daily cyber × ai intelligence

index

tagged

[spyware]

3 editions · 3 items

September 16, 2026

  • Iranian state actors used fake MRI results to deliver CHOSEN BRICK against dissidents, activists and journalists. A joint UK, US and Dutch warning describes extended rapport-building over WhatsApp and Telegram before delivery of tailored Windows files. The spyware persists at login and collects contacts, email and social messages, screen content and microphone audio—enabling pattern-of-life analysis that can increase victims’ physical risk (UK NCSC; The Record). · Threat Activity & Malware

in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways

September 11, 2026

  • Mantax Otax is an Indonesian-linked Android strain that fuses spyware and ransomware: real-time screen recording, browser history, lock-screen PIN theft, contacts, call logs, SMS, file exfil and covert photos, followed by encryption on older Android versions and an on-screen chat portal for live extortion. Sideloaded as an APK from a file-sharing host, it resolves its live C2 domain from a GitHub repo and brokers traffic through Firebase (Zimperium, BleepingComputer). Separately, GoldFactory is abusing Android Work Profile to deliver Gigabud in the same country (Dark Reading). · Threat Intelligence

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign