
CYFIRMA Research
@CyfirmaR
Followers
299
Following
27
Media
36
Statuses
543
#externalthreatlandscape #etlm #decodingthreats #cyberintelligence #threatvisibility
Joined July 2022
In the past 90 days, the #InformationTechnologyIndustry faced low to moderate risks. 44% of #APTcampaigns hit #IT. 140 #Ransomware victims were observed. #Qilin & #Incransom were the most active gangs. #US had 45% of victims. #CYFIRMA #CISA #Threatintel.
cyfirma.com
EXECUTIVE SUMMARY The CYFIRMA Industries Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each...
0
0
0
#CYFIRMA research delves into the #RavenStealer! A stealthy #infostealing #malware written in #Delphi & C++, designed to harvest passwords, cookies, payment info & autofill data from Chromium-based browsers like Chrome & Edge. #CyberSecurity #ThreatIntel .
cyfirma.com
EXECUTIVE SUMMARY Raven Stealer is a modern, lightweight, information-stealing malware developed primarily in Delphi and C++, designed to extract sensitive...
0
2
2
#CYFIRMA’s July 2025 #Ransomware Report recorded 504 global victims. #Qilin was the most active group, while #Incransom & #SafePay surged. #US was the top target & #consumerservices, #professionalservices, & #manufacturing sectors were the hit hardest.
cyfirma.com
EXECUTIVE SUMMARY In July 2025, ransomware activity remained high, with major impacts on consumer services, professional services, and manufacturing. Qilin...
0
0
0
#China's #SouthChinaSea ambitions stalled: #ASEAN Fights Back Amid #US Distractions. #Beijing's ambitions hit a wall, with a fallout in #cyberspace. #Geopolitics #CYFIRMA #ThreatIntelligence #cybersecurity #currentaffairs #MilitaryAffairs .
cyfirma.com
INTRODUCTION – A DECADE OF AGGRESSION For the past several years, an emboldened China has intensified its aggression in the...
0
2
2
#CYFIRMA’s Monthly #Ransomware Report – July 2025. recorded 504 global victims, a 7.5% rise from June. #Qilin was the most active group, while #Incransom & #SafePay surged. #US, #Canada & #UK were top targets. #CISA #Threatintel.
cyfirma.com
EXECUTIVE SUMMARY In July 2025, ransomware activity remained high, with major impacts on consumer services, professional services, and manufacturing. Qilin...
1
0
1
Posing as Indian #bankingapps, this #Androidmalware harvests SMS, steals debit card details & hijacks call forwarding, all while leveraging Firebase Cloud Messaging (FCM) as its Command & Control (C2) channel. #CYFIRMA #CyberThreat #BankingMalware.
cyfirma.com
ANDROID MALWARE POSING AS INDIAN BANK APPS EXECUTIVE SUMMARY At CYFIRMA, we are committed to delivering timely intelligence on emerging...
0
3
7
#CYFIRMA provides an analysis of a newly identified #RemoteAccessTrojan, #EdskManager #RAT, which exhibits stealthy infection mechanisms and covert control using #HVNC. This #malware showcases advanced evasion & surveillance features. #Threatintel #CISA .
cyfirma.com
Executive Summary At CYFIRMA, we are dedicated to providing current insights into prevalent threats and the strategies employed by malicious...
0
3
4
In the past 90 days, #MaterialsIndustry faced 3 of 10 #APTcampaigns. #Turkish, #Philippine #English-speaking actors were responsible. It faced 82 #Ransomwarevictims. #Akira & #Play led. #USA had 41% victims. #CYFIRMA #CISA #Threatintel #Cybersecurity.
cyfirma.com
EXECUTIVE SUMMARY The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each...
0
0
0
#CVE20255777 – Pre-Auth Memory Leak in #CitrixNetScaler (#CitrixBleed2) #vulnerability allows unauthenticated attackers to leak sensitive memory. It has been exploited in the wild and backed by public PoC code. #CYFIRMA #CISA #Threatintel #Cybersecurity.
cyfirma.com
EXECUTIVE SUMMARY CVE‑2025‑5777 is a critical information disclosure vulnerability in Citrix NetScaler ADC and Gateway appliances, caused by unsafe memory...
0
1
1
In the past 90 days, the #ManufacturingIndustry faced only 1 of 10 #APTcampaigns. 138 #Ransomware victims were observed. #Play & #Qilin led in volume. The #USA had 52% of cases. #CYFIRMA #CISA #CyberSecurity #Threatintel #Industryreport.
cyfirma.com
EXECUTIVE SUMMARY The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each...
