State-sponsored attackers are systematically weaving AI throughout their entire attack chains and leveraging legitimate cloud services for obfuscation, circumventing traditional security controls.
The rapidly growing Dysphoria botnet uses blockchain-based decentralized domains for C2 obfuscation and has already infected 200,000 devices through exploitation of known CVEs and weak credentials.
Dysphoria replaces centralized C2 infrastructure with blockchain name services and device relays, reducing the effectiveness of law enforcement disruptions.
Golden Chickens MaaS operator continues operations with four new malware families (TinyEgg, ChonkyChicken, modular ChonkyChicken variant, and modified browser credential stealer).
Cybercriminals in Germany increasingly use social engineering and impersonation of legitimate processes instead of pure malware techniques, as the Gen Report shows with increases of 134 percent in fake shop fraud and 160 percent in dropper malware.
Cybercriminals exploit legitimate AI chat sharing features from Claude to trick developers into manually executing malware and stealing corporate login credentials.