ZCyberNews
中文

#backdoor

11 articles

This archive collects 13 articles tagged backdoor published between April 13, 2026 and May 14, 2026, giving security teams a focused view of how this topic has appeared across ZCyberNews coverage. Observed actor references include Silver Fox, APT41, and Harvester, presented only where the underlying article metadata supports the attribution. The affected-scope signals emphasize government, technology, and financial services across Global, India, and Russia, helping readers compare exposure patterns without adding claims beyond the archive data. Severity coverage includes 2 critical, and 11 high reports.

Silver Fox Deploys ABCDoor Malware via Tax-Themed PhishingHIGH
Threat Intel

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing

China-linked Silver Fox group targets Indian and Russian organizations with ABCDoor backdoor via tax-themed phishing emails in December 2025 campaign.

2 min readSilver Fox
Silver Fox Targets Russia, India With ABCDoor BackdoorHIGH
Malware

Silver Fox Targets Russia, India With ABCDoor Backdoor

Silver Fox group impersonates tax authorities to deliver ValleyRAT and the new ABCDoor backdoor to organizations in Russia and India, per Kaspersky.

2 min readSilver Fox
FIRESTARTER Backdoor Compromised Federal Cisco Firepower DeviceHIGH
Threat Intel

FIRESTARTER Backdoor Compromised Federal Cisco Firepower Device

CISA revealed FIRESTARTER backdoor compromised a federal Cisco Firepower device running ASA software in September 2025, surviving patching and enabling persistent remote access.

2 min read
Harvester Deploys Linux GoGra Backdoor via Microsoft Graph APIHIGH
Malware

Harvester Deploys Linux GoGra Backdoor via Microsoft Graph API

The Harvester threat actor deploys a new Linux version of its GoGra backdoor, using Microsoft Graph API and Outlook mailboxes for stealthy C2 communication in attacks targeting…

2 min readHarvester
Mustang Panda Deploys New LOTUSLITE Variant Targeting Indian BanksHIGH
Threat Intel

Mustang Panda Deploys New LOTUSLITE Variant Targeting Indian Banks

Mustang Panda's new LOTUSLITE variant targets Indian banks and South Korean policy circles via a dynamic DNS C2 over HTTPS, enabling remote shell access and file theft.

3 min readMustang Panda
WordPress Supply Chain Attack Infects 30+ Plugins Planted Malicous Backdoor CRITICAL
Threat Intel

WordPress Supply Chain Attack Infects 30+ Plugins Planted Malicous Backdoor

A malicious buyer used the Flippa marketplace to acquire a plugin developer, injecting a backdoor into over 30 WordPress plugins with hundreds of thousands of installations to deploy hidden SEO spam.

6 min read
EssentialPlugin WordPress Suite Compromised to Deploy Backdoor on Thousands ofHIGH
Malware

EssentialPlugin WordPress Suite Compromised to Deploy Backdoor on Thousands of

The EssentialPlugin suite, comprising over 30 popular WordPress plugins, has been compromised to inject a backdoor granting attackers administrative access to thousands of websites. The supply chain attack is actively being exploited.

4 min read
WordPress Plugin Supply Chain Attack Deploys Backdoor After 8-Month DormancyHIGH
Threat Intel

WordPress Plugin Supply Chain Attack Deploys Backdoor After 8-Month Dormancy

A threat actor purchased a legitimate WordPress plugin business and hid a backdoor in updates for eight months before activating it, compromising thousands of sites in a sophisticated supply chain attack.

4 min read
VIPERTUNNEL Python Backdoor Evades Detection via Fake DLL and Obfuscated LoaderHIGH
Malware

VIPERTUNNEL Python Backdoor Evades Detection via Fake DLL and Obfuscated Loader

Threat actors deploy VIPERTUNNEL, a Python backdoor, using a fake DLL and multi-stage obfuscated loader to establish stealthy SOCKS5 proxy tunnels for persistent network access.

4 min read
APT41 Deploys Stealthy Backdoor to Harvest Cloud CredentialsHIGH
Threat Intel

APT41 Deploys Stealthy Backdoor to Harvest Cloud Credentials

China-linked threat actor APT41 is deploying a novel, low-detection backdoor against AWS, Google, Azure, and Alibaba Cloud to harvest credentials and establish persistence.

4 min readAPT41
Backdoored Smart Slider 3 Pro Update Deployed via Compromised Plugin ServersHIGH
Threat Intel

Backdoored Smart Slider 3 Pro Update Deployed via Compromised Plugin Servers

Unknown threat actors compromised the update infrastructure for the Smart Slider 3 Pro WordPress plugin, pushing a backdoored version (3.5.1.35) to users. The attack leverages a supply chain compromise to gain administrative access.

4 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.