Connect with us

Infosecurity

China-Linked Hackers Weaponize New Flaws in Under a Day, CrowdStrike Warns

Published

on

China-linked hackers exploit

The 24-Hour Window Just Got Smaller

It used to be that defenders had a few days, maybe a week, to patch a newly disclosed vulnerability before attackers caught on. Those days are gone. CrowdStrike has documented China-linked threat actors weaponizing a critical flaw in less than 24 hours from public disclosure.

The groups in question — Vault Panda and Genesis Panda — moved with alarming speed against the React2Shell vulnerability. That’s the critical web application bug allowing unauthenticated remote code execution in React Server Components and Next.js applications. It was disclosed in December 2025, with patches released at the same time.

This isn’t a theoretical concern. These are active campaigns.

Who Are Vault Panda and Genesis Panda?

Both are China-nexus groups tracked by CrowdStrike. Vault Panda (UNC6588) and Genesis Panda (REF0657, Earth Lamia) were observed deploying remote access trojans (RATs) and harvesting credentials shortly after the React2Shell disclosure.

They didn’t just scan for the flaw. They came prepared with tooling, ready to deploy at a moment’s notice. CrowdStrike researchers described the behavior in the CrowdStrike 2026 Threat Hunting Report, published August 3.

The report states: “The speed of this response highlights their posture as adversaries who actively monitor vulnerability disclosures, rapidly validate exploitability, and pre-stage tooling in anticipation of a constantly changing attack surface.”

AI Is Compressing Patch Windows Further

React2Shell isn’t an isolated case. CrowdStrike found that in 88% of publicly disclosed vulnerability exploits during H1 2026, the intrusion occurred within 48 hours of release. That’s a staggering figure.

Zero-day exploitation also jumped 42% year-over-year from 2024 to 2025. And here’s the worrying part: these trends predate the integration of frontier AI into vulnerability research.

AI tools like Anthropic‘s Mythos and OpenAI‘s GPT-5.4-Cyber and GPT-5.5-Cyber are designed to find and fix vulnerabilities at scale. But they’re also giving attackers a head start.

CrowdStrike researchers warn: “Frontier models are likely contributing to the rising volume of disclosed vulnerabilities, exacerbating the challenges faced by network defenders as they attempt to cope with ever-shrinking patch windows.”

Translation: expect the timeline between disclosure and exploitation to compress even further in the coming months.

Identity Attacks: The New Frontline

The report also shines a light on identity-based attacks, which are rising dramatically. A big driver? AI.

LLMJacking: When Attackers Hijack Your AI

One notable trend is LLMJacking. Financially motivated adversaries compromise a victim’s corporate LLM API access, then run up massive bills or sabotage the AI services beyond normal capacity. The goal is financial harm.

In one campaign, a threat actor sent nearly 200,000 API requests in just two minutes after gaining elevated access to a cloud computing service offering foundation models. Two minutes. That’s not a typo.

Vishing Doubles as Initial Access Vector

CrowdStrike also detected a doubling in intrusions using vishing as the initial access vector in H1 2026 compared to H1 2025. Vishing — voice phishing — involves impersonating individuals over phone calls to bypass authentication.

AI has supercharged this technique. Deepfakes make it easier to sound like a CEO or IT admin. And because vishing leaves few digital markers, it’s hard for defenders to detect.

The report notes vishing has become a key technique for e-crime actors precisely because detection is so difficult.

What This Means for Defenders

The takeaway is sobering. Patch windows are shrinking. Attackers are using AI to move faster, and identity-based attacks are becoming harder to spot.

For security teams, this means a few things:

  • Prioritize patching based on exploitability, not just severity scores.
  • Assume your AI services will be targeted — monitor API usage for anomalies.
  • Train employees to question phone calls, even from familiar voices.
  • Invest in detection tools that can spot post-exploit activity quickly.

