Threats Affecting Germany
View all threats affecting or targeting Germany. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Germany
Click on any threat for detailed analysis and mitigation recommendations
Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation 0 Global law enforcement, including agencies from the Netherlands, Canada, United States, and Germany, coordinated Operation Endgame to disrupt TA569, a prominent cybercriminal group tracked since 2018. The operation targeted SocGholish infrastructure, taking down over 100 servers and domains while remediating 14,971 compromised websites. TA569 pioneered web inject techniques using fake browser updates to distribute malware, often leading to ransomware attacks. The group compromised high-traffic websites across multiple industries, affecting millions of visitors globally. Their attack chains involved traffic distribution systems like Keitaro TDS and ParrotTDS, delivering GhoLoader payloads that could lead to ransomware deployment in enterprise environments. Law enforcement actions included server disruption and website disinfection, significantly impacting the threat actor's operations, infrastructure, and reputation within the cybercriminal ecosystem. Join the discussion | AlienVault OTX General | 06/18/2026, 14:53:54 UTC Added: 06/18/2026, 20:20:24 UTC |
Gamers beware: malicious wallpapers on Steam found stealing accounts 0 Since late 2025, cybercriminals have been exploiting Wallpaper Engine, a popular live wallpaper application on Steam, to distribute malware through Steam Workshop. Attackers target primarily Chinese and Russian gamers by embedding malicious code within application wallpapers shared on the platform. These compromised wallpapers deliver various malware types including infostealers, backdoors, crypto miners, and ransomware. One analyzed sample dropped DarkKomet backdoor while hijacking Steam sessions to steal account credentials. The malware modifies system libraries to locate Steam installations and exfiltrate data to attacker-controlled servers. Compromised accounts are then used to upload additional malicious wallpapers. The diverse malware families suggest multiple independent hacking groups are exploiting this distribution method. Infected wallpapers received thousands of downloads before removal, with 89% of infections occurring in China. Join the discussion | AlienVault OTX General | 06/16/2026, 09:50:13 UTC Added: 06/16/2026, 11:30:21 UTC |
Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages 0 A sophisticated smishing and phishing operation active since the second half of 2025 has impersonated over 267 brands across 72 countries, with particular concentration in Latin America. The campaign generated 4,389 phishing domain instances, with Mexico accounting for 1,851 cases. Telecommunications is the most targeted sector with 1,754 instances, followed by financial services and consumer rewards programs. The operation employs fake Cloudflare error pages as decoys, revealing malicious content only to victims matching specific geofencing and mobile device criteria. Data exfiltration occurs through encrypted WebSocket channels using binary encoded payloads. Approximately 30% of infrastructure is hosted on Tencent Cloud and Alibaba US servers, fronted by Cloudflare to mask hosting IPs. The attack chain progresses from SMS lures through progressive credential harvesting, ultimately capturing complete credit card details including CVV codes. Join the discussion | AlienVault OTX General | 06/03/2026, 13:18:23 UTC Added: 06/04/2026, 09:03:35 UTC |
TA4922: The Suspected Chinese Crime Group is Going Global 0 TA4922 is a highly sophisticated Chinese-speaking threat actor demonstrating rapid operational tempo and continually evolving malware capabilities. Initially targeting East Asia, particularly Japan, the group has expanded globally to Europe and Africa. The actor deploys multiple malware families including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0), alongside legitimate remote management tools like AnyDesk and SyncFuture. Campaigns use localized lures themed around HR, payroll, tax, and invoicing, targeting hundreds to thousands of recipients per campaign. TA4922 conducts credential phishing, fraud operations including credit card theft, and attempts to shift communications to out-of-band channels like LINE, WhatsApp, and Microsoft Teams. The group leverages legitimate cloud hosting services and trusted software for delivery and persistence, combining advanced tradecraft with financially motivated objectives such as data theft, fraud, access resale, and persistent remote access. Join the discussion | AlienVault OTX General | 06/03/2026, 12:55:39 UTC Added: 06/04/2026, 08:33:36 UTC |
Over 116,000 Minecraft systems infected in WeedHack malware campaign 0 The WeedHack malware campaign is a large-scale operation targeting Minecraft players by distributing malicious mods, clients, cheats, and utilities. Since January 2026, it has infected over 116,000 systems globally, primarily in the US, Germany, India, and the UK. The malware operates as a malware-as-a-service (MaaS) infostealer, offering free and premium tiers that steal credentials, session IDs, cookies, and cryptocurrency wallet data, and provide remote access capabilities. Distribution relies heavily on YouTube videos and SEO poisoning to lure victims to malicious download sites. The campaign's scale is reflected in thousands of unique malicious files and hundreds of distribution URLs. Users are advised to only download Minecraft mods from official sources and use the in-game Marketplace for safety. Join the discussion | Bleeping Computer | 06/02/2026, 21:54:49 UTC Added: 06/03/2026, 22:56:30 UTC |
Chinese hackers use new Atlas RAT malware in European cyberattacks 0 A Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor. [...] Join the discussion | Bleeping Computer | 06/03/2026, 21:45:27 UTC Added: 06/03/2026, 21:48:37 UTC |
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content 0 A malware-as-a-service campaign named Weedhack targets Minecraft users by distributing malicious Java JAR files via SEO poisoning and YouTube videos. The malware steals credentials, system information, and can remotely control infected systems. It is notable for its ease of access, free tier, and appeal to younger users, with infections primarily in the U. S.and several other countries. Additionally, a large CountLoader campaign spreads cryptocurrency clipper malware via cracked software, and a separate campaign distributes cryptocurrency miners through pirated content sites. These campaigns leverage sophisticated persistence and evasion techniques and have been active since early 2026. Join the discussion | Reddit Cybersecurity | 06/03/2026, 07:35:27 UTC Added: 06/03/2026, 07:48:26 UTC |
Over 116,000 Mincraft systems infected in WeedHack malware campaign 0 A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January. [...] Join the discussion | Bleeping Computer | 06/02/2026, 21:54:49 UTC Added: 06/02/2026, 22:03:34 UTC |
Microsoft Exchange Online outage causes email delays, failures 0 Microsoft is working to address a widespread service issue affecting the mail flow pipeline for Exchange Online customers across North America and Germany. [...] Join the discussion | Bleeping Computer | 06/02/2026, 17:02:40 UTC Added: 06/02/2026, 17:03:34 UTC |
Showing 1 to 9 of 9 results