Skip to main content

Malware & Ransomware

Damaged server racks and equipment in a dimly lit data center with scattered cables and destroyed infrastructure.

AI Cyberattacks Expose Need to Rethink Resiliency

Cyberattacks are no longer just about stealing data - they're now aimed at taking over entire virtual environments, wiping out all data and leaving businesses in a state of digital darkness. The game has changed, and it's time to rethink our approach to resiliency.

Analyst 207
European city street with tech hints and blurred laptop in foreground.

Chinese Hackers Deploy Atlas RAT in Europe With Heightened Cyberattacks

Chinese hackers have significantly ramped up cyberattacks in Europe, with a financially motivated group, tracked as TA4922, launching a high volume of unique campaigns targeting countries including Germany, Italy, and the UK. This surge in activity, which began in March, has been marked by unprecedented diversity in tactics and objectives, including fraud, data theft, and network breaches.

Analyst 207
Brightly-lit office workstation with browser showing redirect chain and cup.

Google DoubleClick Exploited in Malspam Campaign Delivering DesckVB RAT

Cyber attackers are cleverly using Google's DoubleClick to disguise malicious emails, routing victims through a legitimate domain that often flies under the radar of security tools. By exploiting this trusted platform, hackers can easily trick people into downloading the DesckVB RAT malware.

Analyst 207
Smartphone with notification on screen, surrounded by everyday objects.

Google Gemini on Android Exposed to Notification-Based Hijacking

Researchers have uncovered a vulnerability in Google Gemini on Android that allows hackers to hijack the assistant using a single hostile notification, no malicious app required. This shocking exploit lets anyone able to push a notification to a device deliver a payload and take control.

Analyst 207
Industrial setting with fuel storage tanks and an automatic tank gauge system.

Hackers Target Fuel Tank Monitoring Systems with Cyberattacks

Cyber attackers are launching targeted strikes on internet-exposed fuel tank monitoring systems, allowing them to modify and manipulate critical infrastructure. These compromised systems, known as automatic tank gauges, remotely track fuel levels, temperatures, and leaks, making them a prime target for malicious actors.

Analyst 207
Rows of computer servers and networking equipment in a brightly lit server room, conveying disruption and vulnerability.

HTTP/2 Bomb Attack Disrupts Web Servers in Seconds

A home computer on a typical 100Mbps connection can cripple a vulnerable server in mere seconds using a new technique called the HTTP/2 Bomb, which cleverly combines two known weaknesses in HTTP/2 server configurations. This potent attack can be unleashed quickly, leaving servers inaccessible.

Analyst 207
Smartphone on a neutral surface with blurred background.

CISA Warns of Active Exploits Targeting Android, Linux Flaws

A high-severity Android flaw, CVE-2025-48595, is being actively exploited in targeted attacks, allowing hackers to gain increased privileges without needing any user interaction. This critical vulnerability affects Android 14-16 and has prompted CISA to add it to its list of Known Exploited Vulnerabilities.

Analyst 207
Cluttered computer desk with laptop, gaming accessories, and scattered game CDs in a dimly lit home gaming room.

Malware Hidden in Hentai Games Exposes Users to Full System Compromise

Beware of hentai games that seem too good to be true - a new malware campaign has been discovered that hides in these games and can fully compromise your system. Hundreds of users, mainly in Russia, Brazil, Germany, and Vietnam, have already fallen victim to this threat, dubbed Argamal.

Analyst 207
Developer scrutinizes code with concern in a well-lit lab setting.

GitHub Dev Attack Exploits OAuth Tokens

A single click can be all it takes for an attacker to swipe a GitHub token, giving them free rein to read and write to your private repos. Security researcher Ammar Askar warns that a clever exploit in GitHub.dev's web-based editor can turn a harmless link into a token-stealing threat.

Analyst 207
Dark web marketplace setup with laptop and papers in dimly lit room.

AI-Powered Cybercrime Tools Flood Dark Web Marketplaces

The dark web has seen a staggering 3,810% surge in AI-powered cybercrime tools, with posts skyrocketing from 38 in December to 1,486 in February, signaling a new wave of threats. This alarming trend has experts like Cynthia Kaiser, SVP of the Ransomware Research Center at Halcyon, warning that cyber threats have become the "national security challenge of our lifetime."

Analyst 207
Crowded gaming center with gamers playing, some showing concern on their faces.

Malware Campaigns Target Gamers, 86K Infected by CountLoader

A shocking 86,000 gamers have fallen victim to CountLoader, a sneaky malware campaign that's been targeting players since January 2026, and the masterminds behind it are making it easy for others to join the malicious party with their free, user-friendly malware service.

Analyst 207
Minecraft game setup on a laptop on a cluttered desk with a smartphone and tablet nearby.

WeedHack Malware Targets 116,000 Minecraft Systems Worldwide

Over 116,000 Minecraft systems worldwide have fallen victim to the WeedHack malware campaign since January, with an alarming rate of 2,000 to 3,000 infections daily. This massive operation has spread its reach across the US, Germany, India, and the UK, affecting a staggering number of users.

Analyst 207
Ransomware workspace with Russian map and computer screens in dim light.

