Skip to main content

Malware & Ransomware

Invisible npm malware: Exclusive, Dangerous Token Theft

Invisible npm malware: Exclusive, Dangerous Token Theft

PhantomRaven quietly slipped into the npm registry, turning routine installs into token theft by harvesting credentials during install and letting attackers publish malicious updates without touching your code. One stolen token can cascade through thousands of projects—here’s why supply‑chain hygiene and MFA matter now.

Analyst 207
Defense Contractor Guilty in Stunning Costly Zero-Day Sale

Defense Contractor Guilty in Stunning Costly Zero-Day Sale

What happens when the person entrusted to build the locks quietly sells the keys? An indictment alleges a former Trenchant manager sold zero‑day exploits and offensive cyber tools to a Russian broker for about $1.3 million, potentially turning U.S. capabilities into weapons against American systems and allies.

Analyst 207
Npm Malware: Shocking Invisible Dependencies Are Dangerous

Npm Malware: Shocking Invisible Dependencies Are Dangerous

Think your npm packages are safe? Recent attacks that slipped malicious code into 126 npm packages — roughly 86,000 downloads — show how invisible dependency changes can cascade into thousands of projects, so token hygiene, 2FA and publish provenance matter more than ever.

Analyst 207
GhostCall Exclusive: Critical BlueNoroff Malware Reveal

GhostCall Exclusive: Critical BlueNoroff Malware Reveal

Meet GhostCall — a stealthy campaign tied to BlueNoroff that weaponizes low‑profile backdoors and traffic‑manipulation to quietly harvest credentials and hijack Web3 sessions. As blockchain projects scale, GhostCall and its sibling GhostHire show how openness can be turned into an espionage-and-theft platform that technologists, policy makers and users can’t afford to ignore.

Analyst 207
Qilin Ransomware Exclusive: Alarming 40+ Cases Monthly

Qilin Ransomware Exclusive: Alarming 40+ Cases Monthly

Qilin ransomware is surging — over 40 incidents monthly — using double‑extortion leak sites that weaponize stolen files into lasting reputational damage. Is your organization prepared to respond beyond just restoring backups?

Analyst 207
Dark landscape with cracked dam, lone figure amidst shattered screens and wires.

Iran’s MuddyWater Exclusive: Damaging 100+ Gov Hacks

MuddyWater turned one trusted inbox and a rented VPN into a battering ram against more than 100 government networks—proving social engineering beats flashy malware every time. Group‑IB’s forensic breakdown shows how stealthy credential theft and patient lateral movement bought months of access to critical diplomatic and government secrets.

Analyst 207
MuddyWater Stunning Breach Hits 100+ Government Networks

MuddyWater Stunning Breach Hits 100+ Government Networks

The MuddyWater campaign turned a single compromised mailbox and an attacker-controlled VPN into a battering ram, phishing its way into 100+ government networks across the Middle East and North Africa and proving that access and trust beat flashy exploits every time.

Analyst 207
Google Removes 3,000 Malicious YouTube Videos—Stunning Win

Google Removes 3,000 Malicious YouTube Videos—Stunning Win

Google removed roughly 3,000 malicious YouTube videos, dismantling a “ghost network” that lured users into downloading password‑stealing malware disguised as cheats and cracked software. It’s a practical win for online safety—fewer traps and fewer stolen credentials.

Analyst 207
Google Bold Crackdown Removes 3,000 Malicious YouTube Clips

Google Bold Crackdown Removes 3,000 Malicious YouTube Clips

Google just wiped about 3,000 seemingly harmless YouTube tutorials after researchers exposed the “Ghost Network” that used those clips to spread password-stealing malware. If a video pushes cracked software or cheats, pause and double-check the source—your passwords and payment info are worth the extra caution.

Analyst 207
Google Nukes 3,000 YouTube Videos in Stunning Malware Raid

Google Nukes 3,000 YouTube Videos in Stunning Malware Raid

Think that handy YouTube tutorial is safe? Ghost Network hid password‑stealing malware inside thousands of fake how‑tos and cracked‑software walkthroughs — Google pulled roughly 3,000 videos after researchers traced the campaign funneling victims to trojanized installers.

Analyst 207
Google Nukes 3,000 Malware YouTube Videos in Stunning Sweep

Google Nukes 3,000 Malware YouTube Videos in Stunning Sweep

Google just nuked 3,000 malware YouTube videos that used believable tutorials and “cracked” installers to sneak in a credential‑stealing payload—learn the red flags so curiosity doesn’t cost you your accounts.

Analyst 207
LockBit Exclusive: Critical New Victims Identified

LockBit Exclusive: Critical New Victims Identified

LockBit’s latest iteration is back—and meaner: researchers found a cross-platform strain in September that can encrypt Windows, Linux and VMware ESXi in a single strike, shrinking defenders’ response window and multiplying damage. If you haven’t expanded EDR to Linux and hypervisors or tested immutable backups yet, now’s the time.

