Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
thehackernews.com

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

A joint cybersecurity advisory from Japan, the U.S., Australia, and Germany revealed that North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices in more than 100 countries and stolen over $10.71 million in cryptocurrency from 7,000+ wallets. The attackers target web designers, engineers, and blockchain specialists by posing as recruiters on LinkedIn, then deploying malware such as BeaverTail and OtterCookie to gain remote access. The operation, linked to the 313 General Bureau, [...]
SEALSQ, WISeKey, and Canton of Jura Execute MoU for CHF 40–60M ($48.7M–$73M USD) Post-Quantum Semiconductor Personalization Hub
quantumcomputingreport.com

SEALSQ, WISeKey, and Canton of Jura Execute MoU for CHF 40–60M ($48.7M–$73M USD) Post-Quantum Semiconductor Personalization Hub

SEALSQ Corp, its parent WISeKey International Holding Ltd, and the Swiss Canton of Jura signed a Memorandum of Understanding to create the Jura Post‑Quantum Semiconductor and Cybersecurity Center. The public‑private partnership will invest CHF 40 million to CHF 60 million over six years to develop regional expertise in personalizing, testing, and certifying hardware‑embedded post‑quantum cryptography. The center will use SEALSQ’s QS7001 Quantum Shield microcontrollers, which run NIST‑standard ML‑KEM and ML‑DSA lattice algorithms, and will support defense, aerospace, and critical infrastructure sectors. [...]
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
thehackernews.com

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers uncovered TASK#STOMP, a PowerShell backdoor that harvests business documents, Wi‑Fi passwords, clipboard data, and screenshots while accepting remote commands via two token‑authenticated C2 servers. Infection begins with a disguised VBScript (“95c9050t66.vbs”) executed through wscript.exe, establishing persistence through scheduled tasks and the Startup folder. The malware employs timestomping, hidden execution, and mutual‑watchdog modules to maintain a single active session and evade detection. It also opens a Chrome window to an Iranian tender database, though the purpose [...]
SEALSQ, WISeKey and Jura Sign MoU for Swiss Post-Quantum Semiconductor Center
thequantuminsider.com

SEALSQ, WISeKey and Jura Sign MoU for Swiss Post-Quantum Semiconductor Center

SEALSQ Corp, WISeKey International Holding, and the Canton of Jura signed a memorandum of understanding to create a Post‑Quantum Semiconductor and Cybersecurity Center in the Swiss canton. The project will invest roughly CHF 40‑60 million over six years, focusing on the QS7001 Quantum Shield and related secure firmware personalization, testing, and certification. The initiative aims to generate about 40 jobs in two years, expanding to over 250 by year eight, with a majority of positions filled by local residents. [...]
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
thehackernews.com

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

SentinelOne revealed that North Korean threat actor Jade Sleet targeted an India‑based IT services firm, deploying Apple macOS backdoors FLATROOF and ROOFDECK. The attack used social‑engineering job‑interview lures to compromise a DevOps engineer’s Apple Silicon MacBook, with the backdoors first detected on March 18, 2026. The implants remained dormant until March 29, then began beaconing, and a newer ROOFDECK variant appeared on April 20, 2026, stripping debug symbols to evade detection. The campaign underscores Jade Sleet’s focus on cryptocurrency and blockchain vendors. [...]
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
thehackernews.com

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are using ClickFix‑style lures to deliver a new remote‑access trojan dubbed ChainScript. The malware, also seen under names such as ComponentTask33 and OrchidViolet66, masquerades as legitimate software like Spotify, Zoom Workplace and Microsoft Teams. After a malicious MSI installer runs via msiexec.exe, it drops a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages, installing components in “%LOCALAPPDATA%” and persisting via a scheduled task with a Registry Run key fallback. ChainScript employs [...]
Revolut Customers Targeted with New Wave of Phishing Attacks
infosecurity-magazine.com

Revolut Customers Targeted with New Wave of Phishing Attacks

Hackers have exploited a recent Revolut data breach to launch a smishing campaign targeting the fintech firm’s customers, Malwarebytes reported. The phishing texts, first seen on September 14, mimicked legitimate Revolut messages and urged recipients to click a link to “confirm their identity” or face account restrictions. The link directed users to a counterfeit live‑video verification page that requested camera access, then prompted for passwords, allowing attackers to capture selfies or videos for further fraud. Malwarebytes warned that [...]
MovieReaper Malware: From Movie Download to Malware Infection
cyberint.com

MovieReaper Malware: From Movie Download to Malware Infection

MovieReaper, first seen in September 2026, is a modular malware that blends a remote‑access trojan with a loader, targeting x86‑64 Windows systems. It spreads via compromised torrent‑file infrastructure, delivering a disguised loader that passes anti‑sandbox checks, downloads shellcode, and retrieves command‑and‑control endpoints from a Solana blockchain. Subsequent stages establish HTTPS communication with certificate pinning, load additional COFF modules, perform UAC bypass, and persist by masquerading as C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. The final implant offers full file‑management, exfiltration, and remote control, enabling [...]