JavaGhost’s Persistent Phishing Attacks From the Cloud


Unit 42 researchers have observed phishing activity that we track as TGR-UNK-0011. They assess with high confidence that this cluster overlaps with the threat actor group JavaGhost.

The threat actor group JavaGhost has been active for over five years and continues to target cloud environments to send out phishing campaigns to unsuspecting targets. According to website defacement lists such as DefacerID, the group focused historically on defacing websites. However, according to our telemetry, in 2022, they pivoted to sending out phishing emails for financial gain. Between 2022-24, Unit 42 has performed multiple investigations relating to the group JavaGhost, which targeted organizations’ AWS environments. The group focuses on sending phishing campaigns and has not been seen stealing data for extortion during their time in organizations’ AWS environments.

Read more…
Source: Palo Alto Unit 42


Sign up for our Newsletter


Related:

  • ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 14, 2026

    If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware. These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a ...

  • OpenAI’s malicious bot swarm attacked RubyGems

    September 14, 2026

    OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior. A swarm of agents began uploading malware to the Ruby package registry on May 5, and flooded RubyGems with more than 2,000 malicious packages between May ...

  • Revolut confirms customer data breach through fake government requests

    September 12, 2026

    British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including ...

  • The modern bank heist is already under way

    September 11, 2026

    The image of the bank robber is hopelessly outdated. Today’s heist does not begin with a getaway car outside a branch. It begins quietly, with an adversary establishing persistence inside a financial institution’s network and studying how the organisation responds, says Tom Kellermann, VP of AI Security and Threat Research at Trend AI. The objective is no longer ...

  • A new Android attack combines malware and ransomware in a cocktail of cybercrime

    September 11, 2026

    Unique malware variant spotted targeting Android users. When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. Rarely do we see all of these functionalities merged into a single entity, and even rarer – to have it target Android ...

  • ShinyHunters expose 6.4M in attack on medical supplier McKesson

    September 10, 2026

    McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP ...