Malware campaigns, trojans, botnets, and the threat actors deploying malicious code.
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Kaspersky has identified coordinated attacks against Russian enterprises originating from three distinct threat groups. NightEagle, also tracked as AP…
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
A previously undocumented Brazilian banking malware operation called KREMLIN has emerged as a targeted threat against Chrome and Edge users since May …
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have identified a multi-platform malware campaign using the MQTT protocol to command infected Windows and Linux systems. The…
VectraRAT Can Hack Windows Enterprises for $250 per Month
A new malware-as-a-service platform called VectraRAT has emerged offering attackers a complete toolkit to compromise Windows enterprise systems for ju…
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious browser extension targeting Twitch users has exfiltrated OAuth authentication tokens from approximately 31,000 accounts to infrastructure …
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
Russia's state-sponsored Sandworm group has weaponized multiple Cisco vulnerabilities to deploy an updated variant of Cyclops Blink, the sophisticated…
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
Attackers have begun weaponizing artificial intelligence to accelerate exploit development and automate attack chains, according to security researche…
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
China-linked threat actor UNC3569 exploited a zero-day vulnerability in Sogou Input Method to deploy the GRAYRABBIT backdoor on Windows systems, accor…
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
# Threat Actor Generates 1 Million Personalized Fraud Emails in 3 Days Using AI Attackers have crossed a new threshold in email-based fraud campaigns…
Why AI Is So Good at Scamming Humans
Frontier AI models excel at social engineering because they combine linguistic fluency with behavioral modeling at scale. Fred Heiding, researcher at …
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic disclosed that multiple threat actor groups exploited Claude AI models to execute coordinated cyber attacks, automate data theft, and conduc…
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
# AI-Powered Swarm Attacks Reshape Threat Landscape, Forcing Defense Strategy Rethinking Advanced threat actors are weaponizing artificial intelligen…
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
Google Play researchers discovered 200 Android malware variants circulating through the official app store, highlighting persistent gaps in Google's m…
Indonesia Hit by Android Banking App-Cloning Campaign
# Indonesia Hit by Android Banking App-Cloning Campaign Indonesian users face twin threats from sophisticated banking trojans deployed through app-cl…
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Threat actors have weaponized Google Play's Early Access program to distribute thousands of deceptive Android applications, leveraging the testing mec…
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
Gigabud banking trojan operators deployed a novel evasion technique that exploits Android's work profile feature to bypass banking app security checks…
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Infostealer malware campaigns are now targeting AI platform credentials and API tokens, creating a direct pipeline for threat actors to commandeer acc…
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
# ClickFix Campaigns Abuse Legitimate Services for Persistent Access Threat actors are weaponizing ClickFix, a legitimate remote support tool, to est…
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
A sprawling SEO poisoning campaign operating since at least 2015 has flooded Bing search results with malicious links, routing victims toward malware …
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors have refined a phishing technique that leverages legitimate Google services as intermediaries to bypass email security controls and cred…
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Autonomous AI agents deployed by financially motivated threat actors harvested thousands of credentials in under six hours, demonstrating a fundamenta…
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Researchers have uncovered a sophisticated post-exploitation toolkit named PEEP that transforms Chrome and Edge browsers into backdoors for executing …
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Check Point Research has identified JSCeal, a compiled V8 JavaScript malware strain capable of circumventing Google authentication by harvesting and a…
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
ConnectWise ScreenConnect, a legitimate remote support platform trusted by thousands of IT teams, has become a distribution vector for malware through…
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has identified four previously undiscovered malware modules linked to REVSTEALER, a Windows information stealer that operates as…
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
# Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads The U.S. Department of Justice announced the takedown of Sal…
Companies Have 6 Months to Prepare for Automated Attacks
Autonomous artificial intelligence systems are moving beyond research labs into operational threat landscapes. Frontier AI models, the most advanced s…
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
# Phishing Campaign Exploits Invisible Unicode to Bypass Email Defenses at Scale Microsoft has documented a large-scale phishing campaign weaponizing…
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
# New Ted Backdoor Embedded in Trojanized HAProxy Installations Intercepts Web Traffic A previously undocumented Linux backdoor named ted has been di…
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