0
3
4
#CYFIRMAResearch is thrilled to share insights on #APT #FancyBear. Stay ahead with insights on APT Fancy Bear's motives, targeted industries, targeted countries, and TTPs. #CYFIRMA #CISA #CyberSecurity #CYFIRMA #ETLM #Threatintelligence
cyfirma.com
Fancy Bear, also known as APT28, is a notorious Russian cyberespionage group with a long history of targeting governments, military...
0
1
2
#CYFIRMAResearch presents Fortnightly #Vulnerability Summary! Get the latest insights, severity levels, industry-specific threats, current trends & much more. #CYFIRMA #CyberSecurity #CISA #VulnerabilitySummary #ExternalThreatLandscapeManagement #ETLM .
cyfirma.com
Fortnightly Vulnerability Summary CHECK OUT THESE FAST FACTS ON FORTNIGHTLY OBSERVED VULNERABILITIES. Fortnight’s Most Impacted Products Framework | ColdFusion| Illustrator...
0
0
0
#CYFIRMA’s Monthly #Ransomware Report-June saw 463 ransomware victims globally, a 15% decline from May. #Qilin led the threat landscape. The #US, #Canada & the #UK were top targets, with #professionalservices, #IT & #healthcare sectors most affected.
cyfirma.com
EXECUTIVE SUMMARY In June 2025, ransomware attacks targeted critical industries such as professional services, healthcare, and information technology, exploiting their...
0
1
3
#CYFIRMA exposes #Octalyn Stealer, a malicious #GitHub-hosted tool masquerading as a legitimate forensic utility. It functions as a #credentialstealer with Telegram-based C2, targeting browser data, crypto wallets, Discord & VPN configs. #Malware #ETLM.
cyfirma.com
EXECUTIVE SUMMARY The Octalyn Forensic Toolkit, publicly hosted on GitHub, presents itself as a research-oriented tool for digital forensics and...
0
3
12
#ZeroClick Compromise via File Rendering Automation. #RenderShock introduces a powerful new attack framework that leverages trusted file previewing, indexing & sync mechanisms to trigger payloads without exploits, macros or even opening the file. #CYFIRMA .
cyfirma.com
EXECUTIVE SUMMARY RenderShock is a comprehensive zero-click attack strategy that targets passive file preview, indexing, and automation behaviours in modern...
0
2
5
#CYFIRMA's latest report delves into a fake "Free VPN for PC" #app hosted on #GitHub, delivering a packed #DLLpayload using obfuscated #Base64 hidden in junk strings. #MalwareAnalysis #CyberSecurity #DLLInjection #FakeVPN #ReverseEngineering #threatintel.
cyfirma.com
EXECUTIVE SUMMARY At CYFIRMA, we continuously monitor and investigate emerging cyber threats targeting both organizations and individuals. In this report,...
0
2
3
#CYFIRMA uncovers a sophisticated #phishingcampaign by #APT36 (#TransparentTribe) leveraging #Linux-specific #malware on BOSS Linux systems (widely used by Indian government agencies). #LinuxMalware #Phishing #IndianDefense #CyberEspionage #CISA .
cyfirma.com
Executive Summary CYFIRMA has identified a sophisticated cyber-espionage campaign orchestrated by APT36 (also known as Transparent Tribe), a threat actor...
2
7
22
The #Australia Cyber Threat Landscape Report provides strategic insights into its evolving #cyberthreat environment, highlighting targeted sectors & #vulnerabilities, emerging #ransomwaretrends, #darkwebactivities & #nationstatethreats. #CYFIRMA #CISA .
cyfirma.com
Why Cyber Threat Actors Target Australia?Why Cyber Threat Actors Target Australia?Why Cyber Threat Actors Target Australia?Why Cyber Threat Actors Target...
0
0
0
#CYFIRMAResearch presents Fortnightly #Vulnerability Summary! Get the latest insights on Fortnightly vulnerabilities, severity levels, industry-specific threats, current trends & much more. #CYFIRMA #CISA #CyberSecurity #VulnerabilitySummary #Threatintel.
cyfirma.com
Fortnightly Vulnerability Summary CHECK OUT THESE FAST FACTS ON FORTNIGHTLY OBSERVED VULNERABILITIES. Fortnight’s Most Impacted Products D-Link | Teamcity |...
0
1
1
In the past 90 days, #Automotiveindustry faced 2 of 11 #APTcampaigns led by #FIN11 & #Chinese #MSSlinkedactors. 39 #Ransomware victims were observed. #Qilin, #Akira & #Spacebears led. #USA had 46% of victims. #CISA #Threatintel #CYFIRMA #Cybersecurity.
cyfirma.com
EXECUTIVE SUMMARY The CYFIRMA Industry Report delivers original cybersecurity insights and telemetry-driven statistics of global industries, covering one sector each...
0
0
0