Malware

66 articles

Malware

CVE: SmartLoader Malware Spread via 7,600 Fake GitHub Repos

The FakeGit campaign has pushed SmartLoader and StealC malware through 7,600 malicious GitHub repositories, accumulating over 14 million downloads, by using a technique called 'agentbaiting' to increase visibility to AI agents.

Malware

Sandworm_Mode Malware Targets AI Tools

A self-propagating malware strain, Sandworm_Mode, is targeting AI coding assistants and software developers' automated workflows, spreading through code repositories with minimal detection.

Malware

HollowGraph Malware Exploits Microsoft Graph

A new malware, HollowGraph, uses Microsoft Graph for stealthy command-and-control communications, targeting organizations in Israel for espionage purposes.

Malware

OkoBot Framework Steals Data and Crypto

The OkoBot framework delivers over 20 payloads to steal cryptocurrency wallet seed phrases, credentials, and other sensitive data, with most victims located in Brazil, Vietnam, Canada, Mexico, and Turkey.

Malware

ClickLock macOS Malware

New ClickLock macOS malware forces users to reveal their login password, stealing cryptocurrency assets, login credentials, and more.

Malware

GitHub Repo Malware Threat

Researchers at Mozilla's Zero Day Investigative Network discovered a method to trick AI coding agents into running malware from a clean GitHub repository.

Malware

macOS Malware Gaslight Evades AI Analysis

A new macOS malware, dubbed 'Gaslight', embeds fake errors to confuse AI-assisted malware analysis tools, potentially causing them to abort or truncate analysis.

Malware

Malicious Edge Extension Abuses Native Messaging

A malicious Microsoft Edge extension called Edgecution has been used in a ransomware attack to deploy a Python-based backdoor by leveraging the Chrome Native Messaging protocol.

Malware

macOS ClickFix Attack

A new macOS ClickFix campaign silently downloads and launches info-stealing malware from malicious DMG files, targeting browser credentials and cryptocurrency wallets.

Malware

Prinz Eugen Ransomware Targets Recent Files

Prinz Eugen ransomware prioritizes recently modified files for encryption, leaving no ransom note on the system, and operates outside the ransomware-as-a-service model.

Malware

Crypto-Stealing Malware Spreads via USB Worm

A USB worm is spreading crypto-stealing malware via Windows shortcut files, targeting cryptocurrency wallets and using the Tor network to conceal communication.

Malware

Mackay Sugar Ransomware Attack

Mackay Sugar, Australia's second-largest raw sugar producer, has been targeted in a ransomware attack that forced it to shut down some of its mills.

Malware

Arch Linux Packages Compromised

Over 400 Arch Linux packages have been compromised to distribute a Linux rootkit and infostealer malware, targeting credentials and access tokens.

Malware

OnyxC2 Stealer Offers Enterprise-Grade Theft

OnyxC2 stealer is available for hire starting at $250 per month, offering stealth and extensive reach to cybercriminals, with access to 210 applications and extensions across nine categories.

Malware

C0XMO Botnet Targets DD-WRT Routers

The C0XMO botnet spreads via a DD-WRT router flaw, exploiting CVE-2021-27137, and kills rival malware, with a modular design allowing operators to update its techniques and expand capabilities.

Malware

IronWorm Malware Hits npm Packages

A new supply-chain attack has infected 36 packages on the Node Package Manager with IronWorm malware, targeting environment variables and credential files.

Malware

Atlas RAT Malware Used in European Cyberattacks

A Chinese-speaking cybercrime group, TA4922, has deployed the previously undocumented Atlas RAT malware in European cyberattacks, targeting entities in Germany, Italy, the UK, and South Africa.

Malware

DriveSurge Malware Campaign

Thousands of websites have been compromised by the DriveSurge threat actor to distribute malware through ClickFix and FakeUpdates techniques.

Malware

ChatGPT Share Links Abused for Malware Delivery

Threat actors are abusing ChatGPT's content-sharing feature to display fake outage pages that direct users to download malware disguised as the ChatGPT desktop application.

Malware

Cryptojacking Campaign Targets High-Performance Computers

A cryptojacking campaign is spreading via SEO poisoning and AI chatbots, targeting systems with high-performance computers and using legitimate remote management tools to install malware.

Malware

CVE: Mini Shai-Hulud Malware

Mini Shai-Hulud malware has compromised hundreds of npm packages, with the threat actor TeamPCP embedding a self-replicating worm that installs persistent backdoors and steals sensitive data.

