Check Point Research has discovered a new version of the multi-platform backdoor SysJoker, which is capable of targeting Windows, macOS, and Linux systems. According to their report, this malware variant is being used by a Hamas-affiliated advanced persistent threat group to attack Israel. The malware has been completely rewritten but maintains its functionality, and now uses OneDrive instead of Google Drive for storing dynamic C2 URLs.

Qilin Ransomware Surging Following The Fall of dominant RansomHub RaaS
The ransomware landscape experienced a significant shift in the second quarter of 2025 as Qilin ransomware emerged as the dominant threat following the unexpected collapse