Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Security Week
  • In Other News: Scattered Spider Still Active, EncryptHub Unmasked, Rydox Extraditions
  • Security Week

In Other News: Scattered Spider Still Active, EncryptHub Unmasked, Rydox Extraditions

SecurityWeek News Published: April 11, 2025 | Updated: April 11, 2025 4 min read
0 views

SecurityWeek’s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports. 

Here are this week’s stories:

EncryptHub unmasked

The threat actor known as EncryptHub (aka Larva-208) appears to be a Ukrainian national who has been involved in cybercrime activities while trying to find a legitimate job, according to Outpost24. Poor OPSEC enabled Outpost24 researchers to track the man’s life in recent years, but they have not made his name public. He was recently credited by Microsoft for responsibly disclosing two vulnerabilities. 

Neptune RAT steals passwords from 270 applications

Cyfirma has analyzed Neptune RAT, a remote access trojan targeting Windows systems with destructive capabilities and the ability to steal passwords from over 270 applications. The malware uses various persistence methods and anti-analysis techniques, and it also packs ransomware, cryptocurrency clipper, desktop monitoring, and anti-antivirus capabilities. 

Advertisement. Scroll to continue reading.

Google details Russian espionage aimed at Europe

Google Cloud has shared details on the tactics and techniques of UNC5837, a Russia-linked threat actor, in cyberespionage attacks aimed at government and military organizations in Europe. Google’s report focuses on how the attackers leveraged lesser-known RDP features to gain access to victims’ devices and exfiltrate data. The campaign was previously analyzed by Microsoft and AWS.

WK Kellogg data breach

Food giant WK Kellogg is notifying employees that their information may have been compromised in the Cleo attack conducted by the Cl0p ransomware group. It’s unclear how many people are impacted by the data breach, but the number may be low. In Maine, for instance, only one impacted individual has been identified. 

Rydox cybercrime marketplace admins extradited to US

Kosovo nationals Ardit Kutleshi and Jetmir Kutleshi have been extradited from Kosovo to the United States, where they face identity theft, money laundering, and access device fraud charges related to their alleged roles as administrators of the Rydox cybercrime marketplace, which authorities disrupted late last year. 

Significant healthcare data breaches

Two more relatively significant healthcare data breaches came to light recently. Mercer County Joint Township Community Hospital is notifying 88,000 people that their personal information, including SSNs and financial information, may have been stolen in a cyberattack that took place in April 2024. 

The second involves Central Texas Pediatric Orthopedics, which was recently targeted by the Qilin ransomware group. An investigation showed that the cybercriminals managed to steal personal and health information belonging to 140,000 people.

Governments detail spyware targeting Uyghur, Taiwanese and Tibetan groups

Government agencies in the UK, US, Germany, Canada, Australia, and New Zealand have published a joint report detailing BadBazaar and Moonshine, two pieces of spyware used in attacks aimed at Uyghur, Taiwanese and Tibetan groups. Unsurprisingly, the malware has been attributed to Chinese state-sponsored threat actors.

Splunk and Palo Alto Networks patches

Splunk has published 15 advisories describing the third-party package updates of April 2025. The updates mostly address critical- and high-severity vulnerabilities in Juniper, Microsoft, Symantec, and other components. 

Palo Alto Networks has published nearly a dozen new advisories. A majority of them address medium- and low-severity issues affecting Cortex XDR, PAN-OS, Prisma and GlobalProtect products. The security holes can allow command injection, DoS attacks, information disclosure, user impersonation, and privilege escalation. The security giant says there is no evidence of in-the-wild exploitation. 

Scattered Spider still active despite arrests

Despite several of its members being arrested and prosecuted, the Scattered Spider cybercrime group is still active. According to Silent Push, the hackers this year have targeted services such as Klaviyo, HubSpot, and Pure Storage, as well as brands such as Chick-fil-A, Forbes, Instacart, Louis Vuitton, Morningstar, News Corporation, Nike, X, Tinder, T-Mobile, and Vodafone.

Fortinet says hackers exploiting known vulnerabilities with new techniques

Fortinet has informed customers that threat actors have been observed exploiting known vulnerabilities “with a new technique to maintain read-only access to vulnerable FortiGate devices after the original access vector was locked down”. The company’s investigation determined that the attacks were not aimed at a specific region or sector. 

