Skip to main content

Malware & Ransomware

New npm Malware Campaign Exclusive: Severe Crypto Redirects

New npm Malware Campaign Exclusive: Severe Crypto Redirects

When the libraries you trust become trapdoors, developers are in for a rude awakening: a new npm malware campaign by dino_reborn hides in seven packages and uses cloaking and fake CAPTCHAs to selectively redirect victims to cryptocurrency phishing flows. This supply‑chain‑style attack evades scanners by activating only under certain conditions, turning convenience into a costly risk.

Analyst 207
Kraken Exclusive: Dangerous Ransomware Threat Escalates

Kraken Exclusive: Dangerous Ransomware Threat Escalates

Meet Kraken ransomware: an emergent cartel that borrows proven playbooks—exploiting SMB flaws, stalking networks for days, then encrypting systems and threatening data leaks—to squeeze big payouts. Cisco Talos warns this shift from scattershot attacks to precision double‑extortion raises the stakes for already overstretched defenders and demands smarter, faster responses.

Analyst 207
Dragon Breath Exclusive: Critical RONINGLOADER Gh0st RAT

Dragon Breath Exclusive: Critical RONINGLOADER Gh0st RAT

Think twice before clicking Next — researchers warn Dragon Breath is hiding a multi‑stage RONINGLOADER inside trojanized NSIS installers (masquerading as Chrome or Teams) to install a modified Gh0st RAT that gives attackers stealthy, persistent remote access for credential theft, lateral movement and data exfiltration.

Analyst 207
Cyber-Attack Deals Stunning Costly $258m Q2 Blow to JLR

Cyber-Attack Deals Stunning Costly $258m Q2 Blow to JLR

A major ransomware incident cost Jaguar Land Rover $258m in Q2 and helped drive a $639m loss — a stark wake‑up call that a single cyber‑intrusion can paralyze networked factories for weeks. The outage halted production, delayed deliveries and squeezed suppliers as JLR prioritised a cautious, forensic‑led recovery over a rushed restart.

Analyst 207
Akira Ransomware Stunning $244M Haul Sparks Severe Alarm

Akira Ransomware Stunning $244M Haul Sparks Severe Alarm

Akira ransomware has pulled in roughly $244 million since September 2025—and in some attacks thieves exfiltrated data in as little as two hours. By exploiting unpatched VPN/firewall appliances and neutralizing MFA with automated playbooks, Akira’s affiliates turn trusted defenses into rapid exit routes for high-speed extortion.

Analyst 207
IndonesianFoods Worm Exclusive: Alarming 44,000 Malware

IndonesianFoods Worm Exclusive: Alarming 44,000 Malware

Exclusive: The IndonesianFoods worm has already infected 44,000 devices. Find out how it spreads and the simple steps you can take right now to protect your data.

Analyst 207
Handcuffs and broken chain link symbolize takedown of malicious network amidst scattered cables and laptop glow.

Operation Endgame 3.0: Exclusive Critical Malware Takedown

Law enforcement’s multinational takedown that removed the Rhadamanthys infostealer, neutralized VenomRAT and dismantled the Elysium botnet is a major win for international cooperation — but as malware becomes an industrialized, modular business, experts warn this victory may only be a temporary setback for adaptable criminal networks.

Analyst 207
WhatsApp Malware Exclusive: Brazil Banks’ Worst Threat

WhatsApp Malware Exclusive: Brazil Banks’ Worst Threat

Imagine the app you use to call your mother being used to rob her bank — thats Brazils new reality as researchers link a WhatsApp-spread program called Maverick to the Coyote banking malware family. Built in .NET to decrypt, monitor and inject into banking sessions, this WhatsApp-delivered threat marks a worrying leap in scale and sophistication against Brazilian users and banks.

Analyst 207
Qilin Ransomware Exclusive: Damaging Surge Hits Small Firms

Qilin Ransomware Exclusive: Damaging Surge Hits Small Firms

Qilin ransomware has evolved into a commercialized threat that turns simple security lapses—phishing, weak credentials or exposed remote access—into crippling double‑extortion attacks on small and mid-sized firms. With affiliates and leak sites amplifying its reach, now’s the time for SMBs to shore up the basics before opportunistic criminals profit.

Analyst 207
GootLoader WordPress: Exclusive Font Trick Is Dangerous

GootLoader WordPress: Exclusive Font Trick Is Dangerous

Think an exclusive font is harmless? Think again — GootLoader is hiding malicious JavaScript in fonts and other benign WordPress assets, letting tiny site tweaks become a fast route to full-network takeovers.

Analyst 207
Weekly Recap: Exclusive Cyber Threats – Essential Alert

Weekly Recap: Exclusive Cyber Threats – Essential Alert

From Android spyware that turns phones into persistent surveillance hubs to malware hiding inside virtual machines and side‑channel leaks exposing AI chats, last week’s discoveries show attackers favor stealth and persistence over brute force. If you run systems, write policy, or just carry a smartphone, it’s time to harden mobile, VM, and AI defenses before that silent compromise finds a way in.

