San Mateo, CA, June 9, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
$10 million bounty for RedLine hacker
The U.S. Department of State is offering a reward of up to $10 million for information on foreign government-linked hackers involved in the RedLine infostealer malware operation, particularly its suspected creator, Russian national Maxim Alexandrovich Rudometov. According to the Justice Department, “Rudometov regularly accessed and managed the infrastructure of RedLine Infostealer, was associated with various cryptocurrency accounts used to receive and launder payments, and was in possession of RedLine malware.” Under the Rewards for Justice program, this effort targets those conducting cyberattacks against U.S. critical infrastructure, violating the Computer Fraud and Abuse Act. Rudometov was charged in October after “Operation Magnus,” an international law enforcement action that disrupted RedLine and META malware networks, seized infrastructure, and led to arrests in Belgium. If convicted, he faces up to 35 years in prison. Law enforcement shut down RedLine’s promotional Telegram channels and C2 servers, while cybersecurity firm ESET, which aided the investigation, released a tool for identifying infections. The State Department urges tipsters to use a Tor-based reporting channel to submit information on Rudometov or associated cyber activities. Read more.
NSO Group calls WhatsApp verdict excessive
Spyware vendor NSO Group has filed a motion requesting a new trial or a reduction in the $167 million in damages a jury awarded to WhatsApp over a 2019 hacking campaign that targeted over 1,400 users. NSO Group called the award “outrageous” and “unconstitutionally excessive.” On Thursday, the company filed a motion requesting either a new trial or a legal reduction of the damages. NSO’s lawyers argue the award exceeds legal limits, pointing to the much lower compensatory damages of $444,719 and citing Supreme Court guidance that punitive damages typically should not exceed four times that figure. They also claim the jury acted out of anger toward NSO’s broader activities, making the award “unlawful because it reflects the improper desire to bankrupt NSO out of general hostility toward its business activities other than the limited conduct for which punitive damages could be awarded in this case.” WhatsApp, however, maintains its position, with spokesperson Margarita Franklin stating the platform will continue its legal fight to hold NSO accountable and secure a permanent injunction against future targeting. Read more.
U.S. seizes BidenCash domains and crypto
The U.S. Department of Justice has seized cryptocurrency and around 145 clearnet and dark web domains linked to BidenCash, a notorious criminal marketplace used for trafficking stolen credit cards and personal data. Launched in March 2022, BidenCash facilitated over 15 million compromised card sales and served more than 117,000 customers, earning at least $17 million. The site offered credit card data, including CVVs, addresses, and contact info, and even gave away millions of stolen cards to attract users. It also sold compromised credentials and SSH services, enabling cybercriminals to breach systems, exfiltrate data, conduct ransomware attacks, and mine cryptocurrency. Despite the seizure, officials have not revealed the operators’ identities or the amount of cryptocurrency recovered. The operation was led by the U.S. Secret Service and FBI, with international support from the Dutch Politie, the Shadowserver Foundation, and Searchlight Cyber. Read more.
Fake Booking.com emails infect hotels
A phishing campaign targeting the hospitality industry uses spoofed Booking.com emails to trick hotel staff into downloading malware via a deceptive CAPTCHA system called ClickFix, according to Cofense Intelligence. Active since November 2024 and peaking in March 2025, the campaign sends fake guest requests or confirmations containing links to bogus CAPTCHA pages. These prompt users to copy and execute malicious Windows scripts, which then install RATs such as XWorm, which comprised 53% of observed payloads. Other malware includes Pure Logs Stealer and DanaBot. Recent tactics use urgency, false guest requests, and fake cookie banners to coax interaction. The campaign detects user systems, delivering payloads only to Windows devices. ClickFix’s three-step attack method hides a malicious script in the clipboard and instructs users to run it manually. Read more.
Malware campaign targets GitHub users
A vast malware operation exploiting GitHub has been uncovered by Sophos researchers, focusing on a threat actor using the alias “ischhfd83.” The campaign involved at least 133 backdoored repositories disguised as game cheats, hacking tools, and crypto utilities, designed to lure amateur hackers and gamers. The scheme came to light after analysis of a seemingly broken GitHub project, Sakura RAT, revealed a covert malware downloader. Further investigation linked the malware to a larger network of automated, deceptive repositories maintained using GitHub Actions and filled with thousands of bogus commits. The backdoors were often hidden in “layers of obfuscated code across formats, including PowerShell, Python, JavaScript and Windows screensavers,” ultimately delivering payloads such as Lumma Stealer and AsyncRAT. Sophos believes the operation may connect to a larger Distribution-as-a-Service model noted in 2024. While the targets were primarily novice threat actors, researchers warn that the risks extend to curious users and open-source supply chains. Read more.
