Sable Index
896 subscribers
138 photos
2 videos
6 links
Download Telegram
[DEVELOPING · MALWARE] Fake Bank of America emails install hidden ScreenConnect access

Huntress disclosed August 4 that fake Bank of America emails are installing ScreenConnect, a remote-access tool, on Windows PCs.

Victims download “Account Guard,” a fake security tool. Its scripts decode a payload, bypass Windows’ elevation prompt and hide the service under “Windows Security.”

Mac visitors receive a credential and identity-data phishing page. Huntress says the campaign remains active.

@SableIndex | @SableIndexDiscussion
👀11😴21
[AI] INTERPOL links AI to 55% of Africa’s reported cybercrime

INTERPOL’s African Cyberthreat Assessment, released August 3, says AI enabled 55% of reported cybercrime across Africa.

The report draws on surveys from 36 member countries. It links AI-facilitated scams, credential harvesting and automated social engineering to losses that more than doubled, from $192 million to $484 million.

INTERPOL also records 600,000 sextortion detections and says 72% of surveyed countries reported scam centres. It calls for shared data and stronger AI skills in law enforcement.

@SableIndex | @SableIndexDiscussion
🤓721
[CRIME] Tycoon2FA developers arrested after 96,000 phishing victims

Singapore Police reported August 4 that Pakistan arrested two alleged Tycoon2FA developers after a joint investigation with Interpol.

The arrests occurred June 25 and July: the platform sold phishing infrastructure for monthly fees, enabling customers to clone websites and steal login credentials.

Investigators seized a laptop, two computers and six mobile phones.

@SableIndex | @SableIndexDiscussion
👀82💊1
[CRIME] Philippines charges three minors over school threat videos

Philippine authorities reported August 3 that three minors had been charged over social-media threats targeting students and staff at five Angeles City schools.

Police said two other minors were also arrested in related bomb-hoax cases. Since May, officers handled 47 school bomb-threat reports across Central Luzon; all were hoaxes that disrupted classes and diverted resources.

@SableIndex | @SableIndexDiscussion
🕊81👍1
[MALWARE] Octagon Android RAT disguises itself as Bahrain’s BH Alert app

Zimperium said August 4 that Octagon, an Android remote-access trojan, is targeting users through a fake Bahrain Civil Defense app.

After victims grant Accessibility access, the malware can capture screen text, log keystrokes, steal credentials and read SMS messages.

It uses encrypted, dynamically loaded payloads and persistent command-and-control traffic to evade static scanners.

@SableIndex | @SableIndexDiscussion
🤓104🕊1
[MALWARE] XCSSET Spreads Through Xcode Projects and Hijacks Chrome

A new XCSSET variant is spreading through compromised Xcode projects and GitHub repositories, infecting developers when they build downloaded code.

Unit 42 says the campaign hid in projects tied to dozens of legitimate apps with thousands of active users. Its 17 modules steal credentials and browser data; a new Chrome hijacker can intercept sessions, while a Telegram trojanizer replaces the desktop app.

@SableIndex | @SableIndexDiscussion
12👀3🤩1
[BREACH] Intermarché says cyberattack exposed 287,605 customer records

Intermarché said August 4 that a cyberattack exposed data from 287,605 customers of its online grocery service.

Names, phone numbers, addresses, birth dates, loyalty-card numbers and order details were affected; bank data, passwords and email addresses were not.

@SableIndex | @SableIndexDiscussion
🤩10💊43🕊1
[ANALYSIS · CRIME] Audi Gang: Europe’s High-Speed ATM Bombers

The “Audi Gang” was never a single organisation with a known leader and formal membership. Investigators used the name for overlapping, largely Dutch-based crews that crossed into Germany, destroyed cash machines and escaped in stolen high-performance Audis.

Their operations followed a disciplined pattern. One group obtained a vehicle, another prepared explosives, while drivers and demolition specialists carried out the attack. The crews often targeted ATMs at night, collected the cash and returned across the border before local police could coordinate a pursuit.

Early attacks used gas to rupture cash machines. Later crews adopted solid explosives, producing far more destructive blasts. Buildings were damaged, residents were endangered and the cost of repairs sometimes exceeded the stolen cash. Investigators treated several attacks as attempted homicide because people were inside or near the affected properties.

A major German-Dutch operation in February 2023 resulted in nine arrests. Eurojust attributed 31 explosions in Bavaria alone to the investigated network, with approximately €3.4 million stolen and €4 million in damage. A broader independent account connected the investigation to 52 suspected attacks and €5.2 million in proceeds.

Police seized prepared explosives, cash, phones, navigation equipment, luxury clothing and expensive watches. Despite recurring online claims, the public reports do not document Bitcoin wallets, exchange accounts or blockchain tracing. Cryptocurrency laundering may sound plausible, but it remains unproven in this case.

