International authorities from the EU, UK, and US have intensified their crackdown on Russian cybercriminal infrastructure, issuing sanctions against GRU and FSB-linked entities and dismantling the "First VPN Service." These actions target the backbone of ransomware operations, including the indictment of operators behind "Media Land" and "ML Cloud," bulletproof hosting services that facilitated over $62 million in global damages by ignoring legal takedown requests.
Simultaneously, researchers have uncovered sophisticated malware campaigns targeting end-users and developers. The threat actor UAT-11795 is distributing the Starland RAT via trojanized installers of popular platforms like Zoom and WebEx, while a massive GitHub campaign involving nearly 300 imposter repositories is spreading BoryptGrab infostealers. These campaigns utilize advanced techniques such as DLL side-loading and Polygon smart contract-based C2 redundancy to exfiltrate sensitive credentials and cryptocurrency assets.
Top comments (0)