Skip to main content

Malware & Ransomware

Massive tangled worm emerges from cracked package box amidst shattered screens and wires, with ominous cityscape looming in…

Self-Replicating Worm: Stunning Threat Hits 180+ Packages

A stark wake-up call: a self-replicating worm has infected 187+ NPM packages, stealing and publicly exposing developer tokens during installs. By weaponizing automated installs and transitive dependencies, it turns every npm install into a potential propagation engine.

Analyst 207
Self-Replicating Worm Hits 180+ Packages: Exclusive Danger

Self-Replicating Worm Hits 180+ Packages: Exclusive Danger

A fast-spreading self-replicating worm has already infected 180+ packages—our exclusive breakdown reveals how it spreads, who’s at risk, and the quick steps you can take to protect your projects.

Analyst 207
Bulletproof Host Exclusive: Stark’s Controversial EU Evasion

Bulletproof Host Exclusive: Stark’s Controversial EU Evasion

When the EU froze Stark Industries Solutions — a notorious bulletproof hosting provider tied to Kremlin-linked cyberattacks — the aim was to choke off dangerous infrastructure, but months later the same IPs and services resurfaced under new shells. That rapid reconstitution shows how sanctions on paper can fail when operators lean on bulletproof hosting to keep malware, botnets, and disinformation campaigns alive.

Analyst 207
Person in shadows sits before laptop with eerie glow, amidst scattered papers and a remote, with a cityscape of India in…

APT36 Exclusive: Critical Golang DeskRAT Threat to India

Heres the scoop: a targeted spear-phishing campaign installed DeskRAT—a compact, Golang-based remote access tool linked to APT36—into Indian government systems, letting attackers read emails, capture keystrokes and siphon sensitive files. Lightweight and cross-platform, DeskRAT underscores how APT36’s patient social-engineering playbook keeps compromising high-value targets.

Analyst 207
APT36 Exclusive: Golang DeskRAT Threatens India

APT36 Exclusive: Golang DeskRAT Threatens India

This autumn, a seemingly innocent spear-phish opened the door to DeskRAT, a Golang-based remote-access trojan tied to APT36 (Transparent Tribe) that slipped into Indian government networks to harvest credentials and siphon documents. Analysts warn the groups move to Go makes these cross-platform implants smaller, stealthier, and tougher to pin down—an unnerving evolution in a decade-long espionage playbook.

Analyst 207
APT36 Exclusive: Critical Golang DeskRAT Threat Hits India

APT36 Exclusive: Critical Golang DeskRAT Threat Hits India

Think a phishing email cant threaten national security? In summer 2025, tailored spear-phishing delivered Golang DeskRAT into Indian government networks — a stealthy APT36 tool that turns a single click into a strategic risk.

Analyst 207
3,000 YouTube Videos Exposed: Exclusive Malicious Network

3,000 YouTube Videos Exposed: Exclusive Malicious Network

Imagine the how‑to video you trust quietly installing a trojan — researchers have uncovered a malicious network behind 3,000+ YouTube uploads that lure viewers to downloads which deploy credential stealers, cryptominers and remote‑access trojans. By posing as tutorials and fixes and using lightweight loaders, this scalable scheme turns platform trust into a repeatable infection machine.

Analyst 207
YouTube Videos Exposed: Exclusive Dangerous Malware Alert

YouTube Videos Exposed: Exclusive Dangerous Malware Alert

Think twice before clicking — researchers have uncovered a coordinated network that’s published over 3,000 malicious videos, baiting viewers with fake tools and links that install credential stealers, cryptominers, and remote-access trojans.

Analyst 207
ThreatsDay Exclusive: Critical Crypto Fine, AI Hijack Alert

ThreatsDay Exclusive: Critical Crypto Fine, AI Hijack Alert

ThreatsDay peels back how criminals are weaponizing trust — not by inventing new tech but by exploiting convenience, stale components and lax controls, from a billion‑dollar crypto collapse to AI‑assisted hijacks and targeted smishing. Find out why ordinary systems and trusted channels are the new attack surface, and who should be closing the door.

Analyst 207
Iran-Linked MuddyWater Exclusive: Damaging 100+ Targets

Iran-Linked MuddyWater Exclusive: Damaging 100+ Targets

Imagine one hijacked mailbox becoming the battering ram: Iran‑linked MuddyWater used a trusted account, attacker‑controlled VPNs and the Phoenix backdoor to quietly worm into 100+ MENA government networks and siphon sensitive policy and personnel intelligence over months.

Analyst 207
Researchers Identify New LockBit Ransomware Victims

Researchers Identify New LockBit Ransomware Victims

LockBit is back—and meaner: its new cross‑platform payloads can hit Windows, Linux and VMware ESXi, turning a single break‑in into a crisis for hospitals, utilities and virtualized environments. Defenders must speed up containment and broaden detection beyond traditional endpoints or risk irreversible damage.

Analyst 207
ToolShell Gains Traction as Public App Exploits Surge

ToolShell Gains Traction as Public App Exploits Surge

When did a routine update become a battleground? ToolShell has quietly moved from niche reconnaissance to a go‑to exploit chain that turns public apps into launchpads for credential theft, lateral movement and ransomware — a wake‑up call that exposed services and slow patching can let attackers topple whole networks.

