
Read all Blogs from this Author
CloudSEK uncovered a large-scale Loader-as-a-Service botnet distributing RondoDoX, Mirai, and Morte payloads through SOHO routers, IoT devices, and enterprise apps. Exploiting weak credentials, unsanitized inputs, and old CVEs, the campaign surged 230% in mid-2025, weaponizing compromised devices for cryptomining, DDoS, and enterprise intrusions. With rapid infrastructure rotation and multi-architecture malware, the threat is evolving fast—making early detection and defense critical
Threat actors are exploiting a fake Microsoft Teams download site to deliver the Odyssey macOS stealer via Clickfix. Once executed, the malware harvests credentials, cookies, Apple Notes, and crypto wallets, exfiltrating data to a C2 server before ensuring persistence through LaunchDaemons and even replacing Ledger Live with a trojanized version. The campaign poses severe risks of credential theft, financial loss, and long-term reinfection.
Read all Whitepapers and reports from this Author
.png)
CloudSEK’s Middle East Threat Landscape Report 2025 reveals a sharp surge in cyber attacks led by state-aligned hacktivists, ransomware groups, and dark-web marketplaces. Finance, Government, and Telecom emerged as top targets, with 748+ coordinated incidents and escalating data leaks, extortion, and sector-specific breaches. A concise, high-impact report that leaders must read to understand 2025’s evolving threats
Read MoreRead all knowledge base articles from this Author