logo

Cargo thieving hackers running sophisticated remote access campaigns, researchers find

ID: ab13832c-c230-525f-95f9-7cb69566d256

STIX ID: report--ab13832c-c230-525f-95f9-7cb69566d256

Feed Name: Proofpoint Blog

Threat Score
72/100

Date Published: 2026-04-16

Date Updated: 2026-04-28

...
...

Proofpoint researchers monitored a coordinated campaign targeting load boards used by trucking and logistics firms, where attackers deploy multiple remote access tools (including several ScreenConnect instances) and employ a "signing-as-a-service" capability to sign and re-sign installers and components to bypass certificate revocation; compromised hosts are then searched for cryptocurrency wallets, PayPal/banking credentials, fuel card providers, and freight management systems, enabling large-scale cargo theft and broader financial fraud against mostly small carriers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.