Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
2026-05-28T20:51:56Z•562d94e5bdf39e024bccb13006310bc6b4754d589e1e91fc0e6c97be2220b52e
AppleSeedCVE-2025-68670CVE-2026-3102Cloud AtlasEDR killerExifToolKimsukyLinux","IoT","mobileOceanLotusPebbleDashPowerCloudPyPI supply chainRATReverseSocksSSHSparkCatTorTriadaWindowsZiChatBotdata leak extortionmacOSminerransomwarexrdp
What happened
Kaspersky Securelist roundup (May 2026) covering multiple high‑priority findings: an ExifTool flaw (CVE-2026-3102) that enables macOS compromise via a malicious image; discovery of a pre-auth RCE in xrdp (CVE-2025-68670); Cloud Atlas APT activity in late 2025/early 2026 using ReverseSocks, SSH, Tor and a new PowerCloud payload against Russian and Belarusian public/diplomatic targets; OceanLotus PyPI supply‑chain drops delivering ZiChatBot to Windows and Linux; Kimsuky using PebbleDash tools linked to the AppleSeed cluster; consumer‑focused campaigns distributing miners (now with a RAT module)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 562d94e5bdf39e024bccb13006310bc6b4754d589e1e91fc0e6c97be2220b52e
- Enrichment time
- 2026-05-28T20:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.