Skip to main content

Malware & Ransomware

Government office interior with computers and a large window, featuring a subtle network diagram in the background.

China-Linked GopherWhisper Targets Mongolian Government Systems with Go Backdoors

A China-linked cyber group, dubbed GopherWhisper, has been targeting Mongolian government systems with a suite of Go-based backdoors, infecting at least 12 systems and potentially dozens more. The attackers used clever tactics, routing command-and-control traffic through compromised Discord and Slack servers.

Analyst 207
Cluttered office workspace with computer and browser on desk, cityscape outside window.

Researchers Expose AI Agents to Malicious Prompt Injection Payloads

Imagine a browser AI that can summarize web pages, but with a hidden vulnerability that allows malicious instructions to be embedded and executed - a newly discovered threat that security researchers are warning deserves our attention. Forcepoint researchers have uncovered 10 real-world examples of indirect prompt injection payloads designed to subvert AI agents and wreak havoc.

Analyst 207
Security analysts work at a conference table in a brightly-lit operations center with computer screens and network equipment.

Mirai Campaign Exploits RCE Flaw in Obsolete D-Link Routers

In early March 2026, Akamai's Security Incident Response Team detected a Mirai botnet campaign exploiting a critical vulnerability, CVE-2025-29635, in outdated D-Link routers, enlisting vulnerable devices into a botnet through automated attacks. This flaw in D-Link DIR-823X series routers puts countless devices at risk of being hijacked.

Analyst 207
Secure operations center with analysts, computer screens, and VMware ESXi and Windows servers displayed.

Kyber Ransomware Targets Windows, VMware with Post-Quantum Encryption

Meet the Kyber Ransomware, a potent threat that targets both Windows and VMware environments with cutting-edge, post-quantum encryption. This sophisticated malware has been found to strike multiple systems at once, as seen in a March 2026 incident where two variants were deployed on the same network.

Analyst 207
Security analysts respond to a cyber threat in a brightly-lit operations center with laptops and screens displaying code…

Malware Worm Exploits npm Packages to Hijack Developer Tokens

Meet CanisterSprawl, a sneaky self-propagating worm that's compromising npm packages and using stolen developer tokens to spread its reach. This malware goes beyond just stealing credentials, turning one infected environment into a web of additional package compromises.

Analyst 207
Security analysts work at desks with laptops and monitors displaying code and system maps in a brightly-lit operations…

MacOS Attacks Evolve, Exploiting Native Tools for Stealth

As macOS use surges in enterprise environments, accounting for over 45% of organizations, attackers are getting creative - exploiting native tools like Remote Application Scripting, Terminal, and AppleScript to stealthily run code, move undetected, and evade security measures. Cisco Talos warns that these tactics allow hackers to issue malicious instructions across processes and systems without triggering conventional monitoring.

Analyst 207
Security analyst's workstation with multiple screens displaying code and threat analysis tools in a neutral office setting.

Harvester Expands Linux Arsenal with GoGra Backdoor in South Asia

Harvester's Linux arsenal just got a boost with the deployment of the GoGra backdoor in South Asia, enabling the threat actor to sneak past traditional network defenses by hijacking legitimate Microsoft Graph API and Outlook mailboxes. This latest move is linked to Harvester's earlier espionage campaigns targeting key sectors in the region.

Analyst 207
Police officers surrounded by computer equipment and manga books in a brightly lit institutional setting.

Spanish Police Disrupts $4.7M Manga Piracy Platform, Arrests Four

In a major crackdown on piracy, Spanish police have shut down a massive manga piracy platform that had been illegally providing access to millions of copyrighted works since 2014, and arrested four individuals in connection with the operation. The platform's systematic infringement had amassed a huge following, but ultimately led to the authorities taking action.

Analyst 207
Damaged computer equipment and cables in a dimly lit server room.

Lotus Wiper Malware Disrupts Venezuelan Energy Sector

Cybersecurity researchers uncovered a highly destructive malware, known as Lotus Wiper, that was used to disrupt Venezuela's energy sector in a targeted attack. This powerful data wiper was deployed in a series of devastating attacks at the end of 2025 and beginning of 2026.

Analyst 207
Former ransomware negotiator sits contemplative in dimly lit room with laptop and papers.

Former Ransomware Negotiator Pleads Guilty to Aiding BlackCat Cyber Gang

A former ransomware negotiator turned rogue, Angelo Martino has pleaded guilty to aiding the notorious BlackCat cyber gang, betraying his employer and the industry he was meant to serve. By secretly collaborating with BlackCat, Martino launched devastating ransomware attacks, causing harm to innocent victims and lining his own pockets.

Analyst 207
Cluttered workspace with Linux terminal and laptop, cityscape outside, surrounded by notes and coffee cups.

Harvester Malware Exploits Microsoft Graph API for Stealthy Linux Attacks

Meet Harvester, a stealthy espionage group believed to be state-backed, that's been secretly targeting telecommunications, government, and IT organizations in South Asia since 2021. Their latest trick? A Linux-capable GoGra backdoor that uses Microsoft Graph API for covert communications.

Analyst 207
Laptop screen displays code with cityscape visible through window in background.

Mustang Panda Expands LOTUSLITE Malware to Target India, Korea

Meet the evolved LOTUSLITE backdoor, now wielding dynamic DNS-based command-and-control over HTTPS, enabling its operators to remotely access and manipulate targeted systems for espionage purposes. This sophisticated malware supports remote shell access, file operations, and session management, a potent toolkit for data collection and access persistence.

