Summary of Todayโs Cyber Attacks and DoS Activities (July 25, 2025)
Based on the latest reports, hereโs a concise overview of ongoing cyber threats, focused on key incidents.
Ongoing Espionage and Targeted Attacks:
โข Russian aerospace and defense sectors hit by a new backdoor malware called EAGLET, aimed at intelligence gathering.
โข Chinese APT groups (e.g., Linen Typhoon/APT27 and Violet Typhoon/Storm-2603) exploiting Microsoft SharePoint zero-days, affecting over 400 global organizations in critical infrastructure.
โข State-sponsored actors like Patchwork (India-linked) and Fire Ant (possibly North Korea-linked) targeting Turkish and Russian defense via spear-phishing and virtualization exploits.
Ransomware and Malware Campaigns:
โข Chaos RaaS group (possibly ex-BlackSuit members) launching big-game hunts with double extortion, using spam, social engineering, and data exfiltration tools.
โข Soco404 cryptomining campaign exploiting cloud vulnerabilities (Linux/Windows), hiding payloads in fake 404 pages on Google Sites.
โข New VoIP botnet expanding from rural New Mexico, targeting routers with default passwords and Telnet exploits, impacting IoT devices like Cambium networks.
Denial of Service (DoS/DDoS) Incidents:
โข Moroccan Black Cyber Army claiming DDoS attacks on Algerian sites, including Akhbar Dzair, Gulf Bank Algรฉrie, National Library of Algeria,
Algeria-dz.com, and Plant Ecology Lab.
โข Thai and foreign hackers conducting ongoing DDoS against Cambodian websites.
โข Escalating DDoS threats to global ports (80% of world trade), involving Russian, Iranian, and Chinese state actors, ransomware groups, and hacktivists targeting vessel traffic and access systems.
โข Ransomware outfits like Storm-2603 and DragonForce incorporating DDoS in attacks on critical infrastructure.
โข Pay2Key.I2P RaaS (Tehran-linked) offering bonuses for attacks on U.S./Israeli targets, potentially including DDoS.
Other Emerging Threats:
โข Cybercriminals using purchased malware to hit U.S./EU banks, governments, and corporations via initial access brokers.
โข Surge in crypto address poisoning attacks, with stolen funds up by $500K in recent weeks and incidents rising to 83.8M.
โข CISA warnings on hardware vulnerabilities in Honeywell, Medtronic, Mitsubishi, LG devices that could enable DoS.
โข Botnets (Mirai, Andoryu, EnemyBot) attacking GitLab and Eir D1000 routers; Mimo Loader exploiting Craft CMS for miners and proxyware.
Stay vigilantโmonitor CISA and threat intel sources for updates.
#CyberSecurity #DDoS #Ransomware