Skip to main content

Malware & Ransomware

Scissors cut through tangled fiber optic cables with laptop glow in background, surrounded by shredded papers.

Malware Delivers ClipBanker Through Sophisticated Infection Chain

Beware of a sneaky malware that can swap out the cryptocurrency wallet address you copied with a fake one, just by pasting a malicious software masquerading as Proxifier - putting your digital assets at risk. This Trojan uses a multi-stage infection chain to deliver ClipBanker, a stealthy threat that hijacks your clipboard.

Analyst 207
Person in dark room surrounded by papers, laptop and phone glow with eerie light.

Adobe Reader Zero-Day Exploits PDFs to Profile Targets

Malicious PDFs are being used to secretly profile targets, leveraging legitimate features to harvest system data and decide which victims are worthy of a second, more invasive attack. This sneaky tactic uses booby-trapped PDFs to quietly gather intel and determine if you're a high-value target.

Analyst 207
Dark cityscape with giant cracked lock and sprawling botnet network of glowing lines and nodes, pulsing with malicious red…

Botnets Revive 13-Year-Old Apache Flaw in Global Campaign

A shocking resurgence of a 13-year-old Apache flaw has been exploited in a global campaign, highlighting the ongoing threat of old vulnerabilities getting new life. A hybrid P2P botnet and 18 other alarming stories have been uncovered, serving as a stark reminder to stay vigilant in the face of evolving cyber threats.

Analyst 207
Person in hoodie sits before laptop with cracked PDF on screen, surrounded by eerie shadows and cityscape.

Adobe Reader Zero-Day Exploited in Targeted Attacks Since December

A previously unknown zero-day vulnerability in Adobe Reader has been exploited in targeted attacks since December, using maliciously crafted PDF documents to quietly turn trusted files into stealthy threats. This highly sophisticated exploit raises serious questions about the security of everyday file formats and our trust in them.

Analyst 207
Person in a dark room clicks on a laptop icon, surrounded by faint screens and wires.

MacOS ClickFix Attack Exploits Script Editor to Evade Apple Warnings

The cat-and-mouse game continues: after Apple added security warnings to Terminal, attackers behind the Atomic Stealer family adapted their ClickFix attack to exploit Script Editor instead. This latest move shows how adversaries constantly evolve to evade detection.

Analyst 207
Shadowy figure looms over crumpled paper with ransom note and helpdesk phone number in dimly lit scene.

Google Exposes New Extortion Group Targeting BPOs and Helpdesks

A new extortion group, uncovered by Google's threat intelligence team, is setting its sights on Business Process Outsourcing (BPO) companies and helpdesks, posing a significant threat to the service layers that many businesses rely on. This emerging threat, possibly linked to the notorious "Raccoon" persona, has the potential to create widespread pressure points across multiple organizations.

Analyst 207
Cracked laptop screen lock with shadowy figure exploiting vulnerability in dark cityscape background.

Adobe Reader zero-day flaw under active exploitation

Malicious PDF documents have been hiding a nasty secret: a zero-day vulnerability in Adobe Reader that's been exploited by attackers since at least December, allowing them to spread malware and wreak havoc. This stealthy threat highlights the urgent need for better detection and response to these types of attacks.

Analyst 207
Dimly lit gaming setup with laptop screen displaying suspicious software offer, surrounded by gaming accessories and empty…

Malware Targets Gamers with Dubious Software Offers

Malware is taking aim at gamers with sneaky software offers that promise enticing perks, like "+15 armor protection" - but beware, these deals come with a hidden catch. Cyber threats are disguising themselves as tempting game enhancements, putting players at risk.

Analyst 207
Hooded figure in shadows types on laptop surrounded by screens displaying ominous code and ransom demands.

Amateur Hackers Emerge as Growing Ransomware Threat

Ransomware is now the biggest threat today, and a growing concern is amateur hackers who may not know what they're doing - which can make it even harder to recover your data. According to Cynthia Kaiser, a cybersecurity veteran with two decades of FBI experience, these newcomers pose a particularly worrisome risk.

Analyst 207
Laptop screen displays small, hidden SVG padlock image amidst code, with blurred phone and scattered credit cards nearby.

Hackers Conceal Credit Card Stealer in Tiny SVG Images

One tiny pixel can cause massive damage: hackers have successfully hidden credit card-stealing code inside a nearly invisible, one-pixel Scalable Vector Graphics (SVG) image, putting almost 100 Magento-based online stores at risk. This sneaky tactic allowed the malicious code to blend in with normal site assets, evading detection.

Analyst 207
Person sits in dimly lit room surrounded by broken tech, laptop displays fake error message.

macOS Users Targeted in ClickFix Malware Campaign

macOS users are being targeted in a sneaky new malware campaign called ClickFix, which tricks them into executing malicious commands by abusing the Script Editor and Terminal tools. This latest attack raises a pressing question: how can we trust our trusted tools when they're being exploited by hackers?

Analyst 207
Dimly lit server room with humming servers and tangled cables, a laptop screen in the foreground displays a distorted,…

Chaos Malware Expands to Target Misconfigured Cloud Deployments

Malware previously confined to home routers has now set its sights on cloud infrastructure, specifically targeting misconfigured cloud deployments and expanding its botnet territory. This alarming evolution in Chaos malware attacks demands attention from those responsible for securing cloud infrastructure.

Analyst 207
Dimly lit server room with humming servers and blinking lights, overlaid with a glowing global network diagram.

