Active HanGhost Loader Campaign Targets Enterprise Payment and Logistics Workflows

2026-04-15T08:51:46Z4287de3ad6e362ce45ce42493fb5311a93c551d17189ffb6d00e047b915c3ec2
AxiosBITTER APTBooking.comCVE-2026-5194DragonForceHanGhostKrakenOpenAIOpenSSFProSpySlack-malwareToSpyViperTunnelbackdoordata-breach','IoT','routers'filelessinsider-threatloadermacOS-certificatesphishingransomwaresupply-chainupdate-to-5.9.1vulnerabilitywolfSSL

What happened

Multiple active threats and a critical vulnerability: an active HanGhost Loader campaign is conducting fileless, multi-stage attacks targeting enterprise payment and logistics workflows; wolfSSL suffers a critical flaw (CVE-2026-5194) enabling digital ID forgery—update to wolfSSL 5.9.1 immediately; ViperTunnel, a Python backdoor linked to DragonForce ransomware, is targeting Windows servers in the US and UK; BITTER APT is distributing ProSpy/ToSpy via Signal/Google/Zoom lures targeting journalists; OpenSSF warns of Slack-based malware impersonating Linux Foundation figures; OpenAI rotated mac‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
4287de3ad6e362ce45ce42493fb5311a93c551d17189ffb6d00e047b915c3ec2
Enrichment time
2026-04-15T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.