San Mateo, CA, February 16, 2026 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
New ZeroDayRAT stalkerware sold openly on Telegram
A new spyware family called ZeroDayRAT is being sold openly on Telegram, bundling surveillance, credential theft, and info-stealing tools for mass-market criminals, according to mobile security vendor iVerify. Delivered through smishing, phishing, and links shared over WhatsApp, the malware supports Android 5–16 and iOS up to 26, giving attackers near-total device visibility, SMS control that can bypass MFA, keylogging, screen recording, microphone access, and banking and crypto theft. Researchers told Dark Reading the toolkit is “textbook stalkerware,” enabling account takeover and targeted social engineering. With entry-level pricing around $2,000, AttackIQ warns that the commoditization of advanced mobile RAT capabilities widens the risk from individuals and SMBs to enterprises through executive targeting and compromised BYOD devices. Read more.
Google says nation-state hackers now rely on LLMs
Many government-backed threat actors are now relying on AI for reconnaissance, targeting, and social engineering, according to a new study from Google Threat Intelligence Group and Google DeepMind. Researchers observed multiple APT groups using generative models for scripting, vulnerability research, OSINT collection, and the creation of phishing lures in late 2025. Iran-linked APT42 used AI to find official email addresses and build credible pretexts, while North Korean actors leveraged Gemini to profile high-value targets. Chinese groups also employed AI to gather detailed intelligence on individuals and organizations. Google also reported rising model extraction attacks, underground jailbreak ecosystems, and AI-enabled malware, including fileless campaigns that dynamically generate malicious code. “For government-backed threat actors, LLMs have become essential tools for technical research, targeting, and the rapid generation of nuanced phishing lures,” the report noted. Read more.
300,000 users install fake AI Chrome extensions
Thirty malicious Google Chrome extensions posing as AI assistants have been installed by more than 300,000 users, according to researchers at LayerX, who dubbed the campaign AiFrame. The add-ons share identical code and infrastructure and quietly load remote iframes instead of providing real AI features, allowing operators to change behavior without updates. A subset of 15 extensions specifically targets Gmail, scraping visible email content, drafts, and thread text at page load, then transmitting it to attacker-controlled servers. Others harvest browsing data and credentials, while others enable remotely triggered voice capture. Despite removals, several extensions remain live in the store. Read more.
Russia blocks WhatsApp and pushes state messaging app
Russian authorities have effectively blocked WhatsApp for as many as 100 million users by removing it from online directories, accelerating a broader crackdown on foreign communication platforms. Parent company Meta said the move is designed to funnel people toward Max, a government-backed, unencrypted WeChat-style app, warning that isolating users from private messaging will “lead to less safety.” The state also deleted Telegram and erased Facebook and Instagram, while YouTube access reportedly degraded. The escalation follows directives from Vladimir Putin to restrict apps from “unfriendly countries,” even as officials admit Telegram slowdowns risk disrupting drone and missile alerts near Ukraine. Read more.
Google hands student journalist data to ICE via admin subpoena
According to The Intercept, Google handed U.S. Immigration and Customs Enforcement account metadata on British student and journalist Amandla Thomas-Johnson after receiving an administrative subpoena that was not judge-approved and reportedly carried a gag order. The data included usernames, addresses, IP and phone details, subscriber identifiers, and credit card and bank numbers linked to his Google account. They were provided shortly after Cornell said his student visa had been revoked following brief attendance at a pro-Palestinian protest in 2024. Agencies issue administrative subpoenas without a judge and cannot demand email contents, searches, or location data, but can seek identifying metadata. The U.S. government has been using them to demand that tech companies hand over private data belonging to individuals critical of the Trump administration. The Electronic Frontier Foundation urged major platforms to refuse and require court confirmation, warning that companies are failing to defend user privacy and free speech. Read more.
