Cyber attacks fuel surge in cargo theft across logistics industry
2026-04-20T02:51:43Z•2a3007de86a8288333290dc473415658b3e79873fc9aa1ec1aaa2c7a34b5a57e
BlueHammerDDoSGrinexICSIoT botnetMicrosoft DefenderMiraiNexcoriumQEMURedSunTBK DVRTP‑LinkUnDefendZionSiphon','Operation PowerOFF','law enforcement takedown','DDocargo theftcritical infrastructurecrypto heisthidden VMslogisticsorganized crimeransomwareremote access trojanvirtual machine abusewater systemszero‑day
What happened
Multiple 17–19 April 2026 incidents show escalating cyber threats across logistics, IoT, endpoint, financial and critical‑infrastructure sectors. Proofpoint links coordinated remote‑access campaigns to organized‑crime actors stealing cargo and diverting payments; Sophos reports attackers hiding malware inside QEMU virtual machines to evade detection and deploy ransomware; Fortinet details a Nexcorium Mirai variant exploiting TBK DVR vulnerabilities and EOL TP‑Link routers to build DDoS botnets. A researcher disclosed three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) enabling pr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2a3007de86a8288333290dc473415658b3e79873fc9aa1ec1aaa2c7a34b5a57e
- Enrichment time
- 2026-04-20T02:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.