The gap between disclosure and exploitation is closing. The question is whether defenders can keep up.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

North Korea’s Lazarus Group appears to be sharing cyberweapons with ransomware gangs, Seoul warns

Published

on

Lazarus Group sharing tools

State hackers and cybercriminals may be working from the same playbook

For years, the line between state-sponsored espionage and common cybercrime has been blurring. Now, South Korean authorities say they have evidence that North Korea’s infamous Lazarus Group may be handing its tools directly to ransomware gangs.

A joint advisory from four South Korean security and intelligence agencies, released Thursday alongside a technical report from cybersecurity firm AhnLab, warns of a troubling overlap between Lazarus and a ransomware operation called Gunra. Both have been running parallel campaigns against South Korean targets since 2025. The only real difference? Their endgame.

Lazarus plants espionage backdoors. Gunra locks up files and demands payment.

Same flaws, same fingerprints, same servers

The report, which AhnLab dubbed “Operation Double Barrel,” details striking similarities between the two operations. Both groups exploited the same vulnerabilities in Korean financial security software — programs that are effectively mandatory for anyone using banking or government services in the country.

According to AhnLab, the two campaigns used:

  • Identical malware filenames and execution arguments
  • The same privilege escalation tools
  • Shared command-and-control servers
  • The same SSH key fingerprint — a cryptographic identifier akin to a unique digital signature

Both even deleted their malware the same way, renaming files to random four-character strings before wiping them clean.

That’s a lot of coincidences. AhnLab stopped short of definitively blaming both on the same actor, but classified the cases as having “a high likelihood of technical linkage.” The overlaps could indicate collaboration, shared infrastructure, or access brokering, the firm said.

Watering holes and weaponized websites

The scale of the operation is sobering. In 2026 alone, Lazarus hackers installed espionage backdoors in at least 72 organizations — including government agencies, cryptocurrency exchanges, and IT service providers. Gunra, meanwhile, used similar access to encrypt data and extort victims.

Part of the campaign involved compromising 15 legitimate Korean websites across multiple industries. The attackers turned these into watering holes, redirecting select visitors to infrastructure that triggered the software flaws and injected malicious code into legitimate Microsoft processes.

The advisory warns that users may be infected simply by visiting a legitimate website that has been compromised — especially if they’re running outdated security software.

The attackers also ran spearphishing campaigns. One targeted a Korean defense company with emails disguised as a survey about GaN semiconductors. AhnLab noted that some of the lure pages appeared to be generated with AI.

The hosting provider connection

Notably, multiple websites used for the watering-hole attacks were managed by the same Korean website development company. AhnLab assessed that the attackers likely compromised the hosting provider first, then expanded access to client sites through the development company’s management system — rather than hacking each site individually.

That’s a supply-chain approach, and it worked.

A growing entanglement with ransomware

The findings add to a growing body of evidence that Pyongyang-backed hackers are deepening their ties to the ransomware ecosystem. In the past 18 months, different North Korean state-sponsored actors have been linked to the Play, Qilin, and Medusa ransomware operations by researchers at Palo Alto Networks, Microsoft, and Symantec respectively.

That trend came into focus back in 2024, when the U.S. Department of Justice unsealed an indictment against Rim Jong Hyok, an alleged member of the government’s Andariel Unit, for his role in ransomware attacks on U.S. hospitals and healthcare companies.

But the Gunra connection may represent something different. In those earlier cases, North Korean operators joined established criminal franchises as affiliates. Here, the evidence suggests the relationship may run the other direction — with state hackers supplying tools, exploits, and access to a smaller, newer group.

Gunra emerged in April 2025, initially targeting five South Korean companies. The group built its ransomware on leaked Conti v2 source code before transitioning to a ransomware-as-a-service model in January of this year. Prior to the AhnLab report, industry researchers had tentatively linked Gunra to Eastern European operators based on its Conti heritage.

As of March 2026, Gunra had claimed at least 32 victims globally across healthcare, manufacturing, IT, and other sectors. Like many RaaS schemes, it operates a double-extortion model — stealing data before encrypting systems and threatening to publish it on a Tor-based leak site.

