Malware

44 articles

🦠 Malware

CVE: Mini Shai-Hulud Malware

Mini Shai-Hulud malware has compromised hundreds of npm packages, with the threat actor TeamPCP embedding a self-replicating worm that installs persistent backdoors and steals sensitive data.

🦠 Malware

SHub macOS Infostealer Spoofs Apple Updates

A new SHub macOS infostealer variant, dubbed Reaper, steals sensitive browser data and hijacks crypto wallet apps by spoofing Apple security updates.

Malware

REMUS Infostealer Analysis

The REMUS infostealer has emerged with a focus on session theft, MaaS, and rapid evolution, drawing attention from security researchers.

Malware

Mini Shai-Hulud Malware

The 'mini Shai-Hulud' malware campaign has infected hundreds of open-source software packages, embedding credential-stealing code into development tools downloaded millions of times a week.

Malware

Shai Hulud Malware Targets Developers

Hundreds of npm and PyPI packages have been compromised in a Shai-Hulud supply-chain campaign, delivering credential-stealing malware to developers.

Malware

Vidar Stealer Malware

The Australian Cyber Security Center warns of ongoing ClickFix attacks distributing Vidar Stealer info-stealing malware through compromised WordPress websites.

Malware

TCLBanker Malware Targets Banking and Crypto Platforms

TCLBanker malware self-spreads over WhatsApp and Outlook, targeting 59 banking, fintech, and cryptocurrency platforms, with capabilities including live screen streaming and keylogging.

Malware

PCPJack Worm Steals Credentials

The PCPJack worm is stealing credentials from exposed cloud infrastructure and removing TeamPCP infections, with researchers believing it may be the work of a former TeamPCP affiliate.

Malware

PCPJack Worm Targets TeamPCP Infections

The PCPJack worm removes TeamPCP infections and steals credentials across multiple cloud environments, targeting services such as AWS, Kubernetes, and GitHub.

Malware

JDownloader Malware Attack

The JDownloader website was compromised to distribute malicious Windows and Linux installers, affecting users who downloaded installers between May 6 and May 7, 2026.

Malware

Beagle Windows Malware

A fake Claude AI website is delivering a new Windows malware called Beagle, which provides attackers with remote access to compromised systems.

Malware

Quasar Linux RAT Targets Developers

A sophisticated Linux backdoor, Quasar Linux RAT, has been identified to steal developer credentials across the software supply chain.

Malware

Quasar Linux Malware Targets Developers

A new Linux malware, Quasar Linux, targets software developers with rootkit, backdoor, and credential-stealing capabilities, enabling potential supply-chain attacks.

Malware

26 Fake Crypto Wallet Apps Found Targeting China's Apple App Store Users

Kaspersky researchers uncovered 26 malicious apps on the Apple App Store impersonating wallets like MetaMask, Coinbase, Trust Wallet, and OneKey, all linked to a campaign called FakeWallet tied to the ongoing SparkKitty operation.

Malware

ZionSiphon: OT Malware Built to Disrupt Water Treatment and Desalination Plants

A newly discovered malware called ZionSiphon targets water treatment and desalination systems, capable of dangerously spiking chlorine levels and hydraulic pressures. A logic flaw currently prevents execution, but researchers warn a simple fix could make it fully operational.

Malware

AgingFly Malware Targets Ukrainian Governments and Hospitals to Steal Credentials

A newly identified malware family called AgingFly is being deployed against Ukrainian local governments, hospitals, and Defense Forces personnel, stealing credentials from Chromium browsers and WhatsApp. Ukraine's CERT team attributed the campaign to threat cluster UAC-0247.

Malware

Trojanized Claude AI Site Drops PlugX RAT via DLL Sideloading

A fraudulent website impersonating Anthropic's Claude AI platform was found distributing PlugX, a remote access trojan with deep ties to espionage operations, through a cleverly staged installer chain.

Malware

CanisterWorm Wiper Targets Iran as TeamPCP Escalates Supply Chain Attacks

A cybercrime group called TeamPCP has deployed a self-propagating worm that wipes data on systems configured for Iran's timezone or Farsi language, while also conducting supply chain attacks against cloud security tools Trivy and KICS.

Malware

LucidRook: Lua-Based Malware Targets NGOs and Universities in Taiwan

A newly discovered Lua-based malware called LucidRook is being deployed against non-governmental organizations and universities in Taiwan via spear-phishing campaigns. Cisco Talos attributes the threat to a group tracked as UAT-10362.

Malware

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

An elusive hacker who went by the handle \"UNKN\" and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and...

🦠 Malware

AI-Powered Phishing: The New Era of Social Engineering

Threat actors are leveraging large language models and deepfake technology to craft highly personalized phishing attacks at unprecedented scale. Traditional detection methods are struggling to keep pace.