Unit 42 maps a campaign that hit 150 employees and pushed toward domain controllers.
Unit 42 documents Kimwolf v7, a rebuild that hides DDoS floods behind browser fingerprints and Ethereum domains.
Unit 42 details three ways malware can abuse Chrome's synced passkey flows to hijack accounts.
The XCSSET malware returns as v40 with memory-only execution and a new Chrome-hijacking module.
Unit 42 details a DeepSeek-driven agent that launched attacks after a single Telegram command.