daily cyber × ai intelligence

index

tagged

[extortion]

5 editions · 6 items

September 11, 2026

  • Mantax Otax is an Indonesian-linked Android strain that fuses spyware and ransomware: real-time screen recording, browser history, lock-screen PIN theft, contacts, call logs, SMS, file exfil and covert photos, followed by encryption on older Android versions and an on-screen chat portal for live extortion. Sideloaded as an APK from a file-sharing host, it resolves its live C2 domain from a GitHub repo and brokers traffic through Firebase (Zimperium, BleepingComputer). Separately, GoldFactory is abusing Android Work Profile to deliver Gigabud in the same country (Dark Reading). · Threat Intelligence

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign

September 6, 2026

  • Panzer claimed 19 victims in its first month of operation. A profile dates the RaaS launch to early August and describes a comparatively mature double-extortion infrastructure spanning more than ten countries, including government-linked organizations. The victim count remains based on operator claims. CyberXTron · Threat Activity
  • Berlin says Rhysida followed through on its leak threat and published roughly 5.8 TB of stolen government data. Authorities launched a crisis response and forensic review after refusing to pay the group. Reuters reports the material escalation from the original extortion claim (earlier coverage). · Incidents & Extortion

in One Loophole, 100 Agents, 27 Minutes

August 30, 2026

  • Rhysida is auctioning 5.79 TB it claims to have stolen from Berlin's state agencies, and the State of Berlin has confirmed an active extortion attempt it will not meet (The Hacker News, SecurityAffairs). Forensics has since uncovered additional exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment; Governing Mayor Kai Wegner and Interior Senator Iris Spranger say "the State of Berlin will not be blackmailed" (Senate statement). Timing lands just before city elections. · Threat Activity
  • Xploitrs is holding companies worldwide to ransom using credentials harvested from the Trivvy and LiteLLM breaches, according to Kevin Beaumont, who says a longer write-up is coming. The same group has published a statement on the TeamPCP arrests in Australia (earlier coverage) — a reminder that AI-tooling breaches are feeding ordinary credential-driven extortion. · Threat Activity

in CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited

July 7, 2026

A 16-Year-Old KVM Flaw Punches Through the Hypervisor Boundary

A 16-year-old KVM hypervisor vulnerability (CVE-2026-53359) enabling guest-to-host escape is under public exploitation, with panic PoCs already available. Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is being actively exploited in the wild within hours of disclosure, with unauthenticated remote code execution possible. AI-powered coding agents are now a live attack surface, with researchers demonstrating agent hijacking, malicious skill injection, and data exfiltration through prompt injection in creator tools like YouTube's Ask Studio. Iran-linked hackers are deploying a new modular C2 framework called Cavern against Israeli targets, while ClickFix malware operators are leveraging blockchain as a resilient command infrastructure.

June 17, 2026

  • ShinyHunters added American Tower, JCPenney, Madison Square Garden Sports, Ralph Lauren, and Nexstar to its leak site (claims unverified), and separately claims a PeopleSoft zero-day heist of ~297GB from the Council of Europe. Kodak and Infinite Campus (137K school staff via Salesforce) also confirmed/were named in ShinyHunters incidents. Daily Dark Web, SecurityWeek, BleepingComputer. · Data Breaches & Extortion

in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists