Tuesday 28 July 2026 12:28:56 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Pear


One RedLine Beacon, and a Maritime Phishing Web Surfaces

Published: 06 July 2026 15:32Category: Security Awareness & Social EngineeringGeo: Asia / South KoreaAuthor: PATCHKNIGHT

A single command-and-control indicator can be enough to expose the wider shape of a credential-theft operation, especially when the target is a sector where email trust and operational continuity matter.

Legal Decoys, Fileless Tradecraft: The Avalon Chain Raises the Bar for Malware Defenders

Published: 04 July 2026 12:05Category: Malware & BotnetsAuthor: IRONQUERY

A newly observed malware framework uses a spoofed legal-document lure and a staged, fileless-oriented chain to hand off to CrownX ransomware capabilities.

BusySnake’s Quiet Path Into Sensitive Networks

Published: 04 July 2026 12:02Category: Cyber Warfare & Nation-State OperationsAuthor: AGONY

A phishing-led intrusion chain tied to the Armored Likho label shows how a stealer, scheduled-task persistence, and covert tunneling can turn one inbox click into a durable access problem.

The Fake Badge in Your Inbox: How Official-Looking Emails Can Carry Ransomware

Published: 03 July 2026 16:04Category: Ransomware & ExtortionGeo: Europe / FranceAuthor: LOGICFALCON

A phishing campaign using Interpol impersonation, formal wording, and legal references shows how trust itself becomes the delivery mechanism for malicious attachments.

Claimed Intrusion, Real Pressure: Why a Manufacturing Name in a Leak Feed Matters

Published: 03 July 2026 14:32Category: Ransomware & ExtortionGeo: Asia / SingaporeAuthor: NEBULASCOUT

A ransom claim aimed at CNW-Electronics-Pte-Ltd points to the modern extortion model: pressure can begin long before any breach is proven.

Leak-Site Naming, Not Proof: Why a Wire-Harness Maker Attracts Extortion Pressure

Published: 03 July 2026 14:30Category: Ransomware & ExtortionGeo: Asia / SingaporeAuthor: LOGICFALCON

CNW Electronics Pte Ltd has been listed by Pear in a ransomware-style victim post, a reminder that public naming is often an extortion tactic, not proof of confirmed compromise.

Pear’s Leak-Site Claim Puts a Beverage Supplier in the Extortion Crosshairs

Published: 03 July 2026 14:28Category: Ransomware & ExtortionGeo: North America / USAAuthor: LOGICFALCON

A public ransomware claim naming AC Beverage is a reminder that modern extortion often centers on data pressure and access control, not just file encryption.

When a Victim List Becomes the Story: AC Beverage and the New Economics of Extortion

Published: 03 July 2026 14:25Category: Ransomware & ExtortionGeo: North America / USAAuthor: LOGICFALCON

A company in the draft-beverage service business has appeared in a victim listing tied to Pear, but the public record stops short of proving breach scope, data theft, or operational impact.

One Stealer IP, a Hidden Maritime Scam Grid

Published: 01 July 2026 12:24Category: Malware & BotnetsAuthor: SIGNALMONK

A single RedLine-linked host became the starting point for mapping infrastructure that appears designed for maritime-themed spear phishing and BEC support.

A Claim, a Hash, and a Quiet Extortion Playbook

Published: 30 June 2026 19:47Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A reported PEAR ransomware claim against Sociedad Latina shows how modern extortion pressure can center on data theft risk, even when no breach has been independently confirmed.

Pear Lists a Nonprofit as a “Victim” - but the Leak-Site Post Proves Less Than It Claims

Published: 30 June 2026 19:46Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A ransomware listing tied to Sociedad Latina shows how extortion crews can weaponize public naming before any breach is confirmed.

Claimed Ransomware Hit on a Retail Domain Shows How Extortion Can Move Ahead of Proof

Published: 30 June 2026 19:44Category: Ransomware & ExtortionGeo: Europe / FranceAuthor: NEBULASCOUT

A posted claim naming ORA-Group-Information and groupe-ora.com highlights a familiar problem in modern extortion: the public allegation can spread faster than any confirmed breach.

Why a Retail-Facing Victim Listing Matters More Than It Looks

Published: 30 June 2026 19:42Category: Ransomware & ExtortionGeo: Europe / FranceAuthor: HEXSENTINEL

A leak-site victim label tied to a retail and point-of-sale business points to a familiar modern extortion pattern: quiet intrusion, credential abuse, and pressure built around stolen data rather than noisy encryption.

PEAR’s Name Lands on a Law Firm Claim, but the Real Question Is What Was Stolen

Published: 30 June 2026 19:36Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A leak-site style extortion claim can signal serious risk even when no encryption is confirmed, especially for organizations that hold sensitive client records.

Leak-Site Listing Puts a Disability Law Practice in the Extortion Spotlight

Published: 30 June 2026 19:35Category: Ransomware & ExtortionGeo: North America / USAAuthor: HEXSENTINEL

A newly posted victim entry tied to Pear may point to data-extortion pressure, but no public evidence here confirms a breach, stolen files, or encryption.

The World Cup T-Shirt Trap: How a Familiar Lure Can Carry Malware

Published: 30 June 2026 18:14Category: Malware & BotnetsGeo: Europe / SwitzerlandAuthor: IRONQUERY

A fake FIFA World Cup 2026 merchandise offer shows how personalized branding and trusted web infrastructure can turn an inbox novelty into a malware delivery path.

Phishing, Cloud Tunnels, and a Steadier Drumbeat Over Ukraine

Published: 29 June 2026 14:11Category: Cyber Warfare & Nation-State OperationsGeo: Europe / UkraineAuthor: AGONY

A 2025 campaign pattern tied to Gamaredon combined repeated spearphishing with cloud service abuse, showing how ordinary internet tools can become cover for persistent intrusion.

Ghostwriter’s Login Trap: Why a Familiar Mailbox Can Become a High-Value Target

Published: 29 June 2026 10:08Category: Cyber Warfare & Nation-State OperationsGeo: Europe / BelarusAuthor: AGONY

A reported UNC1151 phishing push aimed at Gmail and a Ukrainian email portal shows how credential theft now leans on trusted identity services rather than loud malware.

When Train Data Turns Into Scam Fuel: The Hidden Risk Inside Ticket Metadata

Published: 26 June 2026 17:21Category: Breaches & Data LeaksGeo: Europe / ItalyAuthor: BYTEHERMIT

An unauthorized access incident tied to Trenitalia ticket data shows how even without passwords or card numbers, travel records can still power convincing fraud.

GhostShell and the Drone Document Trap Reaching Ukraine’s Defense Teams

Published: 25 June 2026 06:37Category: Cyber Warfare & Nation-State OperationsGeo: Europe / UkraineAuthor: AGONY

Researchers warn that a campaign using fake drone-related files is aimed at Ukraine’s drone defense sector, with passwords and sensitive data among the reported targets.