Coinbase sat on data breach for months
Coinbase reportedly knew about its customers’ data leak as early as January 2025, four months before a major breach came to light following an extortion attempt in May. According to filings and insider accounts, the company was aware that hackers had accessed employee information “without work necessity” months earlier but failed to link it to a broader security issue until the ransom demand. The breach appears to have stemmed from Coinbase’s outsourcing partner, TaskUs, where an Indore, India, employee was caught photographing customer data on her work screen. Former TaskUs staff claim Coinbase was informed of the incident immediately, triggering an internal probe and the firing of over 200 employees. TaskUs confirmed that two staff members were let go earlier in the year for unauthorized data access. They suggested the breach was part of a larger criminal scheme targeting multiple service providers. Coinbase has since sued TaskUs, but its January awareness of the breach raises new questions about the company’s delay in disclosing the potential $400 million compromise. Read more.
Trump budget plan slashes CISA funding
President Donald Trump’s proposed fiscal year 2026 budget would slash nearly $500 million from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), cutting almost 1,000 positions and significantly reducing the agency’s operational scope. The plan aims to reorient CISA toward protecting federal networks and critical infrastructure while eliminating programs the administration claims were politically weaponized. Key divisions, including Stakeholder Engagement and the National Risk Management Center, face deep funding reductions of up to 73 percent. Critics warn the cuts undermine national cyber defense at a time when threats are accelerating. Experts argue the proposal erodes essential collaboration and resilience functions and question the rationale of eliminating election security funding. Read more.
Microsoft, CrowdStrike sync threat names
CrowdStrike and Microsoft announced a new collaboration to formally align on the names they use for threat groups. This addresses a longstanding issue in the cybersecurity community where different vendors assign multiple aliases to the same bad actors. While not establishing a universal naming standard, the initiative aims to reduce confusion by clarifying overlaps between groups tracked by different companies. The effort, which is already supported by Mandiant and Palo Alto Networks’ Unit 42, is intended to streamline attribution, quicken defensive responses, and reduce blind spots. By mapping over 80 threat groups and their aliases, Microsoft and CrowdStrike hope to improve consistency and speed in cyber threat identification. Despite this progress, experts caution that complete standardization is unlikely due to competing business interests and analytic independence. Read more.
Acreed fills gap left by Lumma Stealer
According to findings from ReliaQuest, Lumma Stealer’s May 2025 takedown has left a vacuum that has allowed a competitor to rise in popularity. Acreed is now the go-to info stealer, beating out other established, popular strains such as RedLine, Raccoon, StealC, and Vidar. ReliaQuest came to this conclusion after studying Russian Market, “one of the most popular platforms for selling and buying stolen credentials on the dark web.” Russian Market has outlived or outperformed other forums in the cybercrime space that offer similar features and information. While Lumma Stealer accounted for almost 92% of Russian Market credential alerts in the fourth quarter of 2024, the seizure of more than 2,300 associated domains means that other stealer providers are vying for the top position. Read more.
U.S. shuts down crypting service domains
The U.S. Department of Justice (DoJ) has reported that it has seized four domains and a server used to provide crypting services that let threat actors’ malicious software remain undetected. The operation was conducted with Dutch and Finnish authorities, with additional participation from France, Germany, Denmark, Portugal, and Ukraine. “Crypting is the process of using software to make malware difficult for antivirus programs to detect,” the DoJ said. “The seized domains offered services to cybercriminals, including counter-antivirus (CAV) tools. When used together, CAV and crypting services allow criminals to obfuscate malware, making it undetectable and enabling unauthorized access to computer systems.” The domains are AvCheck.net, Cryptor.biz, and Crypt.guru, all of which now display seizure notices on their landing pages. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, which built and re-architected data centers for Fortune 500 firms, NetworkTigers provides consulting and network equipment to global governmental agencies, Fortune 2000, and healthcare companies. www.networktigers.com.