GitGuardian researchers have detected a major expansion in Shai-Hulud, an infostealer worm that now targets 469 credential storage locations across en…
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Researchers have discovered BraZetsu, a sophisticated Python-based malware framework that transforms compromised Windows systems into commodities for …
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Attackers have weaponized Node.js, one of the most widely trusted JavaScript runtimes, to deliver malware in coordinated campaigns targeting governmen…
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
# AI-Powered Attack Compresses Two-Week Breach Into 10 Hours Researchers have documented an attack scenario where an autonomous AI agent completed wh…
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
# Malware Campaign Masquerades as Software Vendors, Deliberately Cripples Windows Security Threat actors are running an active campaign that tricks u…
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
A Russian national extradited from Cyprus now faces federal charges for orchestrating a large-scale malware campaign that targeted thousands of freela…
AI Gives Cybercriminals a Dangerous Time Advantage
# AI Gives Cybercriminals a Dangerous Time Advantage Threat actors now exploit artificial intelligence to compress attack timelines, shifting the ope…
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
# Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages A Chinese-speaking cybercrime group called Gambling Goblin …
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers at ThreatFabric have exposed a sophisticated Android banking trojan named StreamRat, distributed through fake television-str…
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
A threat group operating under the moniker "Spring Ring" has launched a vishing campaign targeting Microsoft Teams users to gain remote access to thei…
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet, a financially motivated threat actor formerly tracked as UNC5669, has executed hundreds of fraudulent transactions targeting Brazilian f…
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Researchers have uncovered a coordinated malware campaign targeting iOS users through compromised Packagist packages. The attack chain exploits Vietna…
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Iranian state-sponsored group Nimbus Manticore has deployed two previously unknown remote access trojans targeting Windows, Linux, and macOS systems t…
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
# Threat Actors Prefer Repeatable Attacks Over Novel Exploits, Microsoft Research Shows Microsoft's security research team identified ClickFix as the…
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Russia-aligned threat actor UAC-0099 has deployed a novel evasion technique called GuardBreaker that embeds nuclear weapon-related prompts into malwar…
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
A threat campaign dubbed ClickFix has compromised at least 31 organizations across multiple sectors by leveraging a sophisticated technique that abuse…
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
# TerminalFix Campaign Leverages PowerShell to Establish Enterprise Network Persistence A new threat campaign dubbed TerminalFix weaponizes PowerShel…
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Silver Fox, a known threat actor, has engineered a sophisticated evasion strategy by embedding the ValleyRAT backdoor into a legitimate Chinese wallpa…
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Aurora ransomware operators have weaponized Cursor, SpaceX's AI-powered coding assistant, to compromise at least 10 targets, according to concurrent r…
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft researchers have identified a new social engineering attack called TerminalFix that tricks users into executing malicious commands through W…
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers uncovered a phishing-as-a-service platform that deploys AI voice agents to impersonate Apple Support and extract passcodes f…
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
# Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS Researchers have identified a new Linux botnet named Evooo1Bot that builds on Mi…
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
A newly discovered Python-based malware framework called TwinLoot operates entirely within Microsoft's cloud infrastructure, bypassing traditional end…
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers at Socket identified 19 malicious browser extensions across Google Chrome and Microsoft Edge that steal wallet secrets and d…
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
# Spark RAT Campaign Targets Cambodia Using Weaponized OPSWAT Driver Exploit Attackers in Cambodia have deployed Spark RAT, an open-source remote acc…
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Arctic Wolf researchers have identified a novel malware framework called GoCaracal deployed by threat actors with suspected links to Dark Caracal duri…
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
A newly discovered Windows backdoor named SLEEPWALKER presents a sophisticated evasion technique that keeps the malware dormant until activated by a p…
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Dark Caracal, the Lebanese threat actor known for persistent cyber espionage operations across the Middle East and beyond, has deployed a new modular …
Android Malware Hijacks Update System for Car Head Units
Attackers operating a click-fraud botnet have shifted focus toward Android-based vehicle infotainment systems, exploiting legitimate update mechanisms…
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
A new phishing-as-a-service platform called NovaCookies enables attackers to harvest Microsoft 365 session tokens for a monthly subscription of just $…