Who’s at risk?

AhnLab warned that the danger extends beyond the organizations specifically targeted.

“The Korean financial security software currently being abused… is used not only in various enterprise environments but also on many personal PCs,” the company said. “Because the vulnerabilities can be triggered simply when a user accesses a specific page, not only explicitly targeted organizations but also general user environments running vulnerable software may be exposed to risk.”

The advisory urges both individuals and organizations to update their security software and exercise caution when browsing. The threat isn’t abstract — it’s sitting on legitimate websites, waiting.

For more on how state-backed hackers operate, see our breakdown of North Korean cyber espionage tactics and ransomware-as-a-service trends.

Continue Reading

Infosecurity

Midnight Blizzard Turns Hotel Wi-Fi Into a Trap for Travelers

Published

on

captive portal attack

When the Hotel Wi-Fi Login Page Bites Back

You’ve just landed, you’re exhausted, and the hotel lobby Wi-Fi asks you to tick a box and hit “connect.” That innocent little page could be the last thing your laptop ever does without your permission.

Microsoft Threat Intelligence has uncovered a campaign it calls CaptiveCrunch, active since early May, that hijacks captive portals on hotel and conference Wi-Fi networks. The goal? Route guests through attacker infrastructure and serve fake browser or OS updates that install Russian espionage malware.

The group behind it is Storm-2945, a sub-cluster of Microsoft ’s old friend Midnight Blizzard — also known as APT29, the Dukes, or Cozy Bear. Both the US and UK governments have pinned that crew on Russia’s Foreign Intelligence Service, the SVR.

How the Captive Portal Attack Works

This is not your typical phishing lure. The attackers don’t wait for you to click a link in an email. Instead, they intercept the automated connectivity checks that browsers and operating systems fire off the moment you join a new network.

Those checks normally hit a known endpoint and get a “200 OK.” Here, they get a page that looks like a legitimate update prompt. The landing pages use ClickFix techniques — fake verification failures that instruct you to paste a command into your terminal or Run dialog. Some even serve an APK, suggesting Android devices are in the crosshairs too.

From July 16 onward, some pages started redirecting users into device code authentication flows. You’re told to enter an attacker-supplied code on a real Microsoft sign-in page. The code is genuine. The session behind it is not.

Microsoft notes the device code trick isn’t new, but wrapping it in a captive portal makes it feel legitimate. When you’re already in a weird network environment, one more code prompt hardly registers.

Who’s Being Targeted?

Security firm ReliaQuest spotted part of this activity on July 23 and traced it to hotels, conference centers, and other shared venues. The victims are corporate travelers — people whose accounts are worth more than their luggage.

Three Malware Tools, One Cover Story

Once you’re hooked, the attackers drop a trio of tools, each with a specific job.

  • CornFlake — a Go-based remote access trojan (RAT) that shows a fake progress window while it installs, then registers as a Windows service named “Cloud Sync Service.” It comes with keylogging, screenshots, microphone and webcam access, browser credential theft, a remote shell, and a watchdog that restores any persistence mechanism defenders remove.
  • ChocoShell — a PowerShell infostealer that runs entirely in memory. It disables the Antimalware Scan Interface (AMSI) before harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and Wi-Fi credentials.
  • FruitStone — the command-and-control panel, dressed up as a fake enterprise cloud product to match the implant’s cover story.

ChocoShell’s developer comments are a tell. They name specific Microsoft detection signatures and explain each evasion choice. Microsoft says that level of annotation suggests AI-assisted code generation — and the company thanked Anthropic and OpenAI for their support during the investigation.

What This Means for Travelers

The takeaway is blunt: treat hotel, conference, and airport Wi-Fi as hostile territory. Use cellular or eSIM connectivity whenever possible. And never — ever — install software offered through a captive portal.

For enterprises, Microsoft recommends blocking device code flow where it’s not strictly needed and pushing passkeys over passwords. That’s sound advice, but it doesn’t stop the human reflex to click “update now” when the Wi-Fi gods demand it.