Masjesu Botnet Targets Global IoT Devices with DDoS-for-Hire Service

Meet Masjesu, a stealthy botnet that's been quietly building an army of compromised IoT devices to launch devastating DDoS attacks - and it's available for rent to anyone with a Telegram account. This covert network has been operating in the shadows since 2023, offering a sinister DDoS-for-hire service that's got cybersecurity experts sounding the alarm.

Analyst 207
Dimly lit journalist's workspace with scattered papers and broken pen, cityscape at dusk with ominous glow in background.

Indian-linked spyware targets MENA journalists

Researchers have uncovered a chilling spyware campaign linked to India that targeted journalists in the Middle East and North Africa, raising serious concerns about surveillance and freedom of the press. The operation, carried out by a suspected Indian government-connected group, used a potent spyware tool to secretly monitor the work of brave journalists exposing conflict, corruption, and abuse of power.

Analyst 207
Shadowy figure looms over dimly lit cityscape, laptop screen displays Eastern Europe map, nearby smartphone lies broken.

APT28 Targets Ukraine, NATO Allies with PRISMEX Malware

Russian threat actor APT28 has launched a new campaign, deploying a previously unknown malware suite called PRISMEX to target Ukraine and its NATO allies, using clever concealment techniques to evade detection. This sophisticated attack combines steganography, COM hijacking, and legitimate cloud services to stay under the radar.

Analyst 207
Darkened hospital corridor with a cracked laptop screen displaying a red lock symbol.

Ransomware Attack Cripples Dutch Healthcare Software Vendor ChipSoft

A ransomware attack has taken down ChipSoft, a Dutch healthcare software vendor, leaving many questions unanswered - but one thing is certain, the company's website is currently offline and its email system is still functioning. The extent of the damage and the identity of the perpetrators remain unclear.

Analyst 207
Shadowy figure in hoodie surrounded by screens and cables, coding on laptop with multiple terminals open.

North Korean Hackers Expand Malicious Package Reach Across Multiple Coding Ecosystems

Beware of the Trojan horse in your code: North Korean hackers have quietly infiltrated multiple package ecosystems, publishing around 1,700 malicious packages that masquerade as legitimate developer tools but act as malware loaders. This sneaky campaign, linked to the Contagious Interview group, puts developers and organizations relying on shared code on high alert.

Analyst 207
Dark industrial control room with spotlight on US map showing targeted areas and exposed industrial equipment.

Iran-Linked Hackers Target Internet-Exposed PLCs in US Infrastructure

Iran-affiliated hackers are launching targeted cyber attacks on internet-exposed devices controlling US critical infrastructure, including power plants, water systems, and manufacturing lines. This urgent threat requires immediate attention to protect vulnerable systems from devastating intrusions that can diminish functionality and manipulate operations.

Analyst 207
Darkened underground lair with modern computer equipment and a lone figure hunched over a laptop.

Ransomware Ecosystem Evolves Amid Profitability Decline

The ransomware ecosystem is evolving, with the threat remaining alarmingly widespread across industries and regions, yet the business model fueling it is showing signs of strain. This paradox has emerged as ransomware-as-a-service and specialization have driven its growth, despite declining profitability.

Analyst 207
Person intensely focused in dimly lit room surrounded by screens displaying code and Mexico maps.

Kaspersky Uncovers Horabot Campaign Targeting Mexico

Kaspersky's Security Operations Center has uncovered a complex Horabot campaign targeting Mexico, and is now sharing crucial insights on how it works and how to detect it. This critical threat intelligence will help defenders in Mexico and beyond prioritize their resources and stay one step ahead of the threat.

Analyst 207
Shadowy figure in hoodie sits before laptop with eerie glow, surrounded by clutter, with cityscape and damaged skyscrapers…

DarkSword Exploit Chain Spreads Across Threat Actors

A single iOS exploit chain, known as DarkSword, has been spreading rapidly among threat actors, allowing multiple groups to fully compromise iPhones across several countries. This compact, multi-vulnerability exploit leverages zero-day vulnerabilities to achieve complete device takeover, and was first detected in the wild in November 2025.

Analyst 207
Dimly lit industrial control room with a lone figure in shadows, surrounded by flickering computer screens and a cracked…

Iran-Backed Hackers Infiltrate US Industrial Controls

US cyber and intelligence agencies have sounded the alarm: pro-Iran hackers have infiltrated and disrupted critical US infrastructure, including water and energy systems, posing a pressing threat to national security. These foreign actors have breached government networks and industrial controls, sparking urgent concerns about the vulnerability of America's essential services.

Analyst 207
Shadowy figure in a hoodie amidst industrial complex with glowing laptop screens and cables.

TeamPCP Infiltrates Security Infrastructure with Multi-Stage Supply Chain Attack

When security tools meant to safeguard networks become the entry point for attacks, trust is shattered - and that's exactly what's happening with TeamPCP's multi-stage supply chain attacks on security infrastructure. This sinister tactic lets threat actors turn protectors into launchpads for wider compromise.

Analyst 207
Dimly lit control room with computer screens and machinery, a lone chair pushed back from a console in the foreground.

Feds Warn of Iranian Cyberattacks on US Energy, Water Systems

US government agencies have issued an urgent warning that Iranian hackers are launching targeted cyberattacks on America's energy and water infrastructure, posing a serious threat to the communities that rely on them. These attacks have already caused harm to victims in the past month, highlighting the need for immediate vigilance.

Analyst 207