News

The Hacker News
thehackernews. com > 2026 > 04 > fake-captcha-irsf-scam-and-120-keitaro. html

Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud

2+ hour ago  (524+ words) Cybersecurity researchers have disclosed details of a telecommunications fraud campaign that uses fake CAPTCHA verification tricks to dupe unsuspecting users into sending international text messages that incur charges on their mobile bills, generating illicit revenue for the threat actors who…...

The Hacker News
thehackernews. com > 2026 > 04 > nasa-employees-duped-in-chinese. html

NASA Employees Duped in Chinese Phishing Scheme Targeting U. S. Defense Software

2+ day, 18+ hour ago  (430+ words) The Office of Inspector General (OIG) of the U. S. National Aeronautics and Space Administration (NASA) has revealed how a Chinese national posed as a U. S. researcher as part of a spear-phishing campaign to obtain sensitive information from the space agency, as well…...

thehackernews. com
thehackernews. com > 2026 > 04 > obsidian-plugin-abuse-delivers. html

Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

1+ week, 4+ day ago  (360+ words) A "novel" social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurrency'sectors. The…...

thehackernews. com
thehackernews. com > 2026 > 04 > mirai-variant-nexcorium-exploits-cve. html

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDo S Botnet

1+ week, 2+ day ago  (586+ words) Threat actors are exploiting security flaws in TBK DVR and end'of'life (Eo L) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet Forti Guard Labs and Palo Alto Networks Unit 42. The attack targeting TBK DVR…...

The Hacker News
thehackernews. com > 2026 > 04 > n8n-webhooks-abused-since-october-2025. html

n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

1+ week, 4+ day ago  (371+ words) N8n is a workflow automation platform that allows users to connect various web applications, APIs, and AI model services to sync data, build agentic systems, and run repetitive rule-based'tasks. Users can register for a developer account at no extra cost'to avail…...

The Hacker News
thehackernews. com > 2026 > 04 > mirax-android-rat-turns-devices-into. html

Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220, 000 via Meta Ads

1+ week, 5+ day ago  (557+ words) "Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to fully interact with compromised devices in real time," Italian online fraud prevention firm'Cleafy said. "Beyond traditional RAT behavior, Mirax enhances its operational value by turning infected devices'into residential…...

The Hacker News
thehackernews. com > 2026 > 04 > 108-malicious-chrome-extensions-steal. html

108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20, 000 Users

1+ week, 5+ day ago  (361+ words) Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and…...

thehackernews. com
thehackernews. com > 2026 > 04 > fbi-and-indonesian-police-dismantle. html

FBI and Indonesian Police Dismantle W3 LL Phishing Network Behind $20 M Fraud Attempts

1+ week, 6+ day ago  (743+ words) The U. S. Federal Bureau of Investigation (FBI), in partnership with the Indonesian National Police, has dismantled the infrastructure associated with a global phishing operation that leveraged an off-the-shelf toolkit'called W3 LL to steal thousands of victims' account credentials and attempt more than…...

The Hacker News
thehackernews. com > 2026 > 04 > masjesu-botnet-emerges-as-ddos-for-hire. html

Masjesu Botnet Emerges as DDo S-for-Hire Service Targeting Global Io T Devices

2+ week, 4+ day ago  (319+ words) Called Masjesu, the botnet has been advertised via Telegram as a DDo S-for-hire service since it first surfaced in 2023. It's capable of targeting a wide range of Io T devices, such as routers and gateways, spanning multiple architectures. "Built for…...

The Hacker News
thehackernews. com > 2026 > 04 > russian-state-linked-apt28-exploits. html

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign

2+ week, 5+ day ago  (806+ words) The Russia-linked threat actor known'as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure Mikro Tik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of…...