Threats Affecting Romania
View all threats affecting or targeting Romania. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Romania
Click on any threat for detailed analysis and mitigation recommendations
Between late September 2025 and early April 2026, the threat group BlueDelta conducted espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye. They deployed HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents with diplomatic-themed lures. HOOKEDGE shares code and tradecraft overlap with the HEADLACE backdoor and abuses legitimate webhook services for command-and-control, payload staging, and data exfiltration. The implant was continuously refined to evade sandbox detection and adapt to webhook service constraints. BlueDelta used a tiered operational model, deploying second-stage payloads with shorter beaconing intervals for high-value targets while preserving initial access infrastructure. Join the discussion | AlienVault OTX General | 08/27/2026, 17:37:41 UTC Added: 08/28/2026, 09:07:13 UTC |
A sophisticated Russian-speaking financially motivated adversary designated UAT-11795 has been conducting malicious operations targeting users in the United States and Europe since June 2025. The campaign delivers a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as the WLDR agent. The actor distributes trojanized installers disguised as legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT through likely ClickFix social engineering techniques. The operation targets victims' credentials and cryptocurrency wallet assets while establishing persistent connections for additional payload delivery. Alternative payloads include CastleStealer and Remcos RAT. The infrastructure utilizes distributed staging and C2 domains, Telegram bots for notifications, and a Polygon smart contract as a fallback mechanism for C2 domain resolution. The WLDR agent features encrypted beaconing, task queuing, and a Runspace execution engine for exe... Join the discussion | AlienVault OTX General | 07/16/2026, 11:34:02 UTC Added: 07/17/2026, 00:32:32 UTC |
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. [...] Join the discussion | Bleeping Computer | 07/16/2026, 10:19:34 UTC Added: 07/16/2026, 10:47:37 UTC |
A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications. MediumCampaign Join the discussion | AlienVault OTX General | 05/27/2026, 20:22:10 UTC Added: 05/28/2026, 15:33:32 UTC |
A sophisticated Android malware campaign has been identified conducting carrier billing fraud through premium SMS abuse across Malaysia, Thailand, Romania, and Croatia. The operation comprises nearly 250 malicious applications that selectively target users based on their mobile operators, silently subscribing victims to premium services without consent. The malware demonstrates advanced capabilities including precise regional targeting with hardcoded SIM operator validation, automated subscription workflows using WebView manipulation and JavaScript injection, OTP interception via abuse of Google's SMS Retriever API, and Telegram-based exfiltration of device metadata. The campaign impersonates popular applications including Facebook, Instagram, TikTok, Minecraft, and Grand Theft Auto to lure victims. Active from March 2025 through January 2026, the operation employs three distinct variants with increasing levels of sophistication, utilizing distributed command and control infrastructure and systematic refer... Join the discussion | AlienVault OTX General | 05/20/2026, 22:37:47 UTC Added: 05/21/2026, 16:59:45 UTC |
A new variant of the ClickFix technique has been identified, where attackers convince users to execute malicious commands on their devices through the Win + R shortcut. This variation uses a 'net use' command to map a network drive from an external server, followed by executing a '.cmd' batch file. The script downloads a ZIP archive, unpacks it, and executes a legitimate WorkFlowy application with modified, malicious logic hidden inside an '.asar' archive. This acts as a C2 beacon and a dropper for the final malware payload. The attack bypasses typical detection methods and utilizes Electron application bundling to hide malicious code. Join the discussion | AlienVault OTX General | 03/16/2026, 10:28:13 UTC Added: 03/16/2026, 11:05:05 UTC |
Threat actors are advertising pages featuring malicious instructions for installing AI agents like Claude Code, Doubao, and OpenClaw. Join the discussion | Kaspersky Security Blog | 03/12/2026, 15:56:27 UTC Added: 03/12/2026, 20:59:05 UTC |
A sophisticated new malware called KadNap has been discovered targeting Asus routers and conscripting them into a botnet for proxying malicious traffic. The malware employs a custom version of the Kademlia Distributed Hash Table protocol to conceal its command-and-control infrastructure within a peer-to-peer system, evading traditional network monitoring. The botnet, which has grown to over 14,000 infected devices, is marketed by a proxy service called Doppelganger, tailored for criminal activity. More than 60% of KadNap's victims are based in the United States. The malware demonstrates versatility by targeting various edge networking devices and employing different C2 servers for different victim types. Join the discussion | AlienVault OTX General | 03/11/2026, 10:02:07 UTC Added: 03/11/2026, 10:13:55 UTC |
In his last two diaries, Xavier discussed recent malware campaigns that download JPEG files with embedded malicious payload[1,2]. At that point in time, I've not come across the malicious “MSI image” myself, but while I was going over malware samples that were caught by one of my customer's e-mail proxies during last week, I found another campaign in which the same technique was used.
 Join the discussion | SANS ISC Handlers Diary | 02/23/2026, 14:26:39 UTC Added: 02/23/2026, 13:37:21 UTC |
Catalin Dragomir admitted in a US court to selling access to an Oregon state government office’s network. The post Romanian Hacker Pleads Guilty to Selling Access to US State Network appeared first on SecurityWeek . Join the discussion | SecurityWeek | 02/23/2026, 11:53:35 UTC Added: 02/23/2026, 12:02:32 UTC |
Showing 1 to 10 of 43 results