Active HanGhost Loader Campaign Targets Enterprise Payment and Logistics Workflows
2026-04-15T08:51:46Z•4287de3ad6e362ce45ce42493fb5311a93c551d17189ffb6d00e047b915c3ec2
AxiosBITTER APTBooking.comCVE-2026-5194DragonForceHanGhostKrakenOpenAIOpenSSFProSpySlack-malwareToSpyViperTunnelbackdoordata-breach','IoT','routers'filelessinsider-threatloadermacOS-certificatesphishingransomwaresupply-chainupdate-to-5.9.1vulnerabilitywolfSSL
What happened
Multiple active threats and a critical vulnerability: an active HanGhost Loader campaign is conducting fileless, multi-stage attacks targeting enterprise payment and logistics workflows; wolfSSL suffers a critical flaw (CVE-2026-5194) enabling digital ID forgery—update to wolfSSL 5.9.1 immediately; ViperTunnel, a Python backdoor linked to DragonForce ransomware, is targeting Windows servers in the US and UK; BITTER APT is distributing ProSpy/ToSpy via Signal/Google/Zoom lures targeting journalists; OpenSSF warns of Slack-based malware impersonating Linux Foundation figures; OpenAI rotated mac‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 4287de3ad6e362ce45ce42493fb5311a93c551d17189ffb6d00e047b915c3ec2
- Enrichment time
- 2026-04-15T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.