Cyware Weekly Threat Intelligence, September 29–October 03, 2025

Weekly Threat Briefing • October 3, 2025
Weekly Threat Briefing • October 3, 2025
Like a blueprint for digital fortresses, seven nations have rolled out OT security guidance. Built on five principles, it demands clear records of OT components and robust risk management to shield critical systems from supply chain threats. With a global dragnet, Interpol’s Operation Contender 3.0 nabbed 260 suspects across 14 African countries, smashing romance scams and sextortion rings.
Through cunning DNS trickery, Detour Dog is spreading Strela Stealer via TXT records and compromised sites. A VMware zero-day flaw, exploited by China’s UNC5174 since last October, is granting attackers root access. A cunning malvertising scheme lures victims with a fake Microsoft Teams installer to unleash Oyster malware.
Luring UAE users with fake Signal and ToTok apps, Android/Spy.ProSpy and ToSpy are pilfering sensitive data. Spread through phishing sites, these spyware variants steal SMS, contacts, and chat histories. Posing as an IPTV and VPN app, Klopatra is snaring over 3,000 European Android devices. Hiding behind trusted EV certificates, hackers are slipping undetectable DMG payloads into macOS systems. This campaign mimics legitimate developers to deploy Odyssey Stealer.