CYFIRMA

CYFIRMA Research

News EN ↓ 322 episodes

Cyber defenders, listen up! The CYFIRMA Research podcast has some juicy intel on the latest cyber threats that are lurking in the shadows. Tune in to this security briefing to stay on top of emerging threats and be ready to tackle digital risk like never before.

Author

CYFIRMA

Category

News

Podcast website

www.cyfirma.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

CYFIRMA Research: DuplexSpy RAT- A Stealthy Windows Malware Enabling Full Remote Control and Surveillance 11.06.2025

A highly modular Windows Remote Access Trojan (RAT), DuplexSpy, written in C#, has surfaced with advanced surveillance and system control capabilities. Features include keylogging, remote shell access, screen & webcam spying, audio eavesdropping, and live C2 chat.  It uses fileless execution, UAC bypass, registry persistence, and DLL injection to evade detection.  Logs keystrokes in real time,...

CYFIRMA Research: Firewalls and Frontlines- The India-Pakistan Cyber Battlefield Crisis 06.06.2025

As tensions between India and Pakistan escalated in early 2025, the conflict spilled into cyberspace. In the wake of the April 22nd Kashmir attack and India’s Operation Sindoor, dozens of hacktivist groups launched a wave of digital assaults — from DDoS attacks and defacements to claimed data breaches — targeting critical infrastructure and government entities on both sides. While the technical im...

CYFIRMA Research- Versa Concerto: Understanding and Mitigating CVE-2025-34027 04.06.2025

Critical Alert: CVE-2025-34027 – Authentication Bypass + RCE in Versa Concerto!   Organizations using Versa Concerto for network orchestration must take immediate action. This newly disclosed vulnerability allows unauthenticated attackers to bypass login mechanisms and gain remote code execution through exposed REST APIs. The flaw affects key authentication flows, exposing internal configurations...

CYFIRMA Research- Lyrix Ransomware 03.06.2025

A new ransomware! Lyrix Ransomware targets Windows systems, encrypting files and appending random 10-character extensions. Victims receive a README.txt ransom note demanding payment, threatening to leak stolen data.   Strengthen robust defenses & comprehensive incident response now!   Link to the Research Report : https://www.cyfirma.com/research/lyrix-ransomware/ #LyrixRansomware   #CYFIRMA  ...

CYFIRMA Research- While Trump Disrupts World Order China Prepares for War Over Taiwan 29.05.2025

Read CYFIRMA’s latest geo-political analysis, regarding Trump’s continued disruption of the world order, calling U.S. alliances into question while an emboldened China prepares for war over Taiwan. Link to the Research Report : https://www.cyfirma.com/research/while-trump-disrupts-the-world-order-china-prepares-for-war-over-taiwan/ #Geopolitics   #CYFIRMAResearch   #ThreatIntelligence   #cybersecu...

CYFIRMA Research: GhostSpy- Web-Based Android RAT 23.05.2025

A high-risk Android malware poses a serious threat by targeting banking apps, bypassing screenshot protections through UI reconstruction to steal sensitive financial data. It records live screen activity, captures video, and audio in real time, SMS, Contacts, Call logs, files and silently auto-grants all permissions. Once installed, it takes full control of the device, monitoring every action whil...

CYFIRMA Research- Tracking Ransomware: April 2025 16.05.2025

Stay ahead of evolving ransomware threats with CYFIRMA’s April 2025 Ransomware Report. Last month revealed shifting dynamics—Qilin surged by 71%, while Play and DragonForce increased by 75% and 25% respectively. Despite a 29% drop in total incidents from March, the Manufacturing, IT, and Consumer sectors remained heavily targeted. The U.S. topped the victim chart, followed by the UK and Canada. Ne...

CYFIRMA Research- PupkinStealer : A .NET-Based Info-Stealer 12.05.2025

CYFIRMA’s latest threat report reveals the workings of PupkinStealer, a .NET-based information stealer designed to extract a focused set of sensitive data from victim systems. Targeting browser credentials, desktop files, Telegram and Discord sessions, and screenshots, the malware compresses all stolen content into a ZIP archive and exfiltrates it using the Telegram Bot API, making attribution and...

