HackMyIP
← Back to News
2026-07-30 The Hacker News

Weekly Cyber Threats: XWorm Phishing, GenieLocker Ransomware, CastleLoader Surge

MalwareRansomwarePhishing

Threat actors continue refining their tradecraft this week, blending social engineering with multi-stage loaders to compromise organizations across manufacturing, finance, and retail sectors. The cybercrime group xplogs22, active since November 2023, has been observed targeting Russia and CIS countries with phishing campaigns delivering the XWorm remote access trojan. The group previously relied on Formbook and Snake Keylogger before pivoting to XWorm around July 2025. In parallel, Russian banking customers are facing LunaSpy, an Android trojan disguised as an antivirus app that captures camera streams, records audio, harvests screen content, and exfiltrates sensitive data. Users concerned about credential exposure can verify their accounts via our email breach checker to determine whether harvested data has surfaced in known leaks.

The financially motivated extortion group Toy Ghouls (tracked as Bearlyfy and Labubu) has been deploying GenieLocker, a custom ransomware family, against Russian organizations in manufacturing, financial services, retail, and technology verticals since March 2026. According to Kaspersky, the group previously operated using third-party encryptors including RedAlert, LockBit, and Babuk before developing GenieLocker to reduce external dependencies. Initial access in at least one incident was achieved through an OpenVPN connection originating from a compromised external partner, allowing lateral movement via RDP and SSH across both Windows and Linux hosts. Attackers terminated active VMs on ESXi servers and encrypted disk contents using an ELF variant of GenieLocker. Organizations should audit VPN trust relationships and enforce strong, unique credentials through our password checker to prevent reuse-based pivots.

CastleLoader, a malware loader previously tied to CastleStealer and a Python-based RAT, has resurfaced delivering Needle Stealer through ClickFix-style social engineering lures. The evolution from credential stealers to dedicated loader infrastructure signals growing commoditization in initial-access marketplaces. Defenders should scrutinize installer prompts and verification flows, while hardening browser environments with our browser fingerprint test to identify tracking artifacts that may indicate prior reconnaissance activity against targeted employees.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →DNS Leak Test →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →