< ciso
brief />
Tag Banner

All news with #arctic wolf tag

10 articles

ClickFix campaign injects fake Cloudflare lures

🛡️ Arctic Wolf Labs and Blackpoint Cyber reported an active ClickFix campaign compromising Ukrainian business websites to serve bogus Cloudflare verification pages that trick victims into executing an MSI installer. The MSI chain delivers a newly observed information stealer called Psychedelic, which harvests browser credentials, tokens, and crypto-wallet data, sets persistence, and contacts a C2 for follow-on tasks. Researchers also linked the ClickFix chain to other payloads including RemotePanel and BoundSiphon, highlighting modular remote-access and data-theft capabilities and evidence pointing to likely Russian-speaking operators.
read more →

Zyxel and Veeam Flaws Under Active Exploitation

🛡️ CISA added a now-patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273, CVSS 8.8) to its Known Exploited Vulnerabilities list after evidence of active exploitation. The stack-based buffer overflow in the device CGI could permit unauthenticated LAN attackers to execute OS commands; multiple GS1900 firmware versions have fixes. Simultaneously, Arctic Wolf reported active exploitation of a local privilege escalation in Veeam Agent for Windows (CVE-2026-32996, CVSS 7.3) allowing local users to attain SYSTEM privileges via a cached elevated session UID.
read more →

Help‑desk vishing fuels Microsoft 365 token theft

📣 Threat hunters warn of a broad data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms via help‑desk vishing, adversary‑in‑the‑middle token theft, and residential‑proxy sign‑ins. Tracked by Arctic Wolf as PREY‑0058 and linked to activity groups like UNC6671 and Cinder, the actors impersonate IT staff to lure executives to authentication‑themed pages and capture MFA approvals. Attacks culminate in SharePoint, OneDrive, Exchange, and Box data exfiltration and extortion without deploying endpoint malware. Organizations are urged to adopt Conditional Access, phishing‑resistant MFA, and tighter SharePoint access controls.
read more →

Microsoft 365 AitM Phishing Targets Payroll Workflows

🔍 Arctic Wolf Labs warns of a widespread email-driven phishing campaign using adversary-in-the-middle (AitM) techniques to seize Microsoft 365 sessions and harvest payroll and HR email. The campaign leverages residential proxies, multi-step redirections through trusted services, and fingerprinting scripts to evade filters and maintain compromised sessions at roughly eight-hour intervals. Affected sectors include healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe.
read more →

Attackers Exploit CVE-2025-32975 to Hijack KACE SMA

🚨 Arctic Wolf reported exploitation of CVE-2025-32975 (CVSS 10.0), an authentication-bypass in Quest KACE Systems Management Appliance (SMA), against internet-exposed instances beginning the week of March 9, 2026. Attackers impersonated administrative users, executed remote commands to download Base64 payloads via curl from an external host, and created additional admin accounts using runkbot.exe. Observed post-compromise activity included Windows Registry modifications, credential harvesting with Mimikatz, reconnaissance, and RDP access to backup systems and domain controllers. Administrators should apply the May 2025 fixes and avoid exposing SMA directly to the internet.
read more →

Fortinet FortiGate SSO Exploited to Steal Configs Remotely

🚨 Cybersecurity firm Arctic Wolf reports automated attacks against Fortinet FortiGate devices that exploit the FortiCloud SSO feature to create rogue admin accounts and rapidly export firewall configurations. The campaign began January 15 and mirrors December exploitation tied to CVE-2025-59718. Observed indicators include SSO logins from cloud-init@mail.io and IP 104.28.244.114. Administrators are advised to disable FortiCloud SSO until Fortinet issues a complete fix.
read more →

Cybersecurity M&A Roundup: Giants Strengthen AI Security

🛡️ November 2025 saw a flurry of cybersecurity acquisitions as major vendors raced to embed AI, observability and exposure management across their portfolios. Deals included Palo Alto Networks' $3.35bn purchase of Chronosphere, LevelBlue's completion of its Cybereason acquisition, and Bugcrowd's buy of AI app-security firm Mayhem. Other moves saw Safe Security acquire Balbix, Zscaler buy SPLX, and Arctic Wolf agree to acquire UpSight to bolster ransomware prevention. Collectively these transactions accelerate AI-driven automation and resilience across cloud, endpoint and software security.
read more →

RomCom Uses SocGholish to Deliver Mythic Agent to US Firms

🔒 Arctic Wolf Labs observed a targeted September 2025 campaign in which the Russia-aligned RomCom group used fake browser-update prompts to deliver the Mythic Agent implant via a classic SocGholish chain. Researchers say this is the first observed instance of RomCom pairing SocGholish initial access with a Mythic C2-based loader. The intrusion was stopped before impact, and Arctic Wolf published IOCs and mitigation guidance.
read more →

China-Linked UNC6384 Exploits Windows LNK Vulnerability

🔒 A China-affiliated group tracked as UNC6384 exploited an unpatched Windows shortcut flaw (ZDI-CAN-25373, CVE-2025-9491) to target diplomatic and government entities in Europe between September and October 2025. According to Arctic Wolf, the campaign used spear-phishing links to deliver malicious LNK files that launch a PowerShell stager, sideload a CanonStager DLL, and deploy the PlugX remote access trojan. Microsoft says Defender detections and Smart App Control can help block this activity.
read more →

Chinese-Linked Hackers Exploit Windows Shortcut Flaw

🔎 Researchers at Arctic Wolf Labs uncovered a September–October 2025 cyber-espionage campaign that used a Windows shortcut vulnerability to target Belgian and Hungarian diplomatic entities. The operation, attributed to UNC6384 and likely tied to Mustang Panda (TEMP.Hex), combined spear phishing with malicious .LNK files exploiting ZDI-CAN-25373 and deployed a multi-stage chain ending in the PlugX RAT. Attackers used DLL side-loading, signed Canon utilities and obfuscated PowerShell to extract and execute an encrypted payload while displaying decoy diplomatic PDFs.
read more →