Analyst 207
Dimly lit server room with a highlighted server and a shadowy figure working on a laptop amidst cables and equipment.

Unpatched SharePoint Servers Exposed to Ongoing Spoofing Attacks

Over 1,300 Microsoft SharePoint servers are still vulnerable to a spoofing attack, despite a security update being available since last week, leaving them exposed to ongoing exploitation by hackers. This comes after Microsoft warned that the CVE-2026-32201 vulnerability was exploited as a zero-day, and attackers are continuing to abuse it in widespread campaigns.

Analyst 207
Former ransomware negotiator sits in federal courtroom, looking down with hands clasped, surrounded by financial documents…

Former Ransomware Negotiator Pleads Guilty to Extortion Scheme

A former ransomware negotiator has pleaded guilty to masterminding a brazen extortion scheme that raked in a staggering $75.3 million, exploiting his position to secretly collude with ransomware gangs and betray the very companies he was supposed to protect. Angelo John Martino III faces up to 20 years in prison for his role in the conspiracy.

Analyst 207
Locked hospital room with faint light, bed, medical equipment, and laptop displaying ransomware message.

Ex-FBI Chief Urges Homicide Charges for Ransomware Actors Tied to Patient Deaths

It's time to hold ransomware attackers accountable for their deadly actions - Cynthia Kaiser, ex-FBI chief, urges prosecutors to consider felony homicide charges when attacks on hospitals result in patient deaths. Closing the gap between crime severity and consequences is crucial, she stresses.

Analyst 207
Abandoned study with laptop displaying ransomware warning, eerie blue glow, and ghostly suit-clad figure in background.

Gentlemen Ransomware Operation Exposes 1,570 Victims Through SystemBC Malware

A shocking 1,570 networks worldwide have been compromised by the sneaky SystemBC malware, which has been quietly building a massive botnet of victims across the globe. This stealthy threat can even download and execute additional malware, putting your security at risk.

Analyst 207
Destroyed electrical substation at dusk with rubble, shattered phone, and scattered papers amidst ominous cityscape.

Lotus Malware Targets Venezuelan Energy Firms with Data-Wiping Attacks

A new, highly destructive malware called Lotus has been targeting Venezuela's energy sector, leaving systems completely unrecoverable after wiping data and disabling recovery mechanisms. This devastating attack systematically deletes files and overwrites physical drives, causing irreversible damage.

Analyst 207
Person sitting in dark room with laptop showing fake login prompt and nearby smartphone and torn paper with credentials.

macOS ClickFix Attacks Harvest Credentials via AppleScript Stealers

macOS users beware: a sneaky ClickFix campaign is using AppleScript stealers to harvest credentials from 14 browsers, 16 cryptocurrency wallets, and over 200 extensions. This targeted attack has already made off with a staggering amount of sensitive info - and it's still on the loose.

Analyst 207
Cracked smartphone screen next to discarded smart card with eerie interface and cursor on sensitive file in background.

Malware Exploits Android App to Harvest NFC Card Data

A new malware called NGate is putting NFC payment card users in Brazil at risk, exploiting the popular HandyPay app to steal sensitive card data and PINs. This sneaky attack leaves cardholders vulnerable to financial loss and compromised personal info.

Analyst 207
Person in hoodie sits before laptop with ransom demand, cityscape behind, cash and phone discarded beside.

Ransomware Negotiator Pleads Guilty to Aiding BlackCat Extortions

Meet Angelo Martino, a 41-year-old from Florida who just pleaded guilty to helping the notorious BlackCat ransomware gang extort even bigger payouts from US companies. Martino teamed up with the BlackCat operators in April 2023, marking the start of his involvement in their malicious activities.

Analyst 207
Person in hoodie with obscured face pleading, surrounded by code and scattered items on a desk.

Scattered Spider Member Pleads Guilty to $8 Million Crypto Heist

A 24-year-old British hacker, Tyler Robert Buchanan, has pleaded guilty to masterminding an $8 million crypto heist as part of the notorious Scattered Spider cybercrime group. His downfall began with a trail of seemingly harmless text messages that ultimately led to his guilty plea.

Analyst 207
Suited figure in shadows surrounded by devices with encrypted screens.

Gentlemen Ransomware Spreads Rapidly Through Affiliate Network

Gentlemen Ransomware is spreading rapidly through its affiliate network, fueling a surge in multi-platform attacks and infections linked to the malicious tool SystemBC. This ransomware-as-a-service operation is making it alarmingly easy for cybercriminals to join the fray and wreak havoc.

Analyst 207
Person in handcuffs stands before dark cityscape with faint glow of screens.

Former Ransomware Negotiator Pleads Guilty in High-Profile Gang Case

In a shocking twist, a former ransomware negotiator has pleaded guilty to aiding the notorious ALPHV/BlackCat gang in extorting millions from US businesses, raising disturbing questions about the blurred lines between victim and perpetrator. This comes on the heels of a nonprofit organization paying a staggering $26.8 million ransom.

Analyst 207
Gloved hands hover over a cracked smartphone with eerie glow and payment terminal reflection.

NGate Malware Targets Brazil, Trojanizes HandyPay for NFC Data Theft

Security researchers have uncovered a sneaky new Android malware, NGate, that has been hiding in plain sight by infecting a legitimate app called HandyPay, used for NFC data relay, and using AI-generated code to steal payment credentials. This cleverly crafted malware has set its sights on Brazil, putting unsuspecting users at risk of NFC data theft.

Analyst 207