CYFIRMA Research- EXPLAINER: THE ALGERIA / MOROCCO TENSIONS 09.05.2025

Geopolitical tensions between Algeria and Morocco have reignited over the Western Sahara issue. Hacktivist groups have exacerbated the situation by targeting each other’s critical infrastructure. Algerian hacktivists claimed to have breached Morocco's CNSS, while Moroccan hacktivists alleged, they had hacked and leaked data from Algeria's MGPTT. However, such claims often prove to involv...

CYFIRMA Research- Gunra Ransomware 06.05.2025

A new threat is on the rise - Gunra Ransomware. This sophisticated ransomware not only encrypts files but also exfiltrates sensitive data, threatening to leak the data unless the ransom is paid. Read the latest report from the CYFIRMA research team to learn more! Stay informed and safeguard your systems!  Link to the Research Report: https://www.cyfirma.com/research/gunra-ransomware-a-brief-analys...

CYFIRMA Research- US MANUFACTURING RELOCATION AND THREATS 05.05.2025

Donald Trump’s new tariff promises to revive American manufacturing, but evidence shows they are more likely to raise prices, reduce competitiveness, deter investment, and fuel geopolitical instability. The vision of millions of factory jobs ignores automation, labor shortages, and global supply chains. Instead of revitalizing the industry, tariffs risk slowing growth and driving inflation, puttin...

CYFIRMA Research- Hannibal Stealer: A Rebranded Threat Born from Sharp and TX Lineage 30.04.2025

Read CYFIRMA’s report on the Hannibal Stealer, a rebranded variant of SHARP and TX Stealers, which has re-emerged with expanded data exfiltration capabilities and an updated command-and-control infrastructure. Hannibal Stealer is built in C# on the .NET framework. It targets a wide range of data sources, including browsers, cryptocurrency wallets, VPN configurations, FTP credentials, and system in...

CYFIRMA Research- Technical Malware Analysis Report: Python-based RAT Malware 29.04.2025

A New Breed of Python-Based RATs is Abusing Discord for C2   The CYFIRMA research team has investigated an emerging class of Python malware that is turning popular platforms into weaponized control panels. One recent variant showcases just how accessible and disruptive these tools have become.   This lightweight Remote Access Trojan (RAT) uses Discord bots and interactive UI buttons to control inf...

CYFIRMA Research- Scamonomics: The Dark Side of Stock & Crypto Investments in India 23.04.2025

Cybercriminals are impersonating trusted business executives and financial experts to trap unsuspecting investors. These scammers are creating fake investment firms with fraudulent registration details, professional-looking websites and manipulated social media engagement to appear legitimate. They are actively using Telegram channels, WhatsApp groups, and fake company domains to lure victims.   M...

CYFIRMA Research: Cyber Espionage Among Allies- Strategic Posturing in an Era of Trade Tensions 22.04.2025

The CYFIRMA research team provides a comprehensive analysis of how diplomacy, defense, and digital strategy are colliding: As trade friction intensifies especially under the 2025 U.S. tariff regime, cyberspace is becoming the frontier of quiet competition between traditional allies. While full-scale cyber warfare remains unlikely, behind-the-scenes intelligence gathering is rising fast. Our latest...

CYFIRMA Research- Tik-Tok: China’s Digital Weapon System? 22.04.2025

U.S. President Donald Trump, once a critic but now a supporter of TikTok, is granting the app’s China-based parent company, ByteDance, a second 75-day extension to finalize a deal that would transfer ownership of TikTok to an American entity. While the legislation allowed only one extension for a sale, the U.S. Congress has yet to push back against Trump’s decision to offer another. However, the m...