Malware

SHub macOS Infostealer Spoofs Apple Updates

A new SHub macOS infostealer variant, dubbed Reaper, steals sensitive browser data and hijacks crypto wallet apps by spoofing Apple security updates.

Malware

REMUS Infostealer Analysis

The REMUS infostealer has emerged with a focus on session theft, MaaS, and rapid evolution, drawing attention from security researchers.

Malware

Mini Shai-Hulud Malware

The 'mini Shai-Hulud' malware campaign has infected hundreds of open-source software packages, embedding credential-stealing code into development tools downloaded millions of times a week.

Malware

Shai Hulud Malware Targets Developers

Hundreds of npm and PyPI packages have been compromised in a Shai-Hulud supply-chain campaign, delivering credential-stealing malware to developers.

Malware

Vidar Stealer Malware

The Australian Cyber Security Center warns of ongoing ClickFix attacks distributing Vidar Stealer info-stealing malware through compromised WordPress websites.

Malware

TCLBanker Malware Targets Banking and Crypto Platforms

TCLBanker malware self-spreads over WhatsApp and Outlook, targeting 59 banking, fintech, and cryptocurrency platforms, with capabilities including live screen streaming and keylogging.

Malware

PCPJack Worm Steals Credentials

The PCPJack worm is stealing credentials from exposed cloud infrastructure and removing TeamPCP infections, with researchers believing it may be the work of a former TeamPCP affiliate.

Malware

PCPJack Worm Targets TeamPCP Infections

The PCPJack worm removes TeamPCP infections and steals credentials across multiple cloud environments, targeting services such as AWS, Kubernetes, and GitHub.

Malware

JDownloader Malware Attack

The JDownloader website was compromised to distribute malicious Windows and Linux installers, affecting users who downloaded installers between May 6 and May 7, 2026.

Malware

Beagle Windows Malware

A fake Claude AI website is delivering a new Windows malware called Beagle, which provides attackers with remote access to compromised systems.

Malware

Quasar Linux RAT Targets Developers

A sophisticated Linux backdoor, Quasar Linux RAT, has been identified to steal developer credentials across the software supply chain.

Malware

Quasar Linux Malware Targets Developers

A new Linux malware, Quasar Linux, targets software developers with rootkit, backdoor, and credential-stealing capabilities, enabling potential supply-chain attacks.

Malware

26 Fake Crypto Wallet Apps Found Targeting China's Apple App Store Users

Kaspersky researchers uncovered 26 malicious apps on the Apple App Store impersonating wallets like MetaMask, Coinbase, Trust Wallet, and OneKey, all linked to a campaign called FakeWallet tied to the ongoing SparkKitty operation.

Malware

ZionSiphon: OT Malware Built to Disrupt Water Treatment and Desalination Plants

A newly discovered malware called ZionSiphon targets water treatment and desalination systems, capable of dangerously spiking chlorine levels and hydraulic pressures. A logic flaw currently prevents execution, but researchers warn a simple fix could make it fully operational.

Malware

AgingFly Malware Targets Ukrainian Governments and Hospitals to Steal Credentials

A newly identified malware family called AgingFly is being deployed against Ukrainian local governments, hospitals, and Defense Forces personnel, stealing credentials from Chromium browsers and WhatsApp. Ukraine's CERT team attributed the campaign to threat cluster UAC-0247.

Malware

Trojanized Claude AI Site Drops PlugX RAT via DLL Sideloading

A fraudulent website impersonating Anthropic's Claude AI platform was found distributing PlugX, a remote access trojan with deep ties to espionage operations, through a cleverly staged installer chain.

Malware

CanisterWorm Wiper Targets Iran as TeamPCP Escalates Supply Chain Attacks

A cybercrime group called TeamPCP has deployed a self-propagating worm that wipes data on systems configured for Iran's timezone or Farsi language, while also conducting supply chain attacks against cloud security tools Trivy and KICS.

Malware

LucidRook: Lua-Based Malware Targets NGOs and Universities in Taiwan

A newly discovered Lua-based malware called LucidRook is being deployed against non-governmental organizations and universities in Taiwan via spear-phishing campaigns. Cisco Talos attributes the threat to a group tracked as UAT-10362.

Malware

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

An elusive hacker who went by the handle \"UNKN\" and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and...

🦠 Malware

AI-Powered Phishing: The New Era of Social Engineering

Threat actors are leveraging large language models and deepfake technology to craft highly personalized phishing attacks at unprecedented scale. Traditional detection methods are struggling to keep pace.