San Mateo, CA, April 6, 2026 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
ISO lures fuel stealth crypto-mining campaign
Elastic Security Labs says financially motivated threat operation REF1695 has used fake installers since November 2023 to infect victims with RATs, crypto miners, and a new .NET implant called CNB Bot. The campaign relies on ISO files, Defender SmartScreen bypass instructions, and a protected loader that launches PowerShell to create broad antivirus exclusions before deploying malware in the background. Researchers said the group also monetizes infections through CPA fraud by pushing victims to content-locker pages that pose as software registration. Other observed payloads include PureRAT, PureMiner, XMRig loaders, and SilentCryptoMiner, with some campaigns abusing vulnerable signed drivers to tune CPUs for higher mining performance. Elastic added that the actor uses GitHub as a delivery CDN and has earned steady returns across tracked Monero wallets. Read more.
Apple rushes wider patch to shut down DarkSword exploit chain
Apple has expanded iOS 18.7.7 and iPadOS 18.7.7 to more devices, an atypical move that brings backported security patches to users still running iOS 18 that remain exposed to the DarkSword exploit chain. First identified in active attacks in November 2025, DarkSword targets devices running iOS 18.4 through 18.7 by exploiting a six-bug chain affecting JavaScriptCore, dyld, and the iOS sandbox, enabling full kernel-level code execution after a single website visit. Researchers said the toolkit can steal passwords, messages, browser history, location data, cryptocurrency wallet contents, and Apple Health data before erasing its tracks. Apple’s broadening of the update is in response to the exploit kit leaking on GitHub in March 2026. The patch also fixes 20+ vulnerabilities spanning critical system components. Read more.
Akira ransomware completes all stages of attack in under one hour
Security researchers say the Akira threat group has pushed ransomware operations into a faster and more dangerous phase, with an observed attack moving from initial access to data theft and encryption in less than an hour. Halcyon researchers said the group often breaks in through exposed VPN appliances and backup systems, especially where multi-factor authentication is missing. However, it has also used phishing, password spraying, stolen credentials, and access brokers. Once inside, Akira exfiltrates data, disables security tools, and relies on common legitimate utilities such as FileZilla, WinRAR, WinSCP, and RClone to stage and encrypt files while avoiding detection. Halcyon said the group’s stealth, disciplined pace, and intermittent encryption techniques help it maximize damage quickly. U.S. officials say Akira has generated up to $244 million since March 2023. Read more.
FBI flags hidden data risks in foreign-built mobile apps
The FBI is warning Americans that foreign-developed mobile apps, especially those built by Chinese companies, may pose privacy and security risks because developers operating digital infrastructure in China are subject to the country’s national security laws. In a public service announcement issued through the Internet Crime Complaint Center, the bureau said some apps may keep collecting data even when users think access is limited. In contrast, others gather extensive information by default, including contacts, phone numbers, email addresses, user IDs, and physical addresses. The FBI said some privacy policies disclose that personal data and system prompts may be stored on servers in China for as long as developers want. It urged users to limit sharing, update devices, use official app stores, and report suspicious activity. Read more.
Fake WhatsApp app used as spyware delivery tool
WhatsApp said it notified about 200 users, mostly in Italy, who were tricked into installing a fake iPhone version of the messaging app that contained spyware. The company said it logged the users out, warned them about the privacy and security risks, and urged them to delete the malicious client and install the official app instead. WhatsApp accused Italian spyware maker SIO of creating the fake app and said it will “send a formal legal demand to stop any such malicious activity to this spyware firm.” The disclosure adds to mounting scrutiny of SIO, which has been linked to malicious Android apps that carry the spyware known as Spyrtacus. The case also follows WhatsApp’s notifications last year to 90 users targeted with Paragon spyware in Italy and beyond. Read more.
DDrift hack drains millions and freezes platform activity
Drift Protocol said Wednesday it was “experiencing an active attack” and halted deposits and withdrawals as multiple security firms worked with the company to contain the breach. Estimates of the stolen cryptocurrency varied widely, with PeckShield putting losses above $285 million and other firms seeing at least $130 million siphoned from the Solana-based decentralized finance platform. Drift did not comment on the size of the theft, but according to investigators, the attacker was rapidly converting the funds into other coins, which complicated tracing efforts. The incident would rank as the largest crypto theft of 2026 so far and adds to a grim backdrop for the sector after Chainalysis tracked $3.4 billion in crypto theft losses last year. Questions currently remain about how the attacker breached Drift. Read more.
Iran-linked hackers claim breach of FBI director’s email
Iran-linked hacking group Handala said it breached the personal Gmail account of FBI Director Kash Patel and published a cache of files that appear to come from it, along with photos of a younger Patel. The FBI said it is aware of malicious actors targeting Patel’s personal email information, has taken steps to mitigate risks, and described the exposed material as historical and unrelated to government information. TechCrunch reported that it verified at least some of the leaked emails by checking message headers and cryptographic signatures, which strongly suggests portions of the cache are authentic. The FBI said that “the information in question is historical in nature and involves no government information” and is offering up to $10 million in exchange for information related to Handala. Read more.
Google Drive adds AI-powered ransomware detection and rollback
Google is rolling out an upgraded ransomware detection and recovery system in Drive to all users, expanding a feature that had been in beta since late 2025. The company said its improved AI model can detect up to 14 times more ransomware-related behavior than earlier versions and will automatically pause syncing when suspicious activity is detected, helping prevent infected files from spreading across devices or shared accounts. Users receive real-time alerts, and collaborators in shared folders may also get email notifications. Google has also added built-in recovery through Drive version history, allowing users to restore clean file versions after an attack and reduce downtime. The protection is enabled by default for users on Google Drive version 114 or later, though sensitivity settings can still be adjusted manually. Read more.
Apple targets ClickFix scams with new Terminal warning
Apple has added a new safeguard in macOS Tahoe 26.4 that warns users before potentially dangerous pasted commands execute in Terminal, a move aimed at slowing ClickFix-style social engineering attacks. Because ClickFix relies on victims pasting commands themselves, it can sidestep many traditional protections and deliver malware under the guise of a fix or verification step. The new macOS behavior pauses execution, tells users that no harm has been done, and warns that scammers often share risky instructions via websites and messages. Users can still proceed, but only if they understand the command. Apple has not documented how the feature decides what is dangerous, and some early user reports suggest warnings may appear only once per session or only for certain commands. Read more.
DeepLoad malware blends AI obfuscation with persistent access
A newly detailed malware campaign, DeepLoad, pairs ClickFix social engineering with AI-assisted code obfuscation to steal enterprise credentials and maintain access even after removal attempts. ReliaQuest said the malware poses an “immediate” threat because it hides its payload within large volumes of meaningless variable assignments, likely generated by AI, to frustrate file-based detection. The campaign also blends into normal Windows activity by running inside a lock screen process. It uses WMI abuse to quietly restore itself three days after an initial payload is removed. Researchers also found signs that DeepLoad can spread through USB drives, widening the risk to additional systems. ReliaQuest warned defenders should expect fast iteration and recommended PowerShell Script Block Logging, WMI audits, and password resets after infection. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
