Skip to content
September 28, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Europol and the British National Crime Bureau banned a crime ring linked to Luminosity RAT
  • Malware

Europol and the British National Crime Bureau banned a crime ring linked to Luminosity RAT

Do Son February 8, 2018 2 minutes read
Luminosity RAT
Add Daily CyberSecurity as a preferred source on Google

According to securityaffairs media reported on February 6 that the European Cybercrime Center and the British Crime Bureau, affiliated with Europol, have recently disclosed details of an international law enforcement operation – more than a dozen law enforcement agencies from Europe, the United States and Australia jointly demolished one A criminal gang associated with the Luminosity RAT remote access Trojan (aka LuminosityLink). It is reported, Luminosity RAT can disable antivirus and anti-malware on the target device, perform commands such as recording keystrokes, stealing data and passwords, enabling webcam to monitor users.

The British Crime Bureau disclosed that the Luminosity RAT was first discovered in 2015 and has become very popular since 2016. According to media sources, a small British criminal gang distributed the Luminosity RAT to more than 8,600 buyers in 78 countries through the use of malicious Web sites.

It is learned that buyers can get Luminosity RAT remote access Trojan for only $40, even though the Trojan costs only $ 30. In addition, Luminosity RAT also offers buyers technical convenience, for example, buyers can acquire the Trojan with little technical knowledge.

Thousands of victim users are currently being stolen with sensitive information, including passwords, private photos, videos and more. Steven Wilson, head of the European Center for Cybercrime, said that although cybercrime is now escalating and updating, cross-border and vigorous coordination of actions cannot prevent hackers from being arrested over long-range criminal offenses around the world.

Source: SecurityAffairs 

Related coverage

  • PyPI Poisoned: “Zebo” and “Cometlogger” Downloaded Hundreds of Times
  • Collateral Damage: Microsoft Defender Blocks Official MAS Script in Malware War
  • The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
  • BlackCat ransomware stole 120GB of medical data from Advarra using a SIM swap attack
  • China-Nexus Espionage: ScatterBrain Obfuscation Tactics Revealed
  • MisakaNetwork: Blockchain Botnet Threatens npm Ecosystem
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Luminosity RAT

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-101894CVSS 9.1
    The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101891CVSS 9.3
    An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker...
    📅 Updated: Sep 28, 2026
  • CVE-2026-86102CVSS 9.3
    An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100721CVSS 9.5
    vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101081CVSS 9.4
    A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100684CVSS 9.2
    Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate,...
    📅 Updated: Sep 28, 2026
  • CVE-2026-63374CVSS 9.3
    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101075CVSS 10.0
    A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.