<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Malware on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/malware/</link><description>Recent content in Malware on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 12:22:25 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/malware/index.xml" rel="self" type="application/rss+xml"/><item><title>TA4922 China Phishing Threat Hits UK &amp; Europe</title><link>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-south-africa-valleyrat-atlas-rat/</link><pubDate>Thu, 04 Jun 2026 12:22:25 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-south-africa-valleyrat-atlas-rat/</guid><description>China-linked TA4922 expands phishing attacks to the UK, Germany, Italy and South Africa using ValleyRAT and Atlas RAT malware families.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">The Hacker News</a></p>
<hr>
<p>A China-linked threat actor, TA4922, has expanded its phishing campaigns beyond its previous targets to now include organisations in the UK, Germany, Italy, and South Africa. The group is deploying known malware families including ValleyRAT and Atlas RAT, with a rapidly evolving toolkit suggesting well-resourced, sustained operations. This represents a significant escalation in geographic scope and poses a direct threat to European enterprises.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review and tighten email gateway controls to block phishing lures associated with TA4922, and ensure endpoint detection rules cover ValleyRAT (Winos 4.0) and Atlas RAT indicators. Consider hunting for lateral movement or C2 beaconing patterns consistent with these RAT families across cloud-hosted workloads and on-premises infrastructure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa</a></p>
]]></content:encoded></item><item><title>TA4922 Phishing Targets UK, Germany &amp; Italy</title><link>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-valleyrat-atlas-rat/</link><pubDate>Thu, 04 Jun 2026 12:22:25 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-valleyrat-atlas-rat/</guid><description>China-linked TA4922 expands phishing attacks to UK, Germany, Italy and South Africa, deploying ValleyRAT and Atlas RAT. What cloud security teams need to k</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">The Hacker News</a></p>
<hr>
<p>A China-linked threat group, TA4922, has significantly expanded its phishing campaigns beyond its previous targets to now include organisations in the UK, Germany, Italy, and South Africa. The group is deploying known remote access trojans including ValleyRAT and Atlas RAT, with a fast-moving operational pace and an evolving malware toolkit. This matters because the expansion into European markets signals a deliberate strategic shift, increasing risk for organisations in these regions.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review email gateway and endpoint detection rules for ValleyRAT (Winos 4.0) and Atlas RAT indicators of compromise, and ensure phishing-resistant MFA is enforced across all cloud console and SaaS access points. Consider threat intelligence feeds covering Chinese APT activity to stay ahead of this group&rsquo;s rapidly evolving malware arsenal.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa</a></p>
]]></content:encoded></item><item><title>FlutterShell macOS Backdoor via Malicious Google Ads</title><link>https://zxcloudsecurity.co.uk/posts/fluttershell-backdoor-macos-malvertising-operation-flutterbridge/</link><pubDate>Thu, 04 Jun 2026 11:19:53 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fluttershell-backdoor-macos-malvertising-operation-flutterbridge/</guid><description>Operation FlutterBridge spreads the FlutterShell macOS backdoor via malicious Google and YouTube ads. Learn the risks and mitigations for cloud teams.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html">The Hacker News</a></p>
<hr>
<p>A macOS malvertising campaign called Operation FlutterBridge is distributing a new backdoor, FlutterShell, through malicious Google and YouTube advertisements. The campaign is an evolution of a previously identified threat cluster (JSCoreRunner/FileRipple) first observed in late 2025. This matters because it uses trusted ad platforms to target macOS users, broadening the attack surface beyond traditional phishing vectors.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Enforce endpoint detection and response (EDR) tooling on all macOS devices, including developer and privileged-access workstations, and consider restricting or monitoring ad-network traffic at the corporate proxy or DNS layer. Review browser isolation and application allowlisting policies to limit the execution of unsigned or unnotarised binaries delivered via browser-based download prompts.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html">FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads</a></p>
]]></content:encoded></item><item><title>Fake Open-Source Sites Deliver Malware via Google SEO</title><link>https://zxcloudsecurity.co.uk/posts/fake-open-source-sites-google-seo-malware-tds-remus-stealer/</link><pubDate>Thu, 04 Jun 2026 09:51:28 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fake-open-source-sites-google-seo-malware-tds-remus-stealer/</guid><description>Attackers are using SEO-optimised fake sites mimicking open-source tools to push malware via a Traffic Distribution System. Here&amp;#39;s what cloud teams should</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html">The Hacker News</a></p>
<hr>
