logo

Cargo thieving hackers running sophisticated remote access campaigns, researchers find

ID: 3dfdd531-3f70-56a8-99ca-64f225dec0a5

STIX ID: report--3dfdd531-3f70-56a8-99ca-64f225dec0a5

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2026-04-16

Date Updated: 2026-05-01

...
...

Proofpoint researchers observed cybercriminals compromising load boards to deploy multiple remote access tools (including several ScreenConnect instances) against trucking carriers, using a novel "signing-as-a-service" to sign installers and re-sign components to evade detection and maintain persistence; attackers also scanned infected systems for cryptocurrency wallets, PayPal and banking credentials, fuel card and freight management platforms to enable cargo theft and broader financial fraud against mostly small carriers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.