Ransomware Operator Flouts Unwritten Rule, Hits Russia

A shocking move by a ransomware operator has sent shockwaves through the cybercrime underworld: they've brazenly targeted Russia, flouting an unwritten rule that's long been observed by hackers. This bold - and some might say, boneheaded - decision has left many in the cybersecurity community scratching their heads.

Analyst 207
Child's bedroom with Minecraft bedspread and gaming setup, laptop screen showing blurred game environment.

WeedHack Malware Infects 116,000 Minecraft Systems Worldwide

A massive malware campaign, dubbed WeedHack, has infected a staggering 116,464 Minecraft systems worldwide since January, with a whopping 2,000 to 3,000 new infections occurring daily. The widespread attack has hit the US, Germany, India, and the UK the hardest.

Analyst 207
Blurred laptop screen and documents on a desk in a typical office setting.

AI-Built Ransomware Toolkit Evades EDR Solutions with Automated Attacks

Sophos researchers uncovered a sophisticated AI-built ransomware toolkit that cleverly evades detection by automated security solutions, triggering alerts only after it had already compromised a customer system. The toolkit's sinister purpose was revealed through investigation, which found references to a ransom note and a list of targeted organizations on a dark web leak site.

Analyst 207
Cluttered office desk with laptop, router, and papers, softly glowing in a cityscape-lit room.

Gamaredon Exploits WinRAR Flaw to Deliver GammaWorm, GammaSteel Malware

Cyber attackers have cleverly exploited a WinRAR flaw to unleash a potent malware duo, GammaWorm and GammaSteel, with the goal of taking control of infected systems and executing malicious scripts. This sneaky tactic, spotted by French cybersecurity firm Sekoia, allows hackers to fingerprint host systems, manipulate network settings, and fetch additional payloads from command and control servers.

Analyst 207
Laptop screen shows a browser window with a webpage, set against a blurred office or city background.

Browser Becomes Front Line in AI Security Battle

The battle for AI security is heating up, and the browser has become the front line - with security teams facing a double threat of AI-powered attacks converging in this critical space. Attackers are leveraging AI to supercharge phishing techniques, including device code phishing kits that have surged 18x in just one year.

Analyst 207
Smartphone with chatbot interface on screen, conveying vulnerability.

Hackers Exploit Instagram AI Chatbot to Hijack User Accounts

Hackers recently tricked Instagram's AI chatbot into handing over account controls, highlighting a critical vulnerability in AI agent authorization - a problem that's proving tougher to crack than authentication. By falsifying user locations and manipulating the chatbot, attackers were able to change account email addresses and passwords.

Analyst 207
Dimly lit computer workstation with code on laptop screen, surrounded by computer hardware and security research books.

Microsoft Threatens Security Researcher Over Windows Exploits

A mysterious security researcher known as "Nightmare Eclipse" has unleashed a string of powerful Windows exploits, including one that can bypass BitLocker, leaving Microsoft scrambling to respond. The bold move has sparked a tense standoff between the researcher and the tech giant.

Analyst 207
Brightly-lit operation center with multiple workstations and cityscape background, hinting at network infrastructure.

Malvertising Campaign Targets macOS with FlutterShell Backdoor

Google swiftly suspended advertiser accounts linked to a massive malvertising campaign that spread a new macOS backdoor, known as FlutterShell, after researchers sounded the alarm. The culprits, tracked by Palo Alto Networks as CL-CRI-1089, used hundreds of verified Google ads and a web of shell companies to deceive ad networks.

Analyst 207
Smartphone displaying a login page on a neutral surface with a blurred office background.

Hackers Exploit Meta's AI Bot to Hijack Instagram Accounts

This weekend, hackers exploited a vulnerability in Meta's AI-powered customer support tool to hijack high-profile Instagram accounts, highlighting the platform's notoriously poor human support infrastructure. A simple sequence of steps, documented in a video circulated on Telegram, allowed attackers to add a new email address to an account and seize control.

Analyst 207
Laboratory setting with computer workstations, coding terminals, and testing equipment.

Threat Actor Leverages AI to Craft EDR Evasion Tools

Sophos X-Ops stumbled upon a secret laboratory while investigating a routine endpoint alert, uncovering a trove of AI-powered tools designed to sneak past modern EDR agents. The surprising discovery revealed a sophisticated operation using partly AI-generated Python scripts to craft evasive tools.

Analyst 207
Laptop screen displays ominous code in dimly lit workspace.

Red Hat npm Scope Hijacked to Spread Cloud Credential Malware

In a shocking 72 seconds, an attacker hijacked Red Hat's npm scope to spread malware, publishing 32 malicious packages that racked up nearly 10 million downloads. The sneaky move exploited the trust developers have in Red Hat's official namespace, turning it into a conduit for cloud credential malware.

Analyst 207
Afghan government office with computer workstation and stacks of papers.

SideCopy Targets Afghan Finance Ministry with Xeno RAT Malware

Seqrite Labs researchers uncovered a sneaky malware attack, dubbed Operation XENOFISCAL, where the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance and government officials with a cleverly crafted phishing lure written in Pashto. The attack used Xeno RAT Malware, delivered through a ZIP archive with a malicious LNK file, to infiltrate its targets.

Analyst 207