Russia sentenced the leader of Hydra Market — the world’s largest dark web marketplace — to life in prison, while more than a dozen accomplices received 8 to 23 year terms for running a $1.35 billion narcotics and cybercrime platform serving 17 million customers worldwide. HN48 also covers South Korea’s arrest of a manufacturing CEO […]
Blog
Andrew Tate's Platform Hacked + Russian RomCom Exploits Firefox Zero-Day | HN 47
Hacktivists breached Andrew Tate’s online platform “The Real World,” exposing data on 794,000 users — a platform the attackers described as “hilariously insecure.” HN47 also covers Russian RomCom hackers chaining two zero-days — a Firefox use-after-free (CVE-2024-9680) and a Windows Task Scheduler privilege escalation (CVE-2024-49039) — to achieve drive-by remote code execution with no user […]
Phobos Ransomware Admin Charged + Helldown Exploits Zyxel VPN | HN 46
US prosecutors charged Evgenii Ptitsyn, the Russian national suspected of administering the Phobos ransomware-as-a-service operation, after his extradition from South Korea — a platform linked to breaches of over 1,000 entities and $16 million in ransom payments. HN46 also covers Helldown ransomware, a fast-growing LockBit 3-based operation exploiting a command injection vulnerability in Zyxel IPSec […]
Remcos RAT Fileless Attack + ZIP Concatenation Hides SmokeLoader | HN 45
A revamped Remcos RAT campaign is targeting Windows users via phishing emails exploiting a 2017 Microsoft Office vulnerability (CVE-2017-0199) — with a payload wrapped in five layers of obfuscation across JavaScript, VBScript, PowerShell, Base64, and C++, plus anti-debugging techniques that produce a fileless, in-memory infection. HN45 also covers attackers abusing ZIP concatenation — appending multiple […]
SteelFox Crack Tool Malware + eBay Malvertising Attack | HN 44
SteelFox malware is spreading through crack tools for AutoCAD, JetBrains, and Foxit PDF Editor — using a bring-your-own-vulnerable-driver (BYOVD) technique to escalate to NT SYSTEM privileges, then mines Monero while stealing data from 13 browsers including cookies and credit cards. HN44 also covers a large eBay malvertising campaign where scammers exploited Google Ads and eBay’s […]
Operation Magnus: Redline and MetaStealer Infostealer Networks Dismantled | HN 43
Dutch National Police and international partners dismantled the infrastructure behind Redline and MetaStealer — two of the most widely distributed infostealer malware families — in Operation Magnus on October 28, 2024. Three command-and-control servers in the Netherlands were seized alongside two domains, disrupting an estimated 1,200 servers across dozens of countries. The US DOJ charged […]