Analyst 207
Sandworm Exclusive: Deadly New Wiper in Ukraine

Sandworm Exclusive: Deadly New Wiper in Ukraine

When code refuses to start, who do you call? Fresh reports say the Russian-linked Sandworm group unleashed a new wiper malware that’s erasing backups and crippling Ukraine’s government, energy, logistics and grain networks—threatening cascading disruptions from ports to hospitals.

Analyst 207
Gootloader malware: Exclusive alert on Dangerous Ransomware

Gootloader malware: Exclusive alert on Dangerous Ransomware

Gootloader malware is back — a JavaScript loader that can turn a single click into a full domain takeover in roughly 17 hours. Learn how its stealthy delivery and lightning-fast lateral movement make fast, modern defenses essential.

Analyst 207
Trojanized ESET Installers Expose Stunning Harmful Backdoor

Trojanized ESET Installers Expose Stunning Harmful Backdoor

Think twice before hitting Install — a May 2025 campaign used trojanized ESET installers, convincing fake vendor pages, and targeted spear‑phishing to slip a stealthy backdoor into Ukrainian victims. This attack is a stark reminder that even trusted updates and familiar brands can be weaponized for espionage.

Analyst 207
Dark cityscape with glowing red circuit board pattern spreading across buildings, a lone figure in a hoodie sits in front…

AI-Enabled Malware: Exclusive Warning of Dangerous Rise

Imagine code that writes its own crimes — AI-generated ransomware is already spawning bespoke, evasive attacks and tailored phishing that outpace traditional defenses. Security teams worldwide are racing to detect and stop these faster, smarter threats.

Analyst 207
Dark cityscape with ominous robotic head emerging from shadows, glowing red eyes, and faint laptop screen in background.

Gemini AI Exclusive: Dangerous Thinking Robot Malware

What if the AI meant to amplify our thinking could be turned into thinking robot malware that rewrites itself to hide from defenders? New research shows attackers chaining prompt- and log-injection tricks to weaponize Gemini into self-modifying, persistent surveillance agents that sidestep many standard safeguards.

Analyst 207
Dark smartphone screen with cracked lock and eerie shadows, glowing thread weaving through cityscape, symbolizing malware…

Malware-Laden Apps: Stunning Threat in 41M Play Store Installs

Think the Play Store is safe? Researchers found hundreds of malicious Android apps that slipped past vetting and amassed tens of millions of installs—using hijacked SDKs, repackaged binaries and delayed activation to turn everyday apps into stealthy attack platforms.

Analyst 207
Russian spies Exclusive: Dangerous VM malware on Windows

Russian spies Exclusive: Dangerous VM malware on Windows

Meet Curly COMrades — a spy group that runs a tiny Alpine Linux “shadow OS” inside a hidden Hyper‑V VM on compromised Windows hosts, letting them slip past endpoint tools and quietly harvest data, credentials and long‑term access.

Analyst 207
DragonForce Cartel Exclusive Deadly Conti Ransomware Threat

DragonForce Cartel Exclusive Deadly Conti Ransomware Threat

Get an exclusive look at how the DragonForce Cartel is unleashing the deadly Conti Ransomware—and learn who’s at risk and simple steps you can take to protect yourself.

Analyst 207
Cybercrooks Exclusive: Dangerous Rise in Europe Payouts

Cybercrooks Exclusive: Dangerous Rise in Europe Payouts

Cyber extortion is escalating in worrying ways across Europe: researchers have logged at least 18 cases this year where ransomware threats are paired with physical violence. With average demands topping $200,000 and countries like France and the UK feeling the heat, the risk has shifted from data loss to public safety.

Analyst 207
Dark laptop screen with shattered glass and padlock, surrounded by papers, with a ghostly robot and ruined cityscape in the…

MIT Sloan Shelves AI Ransomware Study: Stunning Damage

MIT Sloan’s withdrawal of a paper claiming 80% of ransomware is AI-driven has ignited a fierce debate—exposing both genuine signs of AI-assisted extortion and the danger of leaping from plausible scenarios to sensational conclusions.

Analyst 207
Conti Suspect Shocking Court Debut Shows Damaging Leads

Conti Suspect Shocking Court Debut Shows Damaging Leads

A Ukrainian national’s U.S. court debut in a Conti-related ransomware case pulled back the curtain on how cybercrime now moves like commerce—crossing borders, inflicting massive economic harm, and leaving a trail of damaging leads. The indictment is just the opening move in a complex fight to hold this near‑industrial extortion trade to account.

Analyst 207
Leak Site Ransomware Victims: Alarming 13% Spike Exclusive

Leak Site Ransomware Victims: Alarming 13% Spike Exclusive

Wake-up call: ransomware victims in Europe surged 13% year‑on‑year as criminals adopt stealthy, profit-driven tactics—RATs, data theft and public leak sites—to extract bigger payoffs. Businesses, governments and households need to rethink defenses now before they become the next target.

Analyst 207
Dark cityscape with ominous server room and silhouetted figures huddled around a laptop screen.

Threat Actors Utilize AdaptixC2: Exclusive Critical Attacks

It’s alarming: attackers are hijacking AdaptixC2—an emulation framework built for defenders—to run stealthy, hard-to-disrupt ransomware campaigns, forcing security teams to rethink the tools they once trusted.

Analyst 207