Quantcast
Channel: Dark Web – Dark Lab
Browsing all 21 articles
Browse latest View live

Image may be NSFW.
Clik here to view.

Phishing for Profit: Business Email Compromises

There are plenty of phish in the sea and they’re back with new tricks! Dark Lab responds to multiple business email compromise campaigns targeting Hong Kong. We outline two recent incidents, sharing...

View Article


Image may be NSFW.
Clik here to view.

Hong Kong and Singapore Citizens Actively Targeted by Large-Scale Global...

PwC’s Dark Lab uncovers a large-scale smishing campaign actively targeting Hong Kong and Singapore citizens by masquerading as trusted and reputable locally based public and private postal service...

View Article


Image may be NSFW.
Clik here to view.

LockBit 3.0: New Capabilities Unlocked

LockBit persists as the most prominent Ransomware-as-a-Service (RaaS) groups in 2022, showcasing heightened capabilities in their LockBit 3.0 iteration and a persistent nature to continuously evolve....

View Article

Image may be NSFW.
Clik here to view.

Forecasting the Cyber Threat Landscape: What to Expect in 2023

In a blink of an eye, 2023 is upon us. As we bid farewell to another record-breaking year of increased disclosed vulnerabilities, ransomware incidents, phishing scams, data breaches, and crypto...

View Article

Image may be NSFW.
Clik here to view.

Secure Your Holidays: The Case of Qakbot and Black Basta

On the eve of Christmas, a suspected Black Basta affiliate conducted a ‘quick and dirty’ attack on a global client, lending insight into the opportunistic targeting of victims during holiday downtime...

View Article


Image may be NSFW.
Clik here to view.

Bug Bounty Programs – a Public Good that is a Necessity for Corporates, SMEs,...

As the cyber threat landscape continues to evolve and threat actors increasingly target vulnerable external-facing assets, bug bounties present organizations with an opportunity to proactively...

View Article

Image may be NSFW.
Clik here to view.

Cyber Literacy in Hong Kong – a Public Good to Bridge the Talent Gap and...

As the global cyber threat landscape continues to evolve, defenders will continue to play catch-up by finding ways to prevent, detect, respond and recover from cyber-attacks. However, we need to...

View Article

Image may be NSFW.
Clik here to view.

MOVEit Cl0p, You’re Not the Only One

In Q3 2023, PwC’s Dark Lab responded to two incidents derived from exploitation of the zero-day vulnerability in Progress’ MOVEit File Transfer solution. Whilst exploitation of the zero-day is widely...

View Article


Image may be NSFW.
Clik here to view.

Watch Out for the Adversary-in-the-Middle: WhatsApp QR Code Hijacking Targets...

PwC’s Dark Lab investigates the local WhatsApp account hijacking attacks, uncovering multiple campaigns targeting Hong Kong and Macau consumers. Over the last few months, the community has seen a...

View Article


Image may be NSFW.
Clik here to view.

Watch Out for the Adversary-in-the-Middle: Multi-Stage AiTM Phishing and...

PwC’s Dark Lab recently responded to a Business Email Compromise incident, leading to the discovery of an opportunistic multi-stage Adversary-in-the-Middle campaign. Business Email Compromise (BEC)...

View Article

Image may be NSFW.
Clik here to view.

The 2024 Cyber Threat Landscape

2023 saw threat actors relentlessly innovating and specialising to remain sophisticated in speed and scale, through the use of automation intelligence, targeting against supply chains and managed...

View Article

Image may be NSFW.
Clik here to view.

Tracking the proxy: a canary-based approach to locate users from...

As we step through a busy season of ransomware, financial scams involving deepfake, and sophisticated phishing campaigns, we continue to witness campaigns targeting enterprise users with...

View Article

Image may be NSFW.
Clik here to view.

Petty Thefts in Cybersecurity

The term “data breach” has been engrained into the memories of board level executives to security engineers in the last few years. Typically referring to confidential or sensitive information being...

View Article


Image may be NSFW.
Clik here to view.

Forecasting the Cyber Threat Landscape: What to Expect in 2025

2024 marked a pivotal shift in the cyber threat landscape, with threat actors increasingly experimental, yet intentional in their approaches to cyberattacks. Leveraging new and emerging technologies...

View Article

Image may be NSFW.
Clik here to view.

Ransomware’s Uneven Playing Field: Re-Thinking Protection and Detection from...

Recently, Dark Lab attended a conference to present the lessons learnt from ransomware incidents impacting small and medium enterprises (“SMEs”), and how these lessons learnt can help us find...

View Article


Image may be NSFW.
Clik here to view.

Redirected, Taken Over, & Defaced: Legitimate Hong Kong Websites Abused to...

Per our continuous monitoring, Dark Lab has tracked multiple open redirection, site takeovers, and defacement cases weaponising Hong Kong organisations’ websites. Typically exploited to serve users to...

View Article

Image may be NSFW.
Clik here to view.

Redirected, Taken Over, & Defaced: Breaking Down the Attacks Abusing...

Last week, we shared our observations regarding active attacks weaponising trusted Hong Kong domains to serve users to suspicious content for SEO manipulation purposes. Collectively, we have observed...

View Article


Image may be NSFW.
Clik here to view.

Don’t do crime CRIME IS BAD – LockBit Ransomware Hacked, Exposing Operational...

LockBit really can’t catch a break. Following a year of law enforcement disruptions and loss of affiliate base, the world mostly recently witnessed one of the most notorious Ransomware-as-a-Service...

View Article

Image may be NSFW.
Clik here to view.

The Dark Side of SEO: Negative SEO Attacks Targeting Businesses in Asia

In June 2025, DarkLab discovered unusual search results indexed on a popular Hong Kong online platform. This led to our deep dive into another form of DNS abuse impacting legitimate entities; negative...

View Article

Image may be NSFW.
Clik here to view.

RCE in PIXERA TWO Media Server (CVE-2026-7703, CVE-2026-7704)

The PIXERA TWO Media Server is an Audio-Visual (AV) solution widely adopted to create large-scale, high-quality visual experiences in live events, stage productions, and creative projects. PIXERA...

View Article
Browsing all 21 articles
Browse latest View live


Latest Images