Cyber Dispatch™️
386 subscribers
22 photos
1 video
56 links
The definitive source for critical cybersecurity news. When a major threat breaks, we dispatch.

#CyberDispatch #CyberSecurity #InfoSec #ThreatIntelligence #ZeroDay #DataBreach #SecurityNews
Download Telegram
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure.
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading.
US Posts $10 Million Bounty for Iranian Hackers.
UK vows to look at 35-year-old Computer Misuse Act.
STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware.
Over 300,000 Individuals Impacted by Vitas Hospice Data Breach.
North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks.
New GeminiJack 0-Click Flaw in Gemini AI Exposed Users to Data Leaks.
Ransomware IAB abuses EDR for stealthy malware execution.
Goodbye, dark Telegram: Blocks are pushing the underground out.
Cyber Dispatch™️
Goodbye, dark Telegram: Blocks are pushing the underground out.
Telegram has won over users worldwide. While the average user chooses a messaging app based on convenience, user experience and stability (and perhaps, cool stickers).

When it comes to anonymity, privacy and application independence – essential criteria for a shadow messaging app – Telegram is not as strong as its direct competitors.

It lacks default end-to-end (E2E) encryption for chats.
It has a centralized infrastructure: users cannot set up their own servers for communication.
Its server-side code is closed: users cannot verify what it does.

This architecture requires a high degree of trust in the platform, but experienced cybercriminals prefer not to rely on third parties when it comes to protecting their operations and, more importantly, their personal safety.

That said, Telegram today is widely viewed and used not only as a communication tool (messaging service), but also as a full-fledged dark-market business platform – thanks to several features that underground communities actively exploit.

Is this research, we examine Telegram through the eyes of cybercriminals, evaluate its technical capabilities for running underground operations, and analyze the lifecycle of a Telegram channel from creation to digital death. For this purpose, we analyzed more than 800 blocked Telegram channels, which existed between 2021 and 2024.
Key findings

The median lifespan of a shadow Telegram channel increased from five months in 2021–2022 to nine months in 2023–2024.
The frequency of blocking cybercrime channels has been growing since October 2024.
Cybercriminals have been migrating to other messaging services due to frequent blocks by Telegram.
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data.
New JS#SMUGGLER Campaign Drops NetSupport RAT Through Infected Sites.
Poland arrests Ukrainians utilizing 'advanced' hacking equipment.
Malicious VSCode extensions on Microsoft's registry drop infostealers.
GrayBravo’s CastleLoader Activity Clusters Target Multiple Industries.
Ransomware gangs turn to Shanya EXE packer to hide EDR killers.
Oracle EBS zero-day used by Clop to breach Barts Health NHS.
Microsoft just fixed 56 Windows bugs — one’s already being exploited.

It hides in the Cloud Files driver used by OneDrive, Google Drive, and iCloud — even if those apps aren’t installed. Hackers can chain it with phishing to gain SYSTEM access.

Plus: 2 zero-days in PowerShell and GitHub Copilot for JetBrains.
Fortinet, Ivanti & SAP just fixed critical bugs that let attackers break in or run code remotely.

➜ Fortinet: auth bypass via fake SAML login.
➜ Ivanti: admin takeover through poisoned dashboards.
➜ SAP: code injection in Solution Manager (CVSS 9.9).
North Korean hackers are exploiting the new React2Shell bug (10.0-severity) to drop EtherRAT — malware that hides its commands inside Ethereum smart contracts.

It even makes 9 blockchain nodes “vote” to pick its server, so takedowns fail.