Category: GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Proofpoint: TA4922 Deploys New RAT and Loader Arsenal

A rapidly evolving threat cluster tracked as TA4922, a Chinese-speaking cybercriminal actor deploying a diverse and expanding malware arsenal that now includes Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT. The group is notable for its high operational tempo, shifting tactics, and…

Phishing Attacks Pivot to Infostealer Malware Over Fake Login Pages

Cybercriminal tactics are evolving as phishing campaigns increasingly shift away from fake login pages toward infostealer malware designed to quietly harvest sensitive data from infected systems. While traditional credential-harvesting pages remain in use, threat actors are now prioritizing methods that…

JINX-0164 Targets Crypto Firms With macOS Malware

A series of targeted intrusions against cryptocurrency organizations, attributing the activity to a newly identified threat actor tracked as JINX-0164. The campaign combines advanced social engineering, custom macOS malware, and deep access into development and CI/CD environments, enabling attackers to…

Kali365 PhaaS Expands to Okta, MAX Messenger Attacks

The Kali365 phishing-as-a-service (PhaaS) platform has significantly expanded its operational scope, moving beyond Microsoft 365 token theft to target Okta single sign-on (SSO) environments and Russia’s rapidly growing MAX Messenger platform. New threat intelligence reveals a more mature, multi-brand phishing…

Fake Chrome Web Store Copyright Alerts Used to Steal Google Logins

Hackers are actively targeting Chrome extension developers with a sophisticated phishing campaign that impersonates official Chrome Web Store copyright enforcement notices, aiming to steal Google account credentials and potentially compromise widely used browser extensions. Victims are told they have 48…

Acer Confirms Patch in Progress for Wave 7 Router 0-Day Flaw

Acer has confirmed that it is actively developing a firmware patch to address critical zero-day vulnerabilities affecting its Wave 7 routers, following responsible disclosure by an independent security researcher. According to an official advisory published on June 2, 2026, the…

Fake Claude Code Installer on Google Sites Steals Credentials

Fake installers for Anthropic’s Claude Code are being weaponized in a new ClickFix-style campaign that abuses trusted Google Sites hosting to deliver a fileless credential‑stealing malware payload. The operation impersonates popular AI development tools such as Claude Code and Codex,…