Infoblox Threat Intel identifies a threat actor tracked as 'Lurking Lizard' who operates a comprehensive malicious residential proxy ecosystem spanning victim device recruitment through trojanized software (fake 7-Zip, WireVPN), proxy service monetization via lookalike storefronts, and fake review sites for marketing. The actor controls 230+ domains and has been active since at least August 2022, with current operations centered on WireVPN-branded payloads that enroll victim devices as proxy exit nodes rather than functioning as legitimate VPN clients. A shared IPLogger telemetry beacon, consistent API structures, code signing certificate, and deployment patterns link multiple campaigns across several years to a single operator likely based in Wuhan, China.
iOS
14 posts
Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims Cyber Centre Daily Advisory Digest — 2026-06-29 (8 advisories) The Canadian Centre for Cyber Security published a daily advisory digest on 2026-06-29 containing 8 security advisories covering Ubuntu, Red Hat, CISA ICS, Dell, IBM, Microsoft Edge, Oracle, and Apple products. The most critical item is Oracle CVE-2026-46817, which open-source reporting indicates is being actively exploited, affecting Oracle Database Server, E-Business Suite, Communications Unified Assurance, Hospitality OPERA 5, and REST Data Services. Organizations should prioritize patching Oracle products and review all applicable advisories for their environment.
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique Check Point Research identified a DeepSeek-attributed malicious Python Flask sample that transforms a theoretical browser ransomware risk into a practical attack using the File System Access API. The sample, disguised as a Discord avatar AI upscaler named InfernoGrabber v9.0, leverages social engineering to trick users into granting folder-level file access via browser permission prompts. Once access is granted, the web page can enumerate, read, exfiltrate, and encrypt files in the selected directory — all without installing a native payload or exploiting a browser vulnerability. The technique is particularly dangerous on Android where Chrome 132+ exposes the File System Access API to web content, allowing access to high-value photo directories including DCIM.
Yarbo Android/iOS Mobile Application and Cloud Infrastructure (CVE-2026-10557, CVE-2026-7368) Yarbo Android and iOS applications contain hard-coded MQTT credentials (CVE-2026-10557) that, combined with missing cloud authorization controls (CVE-2026-7368), allow attackers to access global robot telemetry and issue unauthorized commands to any device in the fleet.
18th May – Threat Intelligence Report This threat intelligence report highlights a surge in ransomware activity, critical zero-day vulnerabilities in Windows, and the active exploitation of Cisco Catalyst SD-WAN controllers. Additionally, it details emerging AI-driven threats, including malicious Hugging Face repositories and the abuse of AI website generators for phishing, alongside an APT intrusion by FamousSparrow targeting the energy sector.
Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit A supply chain attack compromising the widely-used npm package 'art-template' was discovered delivering the Coruna exploit kit to iOS devices. The injected JavaScript acts as a sophisticated watering hole framework, utilizing extensive anti-bot fingerprinting and WebAssembly memory probes to deliver version-specific WebKit RCE exploits targeting Safari on iOS 11.0 through 17.2.
IT threat evolution in Q1 2026. Mobile statistics In Q1 2026, mobile banking Trojans saw a significant surge, with Mamont variants driving a 50% increase in malicious installation packages. Additionally, a sophisticated new variant of the SparkCat crypto stealer was identified in official app stores, employing custom virtual machines and OCR techniques to compromise both Android and iOS users.
Lookalike Domains Expose the iPhone Theft Economy Infoblox Threat Intel uncovered a thriving underground economy on Telegram dedicated to unlocking stolen iPhones. Threat actors utilize specialized Windows binaries to extract device information and deploy targeted smishing campaigns via Apple lookalike domains to steal iCloud credentials, allowing them to bypass Activation Lock, wipe the device, and resell the hardware.
Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs Threat actors are utilizing Traffic Distribution Systems (TDS) to direct mobile users to fake CAPTCHA pages that trick them into sending premium international SMS messages. This International Revenue Share Fraud (IRSF) scheme leverages social engineering and back button hijacking to generate multiple SMS messages per victim, resulting in significant financial charges.
When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks Researchers have disclosed AirSnitch, a novel set of attack techniques that bypass WPA2 and WPA3-Enterprise Wi-Fi encryption and client isolation. By exploiting vulnerabilities in protocol-infrastructure interactions such as MAC address tables and routing layers, attackers can achieve Meddler-in-the-Middle (MitM) capabilities to intercept and inject traffic across enterprise networks.
Cyber Centre Daily Advisory Digest — 2026-04-02 (2 advisories) The Canadian Centre for Cyber Security issued two security advisories. Apple released extensive updates across its operating systems to mitigate vulnerabilities, specifically targeting web attacks from the DarkSword iOS exploit kit. WatchGuard patched an Arbitrary File Write via Path Traversal vulnerability affecting the Fireware Web UI in multiple versions of Fireware OS.
Intelligence Center The Talos 2025 Year in Review highlights a significant shift towards attackers targeting identity infrastructure and network components to bypass MFA and gain privileged access. Key threats include widespread exploitation of React2Shell, supply chain attacks targeting CI/CD pipelines, and the dominance of Qilin ransomware.
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors Google Threat Intelligence Group discovered DarkSword, a sophisticated iOS full-chain exploit leveraging six zero-day vulnerabilities to target iOS 18.4-18.7 devices. Adopted by multiple state-sponsored actors and commercial surveillance vendors, the pure-JavaScript exploit chain bypasses modern iOS mitigations to deploy data-mining payloads like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER.
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Google Threat Intelligence Group discovered 'Coruna', a highly sophisticated iOS exploit kit containing 23 exploits that target iOS versions 13.0 through 17.2.1. Initially observed in use by a commercial surveillance vendor, the kit has since proliferated to state-sponsored and financially motivated threat actors to deploy PLASMAGRID, a payload designed to steal cryptocurrency wallets and financial data.