Skip to main content

Threats Affecting Bulgaria

View all threats affecting or targeting Bulgaria. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Country:BulgariaBulgaria

Threats Affecting Bulgaria

Click on any threat for detailed analysis and mitigation recommendations

Researchers identified an exposed web directory on infrastructure supporting a cryptocurrency fraud operation tracked as Operation ASTERIX. The server contained phone-number datasets, account-validation tools, phishing panels, voice-dialing scripts, and fake wallet applications for Ledger, Trezor, and Exodus. The operator validated approximately 885,000 phone numbers against cryptocurrency exchange accounts, achieving a 13.6% hit rate on German numbers. Victims received coordinated phishing emails and vishing calls referencing fake support cases before being directed to counterfeit wallet applications designed to steal recovery phrases via Telegram exfiltration. Notable findings include extensive use of AI coding assistants throughout development, including GitHub Copilot and Claude Code. When one AI model resisted malicious requests, the operator switched providers and attempted to bypass safety controls using a structured jailbreak prompt targeting the model's reasoning patterns and safety mechanisms.

Join the discussion

A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications.

Join the discussion

UAT-7290, a sophisticated threat actor active since 2022, is targeting critical infrastructure entities in South Asia, particularly telecommunications providers. The group's arsenal includes malware families like RushDrop, DriveSwitch, SilentRaid, and Bulbature. UAT-7290 conducts extensive reconnaissance before intrusions, using one-day exploits and SSH brute force to compromise edge devices. The actor is believed to be a China-nexus APT, sharing similarities with APT10 and other known Chinese threat groups. UAT-7290 has recently expanded its targeting to Southeastern Europe and may establish Operational Relay Boxes for other China-nexus actors. Their malware suite primarily focuses on Linux systems but can also utilize Windows-based implants.

Join the discussion

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedded in the client-side part of the software.  This vulnerability has been fixed in versions 4.50.1 and 5.38.0

Join the discussion

Flights across Greece were impacted for several hours after noise was reported on multiple air traffic communication channels. The post Cyberattack Unlikely in Communications Failure That Grounded Flights in Greece appeared first on SecurityWeek .

Join the discussion

A ransomware attack targeted the Romanian Water Authority, causing approximately 1000 systems to be taken offline. This incident disrupted critical water management infrastructure, highlighting the vulnerability of essential public services to cyber extortion. The attack was reported recently and has medium severity based on initial assessments. No specific ransomware variant or exploit details have been disclosed, and there is no evidence of known exploits in the wild related to this incident. The disruption of water services can impact public health and safety, making timely mitigation crucial. European organizations managing critical infrastructure should be vigilant against similar ransomware threats. Romania is directly affected, with potential spillover risks to neighboring countries with interconnected infrastructure. Mitigation should focus on robust backup strategies, network segmentation, and incident response readiness. The threat severity is assessed as high due to the critical nature of the affected systems and the scale of disruption despite limited technical details. Defenders must prioritize protecting operational technology environments and ensure rapid recovery capabilities.

Join the discussion

A ransomware attack targeted a Romanian water authority over a weekend, disrupting critical infrastructure operations. The attack was reported via Reddit and covered by BleepingComputer, highlighting its high priority and newsworthiness. No specific ransomware variant or exploited vulnerabilities have been disclosed, and there is no indication of known exploits in the wild. The incident underscores the ongoing threat ransomware poses to essential public services, particularly in the water sector. European organizations involved in critical infrastructure should be alert to similar threats. Mitigation requires focused incident response, network segmentation, and enhanced monitoring tailored to industrial control systems. Romania is the primary affected country, but neighboring European states with similar infrastructure profiles could be at risk. Given the potential impact on availability and public safety, ease of exploitation typical of ransomware, and the critical nature of water services, the threat severity is assessed as high. Defenders must prioritize proactive defenses and rapid recovery capabilities to mitigate such attacks effectively.

Join the discussion

A Russian APT group has been conducting targeted phishing campaigns against government entities in the Baltic and Balkan regions since at least 2023. The attackers use spoofed email attachments mimicking official documents to trick victims into submitting credentials on sophisticated fake login pages. These phishing pages feature blurred backgrounds and complex password validation, yet stolen credentials are exfiltrated regardless of password strength. The campaign specifically targets countries including Moldova, Ukraine, Lithuania, Bosnia and Herzegovina, Macedonia, Montenegro, Spain, and Bulgaria. The stolen credentials are sent to third-party services, enabling potential unauthorized access to sensitive government systems. This ongoing campaign poses a medium-level threat due to its targeted nature and potential for credential theft leading to further compromise. Defenders should focus on phishing awareness, email filtering, and credential monitoring to mitigate risks. The threat is particularly relevant to European government organizations in the affected regions due to geopolitical tensions and strategic importance.

Join the discussion

A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

Join the discussion

The Silent Lynx APT group has been conducting espionage campaigns targeting Central Asian nations, Russia, China, and Azerbaijan. Two main campaigns were identified: one focusing on Russia-Azerbaijan relations and another on China-Central Asia relations. The group uses various malware including PowerShell scripts, .NET implants, and C++ reverse shells. They leverage spear-phishing with malicious attachments, GitHub-hosted payloads, and scheduled tasks for persistence. The campaigns aim to gather intelligence on diplomatic communications, transportation projects, and other strategic initiatives. Silent Lynx shows a pattern of targeting summit meetings and infrastructure deals in the region, with a particular focus on events in Dushanbe, Tajikistan.

Join the discussion

Showing 1 to 10 of 18 results

Filters:Country: Bulgaria
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses