A lot of security still comes down to trusting the wrong screen.This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.Some defenses improved. The loose parts still got found first. Anyway, here's the mess.The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
Phishing delivers XWorm
A cybercrime group known as xplogs22 has been observed targeting Russia and other CIS countries with phishing emails that deliver Xworm. The group, per F6, is believed to have been active since November 2023. Prior attacks mounted by the threat actors leveraged Formbook and Snake Keylogger, before switching to XWorm around July 2025. In recent months, Russian customers of the banking sector have also been targeted by an Android trojan called LunaSpy as part of social engineering attacks. LunaSpy can capture camera streams, record audio and the screen, and collect sensitive data. The malware is disguised as an antivirus application to evade detection.
Custom ransomware targets Russia