Analyst 207
LockBit Exclusive: Critical New Victims Revealed

LockBit Exclusive: Critical New Victims Revealed

LockBit keeps changing its playbook—September telemetry uncovered roughly a dozen incidents, about half tied to a new strain that can hit Windows, Linux and hypervisors. That cross‑platform reach broadens the blast radius from a single breach and forces defenders to rethink old assumptions.

Analyst 207
Threat Actors: Exclusive Surge in Dangerous App Exploits

Threat Actors: Exclusive Surge in Dangerous App Exploits

Exclusive: Threat actors are unleashing a dangerous surge in app exploits—here’s what’s driving the spike and quick, practical steps to keep your apps and users safe.

Analyst 207
LockBit Ransomware Exclusive: Severe Victims Revealed

LockBit Ransomware Exclusive: Severe Victims Revealed

An updated LockBit variant—faster, stealthier and able to run native payloads on Windows, Linux and VMware ESXi—has been tied to a dozen recent intrusions, dramatically shrinking the window defenders have to detect and stop catastrophic outages.

Analyst 207
Pakistani-Linked Hacker Group: Exclusive Severe India Hack

Pakistani-Linked Hacker Group: Exclusive Severe India Hack

A Pakistani-linked hacker group reportedly pulled off a severe, exclusive cyberattack on India — here’s who’s behind it and why the fallout matters for national and regional security.

Analyst 207
Pakistani-Linked Hacker Group Exclusive: Major India Breach

Pakistani-Linked Hacker Group Exclusive: Major India Breach

A Pakistan-linked group called TransparentTribe quietly deployed the DeskRAT trojan to infiltrate Indian government networks, harvesting credentials and sensitive documents over months. The patient, espionage-focused campaign raises urgent questions about when cyber intrusions become acts of war.

Analyst 207
Hooded figure in shadows stands before dimly lit European map, laptop screen glowing with cryptic image amidst broken…

Lazarus Group Exclusive: Stunning Threat to EU Defense

Europe’s drone industry is being stalked by North Korea’s Lazarus Group, which used fake recruitment DreamJob lures to slip malware into engineers’ inboxes and siphon designs, test data and R&D secrets. The campaign shows how porous modern research networks are—and how cyber espionage can become a direct, strategic threat to EU defence and supply‑chain security.

Analyst 207
Lumma Stealer: Exclusive Report on Dangerous Vidar 2.0

Lumma Stealer: Exclusive Report on Dangerous Vidar 2.0

When stolen‑credential marketplaces start to look like legit app stores, everyone loses—Lumma Stealer’s resurgence and the reborn Vidar 2.0 (Vidar 20) are fueling a sustained, hard‑to‑detect threat through Q4 2025. Read our exclusive to learn the practical steps defenders and everyday users need now: validate IOCs, tighten MFA, and sharpen telemetry.

Analyst 207
Lumma Stealer Exclusive: Vidar 2.0 Fuels Dangerous Rise

Lumma Stealer Exclusive: Vidar 2.0 Fuels Dangerous Rise

The Lumma Stealer leak has supercharged Vidar 2.0, recycling stolen credentials and exposed code into a stealthier, cheaper toolkit for criminals. Trend Micro warns defenders to brace for rising Vidar 2.0 activity through Q4 2025.

Analyst 207
Lumma Stealer Exclusive: Upgraded Vidar 2.0 Sparks Threat

Lumma Stealer Exclusive: Upgraded Vidar 2.0 Sparks Threat

A marketplace leak proves Vidar 2.0 (Vidar 20) is evolving into a commercially sold, regularly updated threat—Trend Micro warns it will surge through Q4 2025, so defenders must choose urgent action over complacency.

Analyst 207
Lumma Stealer Vacuum Exclusive Dangerous Vidar 2.0 Upgrade

Lumma Stealer Vacuum Exclusive Dangerous Vidar 2.0 Upgrade

From the public doxxing of Lumma Stealer to the resurfacing of Vidar 2.0, the cybercrime scene is behaving more like a ruthless software market — and that escalation puts millions of credentials and finances at risk. Security teams take note: analysts expect a rise in sophisticated stealer activity through Q4 2025.

Analyst 207
Scattered Spider Duo: Exclusive Shocking $115M Ransom Link

Scattered Spider Duo: Exclusive Shocking $115M Ransom Link

Imagine lights going out at your hospital or your commute being held hostage — and the alleged architects are teenagers. The newly unsealed indictment accuses Scattered Spider of using social engineering and telecom hacks to extract at least $115M in ransoms, turning account takeovers into real‑world chaos.

Analyst 207
ShinyHunters Exclusive: Damaging Corporate Extortion Wave

ShinyHunters Exclusive: Damaging Corporate Extortion Wave

The ShinyHunters campaign has escalated from quiet database dumps to brazen public extortion—naming victims, posting timetables, and using voice‑phishing plus massive file thefts that could turn single breaches into a supply‑chain crisis. Corporations now face a stark choice: pay ransoms or risk a public dump of sensitive customer and corporate data.

Analyst 207