<p>Attackers have built convincing fake websites impersonating popular open-source and freeware tools, engineering them to rank highly in Google search results. Visitors are silently routed through a Traffic Distribution System (TDS) that profiles them before delivering tailored malware, including credential stealers and session hijacking frameworks. The campaign is notable for its scale and the quality of the spoofed sites, making it easy for developers and engineers to be deceived.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Enforce approved software procurement channels and block unapproved download sources at the network or endpoint level. Mandate that developers and engineers source open-source tooling exclusively from verified repositories such as official GitHub pages or package managers, and consider deploying DNS filtering to flag newly registered or lookalike domains.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html">Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS</a></p>
]]></content:encoded></item><item><title>Fake Open-Source Sites Deliver Malware via TDS</title><link>https://zxcloudsecurity.co.uk/posts/fake-open-source-sites-tds-malware-remus-stealer-sessiongate/</link><pubDate>Thu, 04 Jun 2026 09:51:28 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fake-open-source-sites-tds-malware-remus-stealer-sessiongate/</guid><description>Attackers clone open-source project sites, rank them on Google, and use a Traffic Distribution System to deliver stealers and session hijacking malware to</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html">The Hacker News</a></p>
<hr>
<p>Attackers have created convincing fake websites impersonating popular open-source tools, optimising them to rank highly on Google search results. Visitors are silently routed through a Traffic Distribution System (TDS) that delivers malware including credential stealers and session hijacking frameworks. This is a supply chain-adjacent threat targeting developers and technical users who search for and download software directly from the web.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Enforce organisational policies requiring software to be sourced only from verified package managers (npm, PyPI, etc.) or official repositories, and block direct binary downloads from unvetted sites via web proxy or CASB controls. Consider adding developer workstations to your threat model and ensure EDR coverage extends to engineering endpoints.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html">Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS</a></p>
]]></content:encoded></item><item><title>Ransomware Operator Breaks CIS Rule: What It Means</title><link>https://zxcloudsecurity.co.uk/posts/ransomware-operator-breaks-cis-rule-criminal-infects-russia/</link><pubDate>Tue, 02 Jun 2026 21:58:34 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/ransomware-operator-breaks-cis-rule-criminal-infects-russia/</guid><description>A ransomware criminal ignored the unwritten rule protecting CIS nations from attack. Here&amp;#39;s what this shift means for cloud security teams.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/02/dumbass-criminal-breaks-the-first-rule-of-ransomware-club/5250380">The Register — Security</a></p>
<hr>
<p>A ransomware operator has broken the unwritten but widely observed rule among Russian-speaking cybercriminal groups by attacking targets within Russia or CIS countries, drawing attention to themselves and likely facing consequences from both law enforcement and criminal peers. This norm has historically served as an informal shield, with many ransomware variants including code to abort execution if a CIS locale is detected. The incident highlights the internal politics and geographic conventions that shape how ransomware gangs operate.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Use this as a reminder to review whether your ransomware detection and response playbooks account for threat actors who may no longer respect traditional geographic boundaries — do not assume CIS-origin malware will avoid your organisation based on locale checks alone.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/02/dumbass-criminal-breaks-the-first-rule-of-ransomware-club/5250380">&lsquo;Dumbass&rsquo; criminal breaks the &lsquo;first rule of ransomware club&rsquo;</a></p>
]]></content:encoded></item><item><title>Gamaredon Exploits WinRAR CVE-2025-8088 Malware</title><link>https://zxcloudsecurity.co.uk/posts/gamaredon-winrar-cve-2025-8088-gammaworm-gammasteel-ukraine/</link><pubDate>Tue, 02 Jun 2026 18:21:49 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/gamaredon-winrar-cve-2025-8088-gammaworm-gammasteel-ukraine/</guid><description>Russian APT Gamaredon exploits WinRAR path traversal flaw CVE-2025-8088 to deploy GammaWorm and GammaSteel malware against Ukrainian targets.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html">The Hacker News</a></p>
<hr>
<p>Russian state-linked threat group Gamaredon is actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to deploy a chain of malware against Ukrainian targets. The attack begins with an HTML Application payload (GammaPhish) which then downloads further malware including GammaWorm and GammaSteel, designed for data theft and lateral propagation. This is a targeted, state-sponsored campaign with significant implications for organisations operating in or with Ukraine.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Ensure WinRAR is patched to a version addressing CVE-2025-8088 across all endpoints, and consider blocking HTA file execution via AppLocker or Windows Defender Application Control policies. Cloud-connected environments should review egress controls and data exfiltration detection rules, particularly for workloads with access to sensitive data stores.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html">Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine</a></p>
]]></content:encoded></item></channel></rss>