The immediate consequence was a stronger cross-border response. German, Dutch, Belgian and French authorities began treating ATM explosions as organised international crime rather than isolated robberies. Investigators formed specialised teams, coordinated extraditions and shared evidence across jurisdictions.


The Audi Gang label survives, but it can be misleading. Arresting one crew did not dismantle a single criminal hierarchy. It disrupted a repeatable business model that other groups could copy. The lasting legacy is therefore less about one famous gang and more about how mobile criminal networks exploited borders, fast cars and differences in national policing.

@SableIndex | @SableIndexDiscussion
👀143
[RANSOMWARE] Interlock abuses memory tools to exploit Cisco firewall flaw

Sophos said August 4 that Interlock used legitimate memory-forensics tools while exploiting a previously undisclosed Cisco firewall flaw.

On one Windows endpoint, attackers used Volatility3 and WinPmem to extract NTLM hashes and cached domain credentials.

The group reached the domain controller in just over 26 hours after initial access.

Sophos tracks Interlock as GOLD EMBRACE, a double-extortion crew targeting critical infrastructure, healthcare and education.

@SableIndex | @SableIndexDiscussion
😴8🕊3👀2
[DEVELOPING · BREACH] Swiss Federal Office for Information Technology hacked, 200 accounts compromised

Switzerland’s Federal Office for Information Technology and Communications (BIT) confirmed that hackers compromised about 200 accounts on its on-premises SharePoint servers.

The agency blocked Internet access and began reinstalling servers after detecting anomalous access.

@SableIndex | @SableIndexDiscussion
🕊10
[CRIME] Ex-LAPD Officer Gets Life Plus 15 Years for Bitcoin Robbery

Former LAPD officer Eric Halem was sentenced to life plus 15 years after a jury convicted him in a violent Koreatown home invasion.

In December 2024, Halem and three men posed as police, restrained a 17-year-old and threatened to kill him for a hard drive holding $350,000 in Bitcoin. A judge rejected Halem’s request for a new trial; he remains charged in another crypto robbery.

@SableIndex | @SableIndexDiscussion
👀121
[DEVELOPING · MALWARE] npm worm poisons 2,234 package versions across 444 names

A credential-stealing worm spread through npm on August 4, republishing poisoned releases across 12 unrelated organizations.

SafeDep confirmed 2,234 malicious versions across 444 package names, including dependencies used by ESLint.

The payload runs during npm install and steals GitHub, cloud, registry tokens and private keys from developer and CI environments.

@SableIndex | @SableIndexDiscussion
14🕊4
[EXPLAINED · CRIME] Russia Tops Oxford’s World Cybercrime Index

They assessed the impact, professionalism and technical skill of cybercriminals.

The study covered five areas: malware and access services, attacks and extortion, data and identity theft, scams, and money laundering.

Russia ranked first with a score of 58.39, followed by Ukraine at 36.44, China at 27.84 and the United States at 25.01.

@SableIndex | @SableIndexDiscussion
👀6🤓5
[ANALYSIS · CRIME] How P4x Became a Real-World Mr. Robot

Alejandro Caceres revealed in 2024 that he was P4x, the lone hacker behind North Korea’s week-long internet disruption.

His unauthorized 2022 campaign repeatedly knocked the country’s publicly visible websites offline, affecting government portals and the state airline’s booking site.

The resemblance to Elliot Alderson begins with the double life. Caceres ran cybersecurity company Hyperion Gray while privately testing where defensive expertise ends and vigilantism begins.

North Korean operators had targeted him in a campaign against security researchers, apparently seeking their intrusion tools. Caceres reported the attempt to the FBI and later said the response went nowhere

Months later, working from his Florida home, he used custom scripts and rented cloud servers to overwhelm several routers carrying North Korea’s external traffic.

This was not cinematic keyboard magic. It was patient automation aimed at a small, fragile set of systems, producing an outsized national effect.

WIRED reported that Caceres supplied screen recordings and other evidence while the disruption was unfolding. Independent reporting later interviewed him under his real name.

Like Elliot, P4x cast hacking as a personal answer to institutional paralysis. He decided official channels had failed, selected a target and imposed his own consequence.
But the comparison has limits. Caceres was a public entrepreneur, not an isolated fictional vigilante, and he later pitched his aggressive methods to US defense officials.

No evidence shows that Mr. Robot inspired him. The resemblance lies in the uncomfortable question both stories raise: when expertise becomes power, who authorizes its use?

Caceres feared prosecution but found parts of the US government more interested in his techniques. His Pentagon proposal was never formally adopted.

By revealing his identity, he traded the safety of a pseudonym for a political argument: cyber retaliation should be faster, smaller and less bureaucratic.


That makes P4x a convincing real-world echo of Mr. Robot, and a reminder that a compelling motive does not make an unauthorized attack accountable.

@SableIndex | @SableIndexDiscussion
8🤩2🤓2