XStore Documentation

May 27, 2025 – Cyber Briefing

👉 What’s the latest in the cyber world today?

Luna Moth uses callback phishing on U.S. law firms, Winos 4.0 spreads via fake installers

Listen to the full podcast


🚨 Cyber Alerts

1. FBI Warns Luna Moth Targets US Law Firms

The FBI warned that the Luna Moth extortion group has targeted U.S. law firms for two years. They use callback phishing and spoofed IT support calls to socially engineer employees for remote access. After gaining access via tools like Quick Assist attackers exfiltrate data using Rclone or WinSCP. Luna Moth then demands ransoms not to leak stolen data with the FBI urging improved defenses.

2. Winos 4.0 Malware Spread Via Fake Installers

A malware campaign uses fake software installers like LetsVPN to deliver the Winos 4.0 framework. This is done via Catena, a memory-resident loader that evades antivirus targeting Chinese-speaking users. Winos 4.0 an advanced C++ framework based on Gh0st RAT harvests data and offers remote shell. The campaign shows tactical shifts using NSIS installers reflective DLL injection and Defender exclusions.

3. GhostSpy Android Malware Full Device Control

New Android malware GhostSpy gives attackers full device control using advanced surveillance and evasion techniques. It infects by exploiting Accessibility Services to silently install payloads and gain extensive permissions. GhostSpy steals data like credentials, 2FA codes and files while using anti uninstall and C2 communication. Security experts recommend robust defenses, user education and monitoring to counter this pervasive threat.

For more alerts, click here!

💥 Cyber Incidents

For more incidents, click here!

Click to See Tools

📢 Cyber News

For more news, click here

📈Cyber Stocks

On May 26, 2025, Zscaler rose 0.57%, CrowdStrike Holdings gained 2.61%, Palo Alto Networks increased 0.36%, Fortinet dipped 0.46%, and SentinelOne declined 0.15%.

💡 Cyber Tip

Click to Check Events

Copyright © 2025 CyberMaterial. All Rights Reserved.

Follow CyberMaterial on:

SubstackLinkedInTwitterRedditInstagramFacebookYouTube, and Medium.

Get Help

Online Scam Prevention & Recovery

Schedule a free consultation

A free 15-min cybersecurity consultation