits Zero-Click Windows Flaw to Steal NTLM Credentials — CISA Deadline Hits Today
A zero-click Windows shortcut flaw lets APT28 steal NTLM credentials without user interaction. Microsoft's incomplete patch left millions exposed — and CISA's remediation deadline expires today.
Malware & Threat ActorsTCLBANKER Trojan Spreads via WhatsApp to Target 59 Financial Platforms
A new banking trojan called TCLBANKER hijacks WhatsApp and Outlook to spread across 3,000 contacts per victim, targeting 59 financial platforms with full-screen credential overlays.
Malware & Threat ActorsJDownloader Python RAT Supply Chain Attack: SAMA Bank Risk
Attackers compromised the official JDownloader website between May 6 and May 7, 2026, swapping legitimate Windows and Linux installers with a modular Python RAT. Here is what SAMA-regulated banks must do now.
RansomwareAnubis Ransomware Adds Wiper: Critical Risk to SAMA Banks
Anubis ransomware-as-a-service now includes a destructive wiper alongside double extortion, breaking the traditional ransomware bargain. Saudi banks must adapt SAMA CSCC defenses immediately.
Cloud & IdentityMuddyWater Targets Microsoft Teams MFA: SAMA Bank Defense Guide
Iranian state-sponsored MuddyWater is exploiting Microsoft Teams social engineering to harvest credentials and manipulate MFA at financial institutions, then planting Chaos ransomware as a false flag. Here is what SAMA-regulated banks must do.
Malware & Threat ActorsGopherWhisper APT: Slack & Microsoft 365 C2 Risk to SAMA Banks
ESET unveils GopherWhisper — a China-aligned APT using Discord, Slack and Microsoft 365 Outlook as covert C2. SAMA-regulated banks face the same legitimate-service abuse risk and must rethink detection.
From reading to doing
Is your organisation ready for an incident like this?
Fyntralink’s incident response team helps you contain an attack, investigate it and recover from it.
Incident Response
Professional and rapid response to security incidents — threat containment, digital forensics, and full recovery
SOC as-a-Service
24/7 managed Security Operations Center that detects and responds to threats before they become crises
Security Risk Assessment
Comprehensive cybersecurity risk assessment and professional risk register aligned with your strategic decisions