The bigger question is how the portals got compromised in the first place. Microsoft is still investigating but notes commonalities in equipment and management systems across affected networks. That hints at a shared service within the captive portal ecosystem being breached, rather than each hotel being individually hacked. One bad vendor, many poisoned lobbies.

If you’re heading to a conference this fall, pack an eSIM and a healthy dose of skepticism. Your hotel’s free Wi-Fi just got a lot less free.

Continue Reading

Infosecurity

Angola’s biggest telecom Unitel hit by cyberattack hours before landmark IPO

Published

on

Unitel cyberattack

What happened to Unitel?

Angola’s largest telecom operator, Unitel, was hit by a cyberattack in the early hours of Tuesday morning. The incident knocked out voice services, mobile data, and internet access for millions of customers across the country.

The company detected the breach shortly after 2 a.m. local time. In a statement, Unitel said response and containment mechanisms were immediately activated, and technical and cybersecurity teams were mobilized. Yet services remained disrupted as of Wednesday, with no clear timeline for full restoration.

What makes this attack particularly striking is the timing. It struck less than 24 hours before Unitel was due to make its stock market debut on Angola’s exchange, BODIVA.

Network data reveals the likely cause

Network measurement data from RIPE NCC, reviewed by Recorded Future News, shows that Unitel’s IP prefixes remained announced to the global internet throughout the incident. That means the routers connecting the company to the rest of the internet stayed online.

Those prefixes would normally disappear if the disruption came from an external source, such as an upstream connectivity cut or a volumetric DDoS attack. Their persistence suggests the cause was instead an incident that disabled core internal systems.

Traffic telemetry from Cloudflare Radar shows Unitel’s traffic collapsing sharply from around the time of detection and remaining well below baseline into Wednesday. The disruption appears specific to Unitel — no other Angolan network operator showed any degradation over the same period.

Impact on businesses and payments

The outage also disrupted point-of-sale payment terminals running on Unitel’s network, according to Angolan business publication Expansão. That means businesses across the country struggled to process card payments, and digital services dependent on internet access were hobbled.

The IPO went ahead anyway

Despite the ongoing outage, Unitel began trading Wednesday on the Angolan securities exchange, known as BODIVA. It became the largest initial public offering in Angola’s capital market history.

The Angolan state, through its asset management institute IGAPE, sold a 15% stake in the company. The offer, which ran from July 6 to July 24, was oversubscribed at a rate of 120.72%, with more than 11,000 investors participating.

Trading proceeded Wednesday, valuing the company at $2.14 billion and raising around $321 million for the government. Neither BODIVA nor Angola’s capital markets regulator had issued any public statement about the cyberattack as of the time of publication.

A test for Angola’s privatization push

The listing is a centerpiece of President João Lourenço’s privatization program, which aims to reduce state dominance in the former Marxist-Leninist economy and attract foreign capital. Unitel became the first non-financial company listed on the Angolan exchange.

Its successful subscription was widely seen as a test of investor appetite for Angolan state assets — and a potential precursor to the listing of larger entities, including national oil company Sonangol.

Unitel came under state control in 2022 after authorities seized shareholdings previously owned by Isabel dos Santos, daughter of former President José Eduardo dos Santos. That move was part of Lourenço’s broader effort to unwind business networks tied to his predecessor’s 38-year administration.

What’s next?

Angolan authorities have not made any statements regarding the timing of the attack or whether it was linked to the IPO. Unitel has not commented on the nature of the breach — whether it was ransomware, a destructive wiper, or something else entirely.

For now, millions of Angolans remain without reliable mobile service, and businesses are feeling the pinch. The fact that the attack hit exactly when it did — hours before a landmark listing — raises questions that authorities will need to answer.

This isn’t the first time a major telecom has faced such a crisis. Telecom cyberattacks have become increasingly common in emerging markets, where state-owned operators often run aging infrastructure with limited security budgets. Angola’s next steps will be watched closely by investors and regulators alike.

Continue Reading

Trending