In June, Terend Micro researchers identified and investigated an unusual security incident involving the installation of two malware families, C6DOOR and GTELAM, on a victim’s host. Trend Micro investigation determined that the malware was delivered through a legitimate input method editor (IME) software, Sogou Zhuyin.
As brief explanation, an IME is a tool that interprets sequences of keystrokes into complex characters for languages not suited to a standard QWERTY keyboard (like many East Asian languages). The software had stopped receiving updates in 2019; in October 2024 attackers took over the lapsed domain name and used it to distribute malicious payloads. Telemetry data indicates that at least several hundred victims were affected, with infections leading to additional post-exploitation activities.
Read more…
Source: Trend Micro
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- FBI, Coast Guard boarded hacked oil tankers heading toward US coast
September 18, 2026
Cybersecurity teams with the U.S. Coast Guard and the FBI boarded two U.S.-bound oil tankers last month after hackers reportedly compromised at least one of the ship’s networks and took control of its navigation, propulsion, and cargo systems. According to a joint statement shared with TechCrunch, the agencies boarded the vessels in the Gulf of Mexico ...
- Fake parcel delivery messages steal your card and bank details
September 18, 2026
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The ...
- Atomic macOS (AMOS) Stealer Activity
September 16, 2026
This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer. AMOS stealer is an information ...
- NightEagle targets Russian companies
September 16, 2026
Over the past year, Kaspersky Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia. Kaspersky researchers have now identified attacks by the group targeting businesses in Russia. This post examines both known and new ...
- Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
September 16, 2026
The ShinyHunters hacking group has published hundreds of thousands of files from a Florida state database of vehicles and driver information. The hackers said they published the stolen data on its leak site “because the victim did not pay a ransom or cooperate and comply” with the hackers’ demands. The hackers said they breached the database, ...
- CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
September 15, 2026
On September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure ...