North Korean deepfake Zoom calls hit crypto firms
According to researchers at Google Mandiant, North Korean threat actors are escalating financially motivated attacks against the cryptocurrency sector by combining AI-generated deepfake video with the ClickFix social engineering technique. The campaign, attributed to UNC1069, begins with Telegram outreach from compromised executive accounts, followed by a Calendly link that routes victims to a spoofed Zoom page. During the staged meeting, attackers display a deepfake CEO video and claim there are audio issues, instructing victims to execute malicious commands tailored to macOS or Windows. Once triggered, the infection chain deploys seven distinct macOS malware families, including WAVESHAPER, HYPERCALL, HIDDENCALL, SILENCELIFT, DEEPBREATH, SUGARLOADER, and CHROMEPUSH, enabling backdoor access, credential theft, TCC bypass, browser data harvesting, and persistent control. Researchers noted the unusually large malware stack indicates highly targeted operations designed to maximize cryptocurrency theft and harvest victim data for future social engineering. Read more.
Claude desktop flaw enables remote code via calendar invite
A critical vulnerability in Claude Desktop Extensions could allow a single Google Calendar event to trigger remote code execution on a victim’s system silently, LayerX said in a February 9 report. Researchers said the flaw affects roughly 50 Claude DXT extensions and could impact more than 10,000 active users, earning a maximum CVSS score of 10.0. The issue stems from how Claude’s Model Context Protocol chains low-risk data sources, such as calendars, with high-risk actions, such as local code execution, without enforcing security boundaries. LayerX principal researcher Roy Paz said attackers could embed malicious instructions within a calendar entry that Claude would interpret and execute automatically. Paz reported the issue to Anthropic, which declined to fix it, stating it “falls outside our current threat model.” Paz warned, “to unlock the productivity benefits of AI, you need to give these tools deep access to sensitive data.” Read more.
Bing ads funnel victims to Azure-hosted tech support scams
A sophisticated tech support scam used Bing search ads to funnel everyday queries into Azure Blob Storage-hosted fake Microsoft security warnings. Netskope says the campaign hit users at 48 organizations in the U.S., spanning healthcare, manufacturing, and technology, starting February 2, 2026. Searches for terms like “amazon” surfaced malicious sponsored results that forwarded victims to Blob containers with a consistent path, “werrx01USAHTML/index.html,” plus a phone-number parameter. Phone numbers were rotated to keep the scheme alive and active. The pages claimed that users had Trojan spyware infections, putting pressure on them to call. Threat actors then attempted to obtain remote access or to obtain payments. Read more.
SolarWinds Web Help Desk exploited for full domain compromise
Microsoft disclosed that it had observed a multi-stage intrusion exploiting internet-exposed SolarWinds Web Help Desk instances to gain unauthenticated remote code execution. The company said that because “the attacks occurred in December 2025 and on machines vulnerable to both the old and new set of CVEs at the same time, we cannot reliably confirm the exact CVE used to gain an initial foothold.” After access, attackers spawned PowerShell, used BITS to pull payloads, and deployed Zoho ManageEngine components for persistent control. They enumerated domain admins, established reverse SSH and RDP access, attempted virtualized persistence via QEMU, and used DLL side-loading to dump LSASS, with at least one DCSync attack observed. Microsoft warned that a single exposed app can enable full-domain compromise, urging rapid patching, RMM removal, account rotation, and the isolation of affected hosts. Read more.
VoidLink multi-cloud malware shows signs of AI-assisted development
Ontinue has analyzed a Linux-based command-and-control framework called VoidLink, revealing a technically advanced malware implant designed for long-term intrusion across cloud and enterprise environments. The Linux agent targets AWS, Google Cloud Platform, Microsoft Azure, Alibaba Cloud, and Tencent Cloud, fingerprinting each environment to adapt its persistence, stealth, and credential-harvesting techniques. Researchers observed credential theft from cloud metadata APIs, environment variables, Kubernetes secrets and local files, alongside kernel- and container-aware modules for privilege escalation and evasion. Despite its sophistication, Ontinue found indicators suggesting AI-assisted development. Ram Varadarajan of Acalvio said defenders can exploit these traits. “Defenses against modular frameworks, like VoidLink, can be built by deploying AI-aware honeypots that serve as cognitive traps — tripwires — for the AI itself.” Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