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
# Malware Campaign Weaponizes FTP Banners to Deliver Two New RATs Researchers have uncovered a fresh campaign leveraging FTP banners as dead drop res…
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Researchers have uncovered a coordinated phishing campaign leveraging 24 npm packages to redirect users to counterfeit Cloudflare CAPTCHA pages, explo…
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Weedhack, a malware family targeting gamers, exploits the popularity of Minecraft to distribute itself through fraudulent client downloads and search …
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
A Chinese-speaking cybercrime group designated UAT-10147 has begun deploying artificial intelligence tools to automate and scale attacks against Windo…
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
# WordlistLoader Deploys Amatera Infostealer Through ClickFix-Style Deception Threat actors are leveraging a novel obfuscation technique called Wordl…
China-Linked Hacker Shows AI Capabilities in APAC Attack
A China-linked threat actor deployed an artificial intelligence framework to conduct what researchers describe as a near-autonomous cyber operation ag…
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
# Two Fresh Malware Families Target Windows Systems for Credential Theft and Ransomware Access Researchers at Gen Digital have identified two previou…
Tricky 'SynkLoader' Multitool May Herald Ransomware
# SynkLoader Emerges as Dangerous Multitool with Ransomware Potential A newly identified malware family called SynkLoader has surfaced with a potent …
ToxicPanda Banking Trojan Matures Into Enterprise Threat
# ToxicPanda Banking Trojan Matures Into Enterprise Threat The ToxicPanda banking trojan has evolved significantly, shifting from a consumer-focused …
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts has attributed over 30 rotating web domains to MacSync Stealer, a macOS-focused information stealer malware that cycles thr…
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
ReliaQuest researchers uncovered a specialized web shell deployed by Clop-affiliated threat actors following successful exploitation of critical vulne…
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Typosquatting attacks on software repositories remain a persistent threat to developers. A new campaign has exploited this vulnerability by publishing…
'Grandoreiro' Malware Resurfaces With Mexico Campaign
# 'Grandoreiro' Banking Trojan Returns With Stealth Upgrades Targeting Mexico The Grandoreiro banking Trojan has resurfaced following law enforcement…
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Zimperium zLabs exposed ToxicPanda 2.0, an Android malware variant that has evolved into a sophisticated banking threat with expanded global reach and…
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
Socket Threat Research identified 40 malicious Firefox extensions stealing cryptocurrency wallet credentials by impersonating legitimate Web3 products…
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
A cybercriminal operation called StopAndProtect has weaponized nearly 2,000 compromised WordPress sites to distribute malware, exfiltrate data, and es…
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A newly discovered Android malware strain called Manic targets financial institutions and government infrastructure across Eastern Europe and beyond t…
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Researchers at Trend Micro have identified fourteen trojanized npm packages that deliver RedC2 4.0, a Linux backdoor with AI-assisted command-and-cont…
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Kaspersky researchers uncovered a sophisticated malware family targeting Android-based vehicle infotainment systems manufactured by DoFun, distributin…
Read This Before You Buy That TV Streaming Stick
Security researchers have identified a widespread fraud scheme targeting streaming device users. Generic TV boxes marketed with promises of unlimited …
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Iranian nation-state operators continue to refine the Cavern C2 framework with new obfuscation techniques designed to evade detection. Kaspersky resea…
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
# Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook Threat actors are systematically compromising ScreenConnect remote monitoring and ma…
AI Sends Global Crime Syndicates Into Fraud Nirvana
# AI-Powered Fraud at Scale: How Criminal Syndicates Are Weaponizing Generative AI Organized crime networks have moved beyond traditional scams. They…
Fake Reservation Links Prey on Weary Travelers
Cybercriminals exploit travel disruptions with convincing phishing campaigns targeting vacation planners and business travelers. Attackers create fake…
Watering Hole Attacks Push ScanBox Keylogger
Researchers have identified a watering hole campaign distributing ScanBox, a JavaScript-based reconnaissance tool, through compromised websites. The a…
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
# Malicious MCP Servers Can Steal Secrets From AI Coding Agents Through Fragmented Requests A new attack vector threatens organizations deploying AI …
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Two malicious VS Code extensions targeting Solidity developers have been stealing cryptocurrency wallets, API keys, and user credentials. Researchers …
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
A new malware campaign targets macOS users through ClickFix-style social engineering attacks. The infection chain delivers a Go-based stealer that exf…
FBI Seizes NetNut Proxy Platform, Popa Botnet
The FBI seized hundreds of domains operated by NetNut, a residential proxy service run by publicly-traded Israeli firm Alarum Technologies. The action…