Related: In Other News: Hellcat Hackers Unmasked, CrushFTP Bug Controversy, NYU Hacked

Related: In Other News: Apple Improving Malware Detection, Cybersecurity Funding, Cyber Command Chief Fired

About The Author

SecurityWeek News

See author's posts

Original post here

What do you feel about this?

  • Security Week

Post navigation

Previous: SonicWall Patches High-Severity Vulnerability in NetExtender
Next: Vulnerability in OttoKit WordPress Plugin Exploited in the Wild

Author's Other Posts

Network Access Vendor Portnox Secures $37.5 Million Investment Cybersecurity_News-SecurityWeek.jpg

Network Access Vendor Portnox Secures $37.5 Million Investment

April 8, 2025 0 0
Octane Raises $6.75M for Smart Contract Security Tech Cybersecurity_News-SecurityWeek.jpg

Octane Raises $6.75M for Smart Contract Security Tech

April 8, 2025 0 0
In Other News: Apple Improving Malware Detection, Cybersecurity Funding, Cyber Command Chief Fired cybersecurity-news.jpg

In Other News: Apple Improving Malware Detection, Cybersecurity Funding, Cyber Command Chief Fired

April 4, 2025 0 0
In Other News: Hellcat Hackers Unmasked, CrushFTP Bug Controversy, NYU Hacked cybersecurity-news.jpg

In Other News: Hellcat Hackers Unmasked, CrushFTP Bug Controversy, NYU Hacked

March 28, 2025 0 0

Related Stories

Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers

Ionut Arghire April 15, 2025 0 0
ransomware.jpeg
  • Security Week

Kidney Dialysis Services Provider DaVita Hit by Ransomware

Ionut Arghire April 15, 2025 0 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Conduent Says Names, Social Security Numbers Stolen in Cyberattack

Ionut Arghire April 15, 2025 0 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches

Ionut Arghire April 15, 2025 0 0
VC-Funding_China-tech.jpg
  • Security Week

China Pursuing 3 Alleged US Operatives Over Cyberattacks During Asian Games

Associated Press April 15, 2025 0 0
Satellite-Link-Cybersecurity.jpg
  • Security Week

Blockchain, Quantum, and IoT Firms Unite to Secure Satellite Communications Against Quantum Threats

Kevin Townsend April 15, 2025 0 0

Trending Now

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill 1

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

December 6, 2025 0 0
SMS Phishers Pivot to Points, Taxes, Fake Retailers SMS Phishers Pivot to Points, Taxes, Fake Retailers 2

SMS Phishers Pivot to Points, Taxes, Fake Retailers

December 4, 2025 0 0
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse whatsapp-sim.jpg 3

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse

December 2, 2025 0 0
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera korean.jpg 4

Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera

December 2, 2025 0 1

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill 1
  • Uncategorized

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

December 6, 2025 0 0
SMS Phishers Pivot to Points, Taxes, Fake Retailers SMS Phishers Pivot to Points, Taxes, Fake Retailers 2
  • Uncategorized

SMS Phishers Pivot to Points, Taxes, Fake Retailers

December 4, 2025 0 0
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse whatsapp-sim.jpg 3
  • The Hacker News

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse

December 2, 2025 0 0
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera korean.jpg 4
  • The Hacker News

Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera

December 2, 2025 0 1
GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools hacked.jpg 5
  • The Hacker News

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools

December 2, 2025 0 0
Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools npm-mal.jpg 6
  • The Hacker News

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

December 2, 2025 0 1
Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks iran-hacking.jpg 7
  • The Hacker News

Iran-Linked Hackers Hits Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks

December 2, 2025 0 0

You may have missed

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill
  • Uncategorized

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

Sean December 6, 2025 0 0
SMS Phishers Pivot to Points, Taxes, Fake Retailers
  • Uncategorized

SMS Phishers Pivot to Points, Taxes, Fake Retailers

Sean December 4, 2025 0 0
whatsapp-sim.jpg
  • The Hacker News

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse

[email protected] The Hacker News December 2, 2025 0 0
korean.jpg
  • The Hacker News

Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera

[email protected] The Hacker News December 2, 2025 0 1
Copyright © 2026 All rights reserved. | MoreNews by AF themes.