CyberNotableCorroboratingDeveloping
8.9
Discovery of Korean-language malware campaign utilizing ClickFix and RustDesk
vx-undergroundLO·KR·about 15 hours ago
Threat actors are distributing a four-stage Android spyware payload via fraudulent websites mimicking legitimate Bahraini alert applications. The campaign leverages heightened civilian anxiety surrounding Iranian missile activity to facilitate credential theft and device surveillance. It remains unclear which specific threat actor group is responsible for the infrastructure.
Locations
Entities