CYFIRMA Research- Tracking Ransomware: March 2025 21.04.2025

Stay ahead of evolving ransomware threats with CYFIRMA’s Monthly Ransomware Report – March 2025.  The month of March saw shifting dynamics, with Safepay experiencing a huge surge of 223%, while RansomHub and Akira declined. Babuk2 has possibly leveraged fake extortion claims. Manufacturing, IT, and Consumer sectors remained prime targets as total incidents dropped 30.7% from February. The U.S. led...

CYFIRMA Research- The Neptune RAT 15.04.2025

CYFIRMA researchers have identified a dangerous new version of Neptune RAT being actively shared online. This malware spreads through GitHub, Telegram, and YouTube, often advertised as the "Most Advanced RAT." The attack starts when victims run malicious PowerShell commands. First, the "irm" command downloads harmful code from the file hosting website. Then "iex" exec...

CYFIRMA Research- Analysis of Konni RAT: Stealth, Persistence, and Anti-Analysis Techniques 01.04.2025

CYFIRMA’s research team has conducted an in-depth investigation into Konni RAT,  a sophisticated remote access trojan (RAT) that uses advanced evasion techniques to bypass detection. It exploits Windows features, such as file extension hiding and the 260-character limit for LNK files, to conceal malicious activity. After gaining access, Konni RAT maintains persistence through registry modification...

CYFIRMA Research- ANALYSIS OF A DISCORD-BASED REMOTE ACCESS TROJAN (RAT) 31.03.2025

Hackers are leveraging Python-based Discord RATs to exploit Discord’s API as a Command and Control (C2) platform. This sophisticated malware allows attackers to gain complete control over compromised systems, making it a serious cybersecurity risk. Steals credentials from browsers Execute remote system commands Capture live screenshots for surveillance Manipulate Discord servers for persistence Wi...

CYFIRMA Research: Turning Aid into Attack- Exploitation of Pakistan's Youth Laptop Scheme to Target India 28.03.2025

The CYFIRMA research team has identified a fake Indian Post Office website leveraging the Clickfix technique to target Indian users. The report details how a Pakistani threat actor is targeting both Windows and Android users by dropping APK files for Android devices, copying PowerShell commands to the clipboard, and dropping Clickfix instructions pdf file. Link to the Research Report: https://www....

CYFIRMA Research- CVE-2025-24813: Apache Tomcat RCE Vulnerability Analysis 25.03.2025

Critical Alert: Immediate action is required for all organizations using Apache Tomcat! CVE-2025-24813 is a critical Remote Code Execution (RCE) vulnerability that allows attackers to bypass security controls via a path equivalence flaw, leading to arbitrary code execution. Active exploitation has been observed, with public PoC exploits available, increasing the urgency for mitigation. Given Tomca...

CYFIRMA Research- Tracking ransomware: February 2025 20.03.2025

Stay ahead of evolving ransomware threats with CYFIRMA’s Monthly Ransomware Report – February 2025. Ransomware activity surged by 87.45% in February month, with Cl0p witnessing an alarming 453% rise. Manufacturing, FMCG, and Transportation sectors faced the highest spike in attacks. The U.S. remained the top target, followed by Canada, the U.K., Germany, and France. Notably, China-linked actors ex...

CYFIRMA Research- Geopolitical Conflicts and The Unpredictable Nature of Hacktivist Operations 19.03.2025

Hacktivists often become active participants in cyber conflicts whenever geopolitical tensions arise. This has been evident during events like the Israel-Palestine conflict and the Russia-Ukraine war. Recently, tensions flared between Malaysia and Indonesia following the death of a migrant worker attempting to cross the Malaysian border with four others. This incident sparked public outrage agains...

CYFIRMA Research- LithiumWare Ransomware 11.03.2025

The CYFIRMA research has identified a new ransomware variant named LithiumWare, showcasing advanced capabilities designed to disrupt, encrypt, and steal.  Key Features of LithiumWare: Data Theft: Exhibits activities indicative of stealing personal data, including detecting crypto-addresses. Persistence: Creates files in the startup directory, manipulates desktop.ini for cloaking, and executes serv...

Listen to the CYFIRMA Research podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.