Analyst 207
Iran-linked MuddyWater Breach Hits 100+ Government Networks

Iran-linked MuddyWater Breach Hits 100+ Government Networks

How did one compromised mailbox become a battering ram against more than 100 government networks? Researchers say Iran-linked MuddyWater used a hijacked account and its own VPN to send convincing phishing across the Middle East and North Africa, quietly stealing credentials and siphoning sensitive intelligence — a reminder that simple, trusted tools can inflict huge damage.

Analyst 207
Feds Tie Scattered Spider Duo to $115M in Ransoms

Feds Tie Scattered Spider Duo to $115M in Ransoms

U.S. prosecutors say 19‑year‑old Thalha Jubair helped power Scattered Spiders telecom‑focused extortion ring, allegedly netting at least $115 million through SIM‑swap scams, social engineering and account takeovers. The cross‑border indictment is a stark wake‑up call that human trust, lax recovery policies and reused credentials—not exotic malware—still fuel major ransoms.

Analyst 207
Self-Replicating Worm Compromises 180+ Software Packages

Self-Replicating Worm Compromises 180+ Software Packages

What if the package you just installed quietly handed an attacker your API keys? Researchers found a self‑replicating worm in 187 npm packages that harvests secrets during install, posts them to a public GitHub repo, and uses each new install to spread and pivot into other projects.

Analyst 207
Self-Replicating Worm Infiltrates 180+ Software Packages

Self-Replicating Worm Infiltrates 180+ Software Packages

The packages you trust might be betraying you: researchers found a self‑replicating worm in 187+ NPM modules that steals developer tokens, posts them publicly, and uses those leaked credentials to replicate—turning routine installs into a spreading infection.

Analyst 207
BeaverTail and OtterCookie: Stunning Critical Threat

BeaverTail and OtterCookie: Stunning Critical Threat

Cisco Talos warns a North Korean group is fusing BeaverTail’s credential-theft with OtterCookie’s browser persistence into single, stealthier JavaScript malware that’s harder to spot — defenders should start hunting for blended behaviors and tighten basics like MFA, patching, and anomaly detection now.

Analyst 207
Rhysida ransomware: Stunningly Dangerous Threat

Rhysida ransomware: Stunningly Dangerous Threat

Microsoft revoked more than 200 fraudulent certificates after attackers used fake Teams installers to deliver the Oyster backdoor and Rhysida ransomware — a reminder that even seemingly trusted files can be malicious. Treat unexpected downloads with suspicion, enforce layered defenses, and prioritize timely revocation and certificate hygiene to stay safer.

Analyst 207
Scattered Spider Shocking $115M Ransom Scandal

Scattered Spider Shocking $115M Ransom Scandal

How did a 19‑year‑old become the alleged face of a criminal group accused of extracting $115 million in ransoms? U.S. prosecutors say Thalha Jubair and a co‑conspirator tied to Scattered Spider used social engineering and stolen credentials to hit hospitals, transit and retailers—proof that stronger defenses and international cooperation are now essential.

Analyst 207
ransomware payments: Stunning Risky Surge to $3.6M

ransomware payments: Stunning Risky Surge to $3.6M

Ransomware payments jumped 44% to an average $3.6M in 2025 as attackers shift to fewer, higher-value strikes—forcing organizations to weigh grim pragmatism against costly downtime, data leaks, and regulatory fallout.

Analyst 207
NoRobot malware: Exclusive Dangerous Threat

NoRobot malware: Exclusive Dangerous Threat

When LostKeys was exposed this spring, Coldriver didn’t fold — they reinvented, rolling out a lean, modular strain called NoRobot that sneaks past signatures, steals credentials, and blends into normal traffic. Defenders now need behavior-based detection, stronger identity controls like MFA, and faster threat-sharing to keep up with this smarter, stealthier pivot.

Analyst 207
malware vaccines: Must-Have or Risky Defense?

malware vaccines: Must-Have or Risky Defense?

Imagine tricking ransomware into thinking your Windows PC is already looted — that’s the bold idea behind “malware vaccines,” tiny spoofing markers meant to steer attackers away before they strike. Promising but far from foolproof, these proactive defenses could reduce hits if carefully tested and managed, yet they also risk breaking software, legal headaches, and an inevitable adversary response.

Analyst 207
Lumma Stealer: Shocking Risky Reputation Exposure

Lumma Stealer: Shocking Risky Reputation Exposure

A rival cybercrime group has publicly doxxed the operators behind Lumma Stealer, ripping away their secrecy and wreaking reputational havoc while creating both intelligence opportunities—and dangerous misinformation—for defenders, victims, and investigators.

Analyst 207
three new malware families: Exclusive Critical Threat

three new malware families: Exclusive Critical Threat

Heads-up: Google TAG says Russia-linked COLDRIVER has churned out three new malware families and is retooling them within days—an accelerated development pace that makes signature-based defenses brittle and raises the urgency for MFA, behavior-based EDR, and proactive threat hunting.

Analyst 207