Cyber attacks fuel surge in cargo theft across logistics industry

2026-04-20T02:51:43Z2a3007de86a8288333290dc473415658b3e79873fc9aa1ec1aaa2c7a34b5a57e
BlueHammerDDoSGrinexICSIoT botnetMicrosoft DefenderMiraiNexcoriumQEMURedSunTBK DVRTP‑LinkUnDefendZionSiphon','Operation PowerOFF','law enforcement takedown','DDocargo theftcritical infrastructurecrypto heisthidden VMslogisticsorganized crimeransomwareremote access trojanvirtual machine abusewater systemszero‑day

What happened

Multiple 17–19 April 2026 incidents show escalating cyber threats across logistics, IoT, endpoint, financial and critical‑infrastructure sectors. Proofpoint links coordinated remote‑access campaigns to organized‑crime actors stealing cargo and diverting payments; Sophos reports attackers hiding malware inside QEMU virtual machines to evade detection and deploy ransomware; Fortinet details a Nexcorium Mirai variant exploiting TBK DVR vulnerabilities and EOL TP‑Link routers to build DDoS botnets. A researcher disclosed three Microsoft Defender zero‑days (BlueHammer, RedSun, UnDefend) enabling pr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2a3007de86a8288333290dc473415658b3e79873fc9aa1ec1aaa2c7a34b5a57e
Enrichment time
2026-04-20T02:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.