Skip to main content

Tag: malware operations

619 articles

Windows Terminal or PowerShell window on laptop with fake CAPTCHA prompt on compromised website in background.

Microsoft Exposes TerminalFix Attacks Deploying Reverse Tunnels

Beware of TerminalFix attacks that use fake Cloudflare CAPTCHA prompts on compromised websites to trick you into executing malicious PowerShell commands in Windows Terminal. These sneaky attacks can lead to more complex threats, making it crucial to stay vigilant online.

Analyst 207
Windows Terminal or PowerShell window on a laptop screen with office background.

Microsoft Warns of TerminalFix Malware Hiding in PNGs

Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Analyst 207
Person sitting at laptop in quiet home office with blurred screen.

Anthropic Disrupts AI Token Mining by Hijacked User Accounts

Anthropic swiftly took action against compromised accounts, logging users out and removing payment methods to prevent stolen sessions from being exploited for paid AI usage. The company assured users that its investigation found no link between the malware and its AI model, Claude.

Analyst 207
Cluttered office desk with computer, papers, and tea cups, people working in background.

Silver Fox Exploits Adware to Deploy ValleyRAT Backdoor

Meet Silver Fox, a sneaky threat actor that's been using adware to disguise a powerful backdoor called ValleyRAT, which can give attackers full control over your computer. They've even hijacked a legitimate Chinese desktop wallpaper tool to spread their malicious software.

Analyst 207
A typical urban office setting with a blank laptop screen in the foreground.

ValleyRAT Exploits Adware to Evade Detection

Meet ValleyRAT, a sneaky backdoor that's been evading detection with the help of adware, infecting over 1500 users in China and India with a staggering 100,000 detections in 2026 alone. Its clever disguise was uncovered when researchers dug deeper into a suspicious installer initially labeled as ordinary adware.

Analyst 207
Person sitting at desk with laptop, looking worried, surrounded by papers and notes in a calm home office setting.

Anthropic Warns of Infostealer Malware Hijacking Claude Sessions

Beware of infostealer malware that's hijacking Claude sessions! Anthropic is taking swift action to protect users, including signing them out of compromised accounts, removing saved payment methods, and offering refunds for unauthorized charges.

Analyst 207
Person sits at desk with laptop displaying blurred CAPTCHA prompt on screen.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs

Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Analyst 207
Laptop screen on a desk in a home office with a blurred cityscape background.

Malicious Extensions Target Chrome, Edge Users With Crypto-Draining Code

Beware: malicious Chrome extensions have been discovered that can secretly drain your cryptocurrency wallet! Security researchers uncovered a sneaky campaign that uses 19 extensions to steal wallet secrets and drain crypto funds.

Analyst 207
Office desk with papers and a nearby workstation showing a blurred email inbox, hinting at disruption.

SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling

A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.

Analyst 207
Modern office workspace with laptop, papers, and coding materials on tidy desk.

Ransomware Actors Exploit AI Tool in Sophisticated Attacks

Ransomware attackers are now using AI tools like Claude Sonnet to supercharge their assaults, with one group successfully exploiting the technology to target 10 victims in just a few weeks. By leveraging advanced tools like SpaceX's Cursor Agent, these cybercriminals are refining their tactics and getting bolder.

Analyst 207
A calm office lobby with a blurred digital screen on a reception desk.

CRPx0 Ransomware Service Rapidly Expands, Targets 48 Organizations

CRPx0's ransomware service has exploded onto the scene, rapidly expanding its reach to target a staggering 48 organizations - a number that's skyrocketed from fewer than 10 just a few months ago. This alarming growth follows the group's shift from a basic hacking service to a full-fledged, white-label ransomware operation.

Analyst 207
Government building with subtle hint of network infrastructure in background.

China Exploits US Infrastructure in Widespread Hacking Campaign

The US Department of Justice has taken a major stand against China's widespread hacking campaign, disabling malicious software and seizing two key hacking platforms, QScan and QTRouter, to protect America's critical infrastructure. This decisive action is a significant blow to state-sponsored hackers preying on the US, with the Attorney General vowing to use every tool at their disposal to keep the American people safe.

Analyst 207
Modern industrial control room with computer terminals and monitoring systems on a wall, from a slightly elevated view.

ICS Threats Decline, But Biometrics Sector Remains Vulnerable

The threat landscape for industrial control systems (ICS) is showing a welcome decline, with only 19.15% of ICS computers encountering blocked malicious objects in Q2 2026 - the lowest level since 2022. However, amidst this positive trend, one sector remains alarmingly vulnerable: biometrics.

Analyst 207
Two men in formal attire stand in a courtroom with electronic devices on a table, surrounded by subtle police emblems and…

Australia Charges Two in TeamPCP Cybercrime Case Tied to Supply Chain Attacks

In a major breakthrough, the Australian Federal Police charged two men with 14 offences for their alleged roles in the notorious TeamPCP cybercrime syndicate, which compromised over 1,000 organizations worldwide and stole more than 500,000 credentials. The suspects, aged 23 and 21, were arrested and appeared in court after a joint operation seized electronic devices for forensic analysis.

Analyst 207
A cluttered Cambodian office desk with a laptop and smartphone, laptop screen blank.

Spark RAT Campaign Targets Cambodia, Abuses OPSWAT Driver to Disable Security Tools

A new Spark RAT campaign is targeting Cambodia, using clever tactics like phishing emails and signed DLLs to disable security tools and sneak malicious payloads into victims' systems. The attackers are casting a wide net with diverse lure themes, trying to catch as many unsuspecting victims as possible.

Analyst 207
Technician's workspace with laptop and cables, surrounded by rows of computer servers and networking equipment.

GoCaracal Malware Exploits Ethereum for Covert C2 Communications

Researchers have uncovered a sneaky new malware, GoCaracal, that uses Ethereum to secretly communicate with its controllers, and with medium confidence, they've linked it to the notorious Dark Caracal group. This clever malware was used in a recent attack on a Venezuelan communications organization.

Analyst 207
Rows of computer servers and networking equipment in a bright, institutional server room with screens displaying data and a…

FBI Disrupts Chinese Hacking Tools Targeting US Critical Networks

The FBI has successfully disrupted a Chinese hacking operation, seizing two malicious platforms - QScan and QTRouter - used to target high-value US networks and critical infrastructure. This significant takedown thwarts a major threat to US security, thanks to the Justice Department's court-authorized seizures of key domains.

Analyst 207
Dimly lit server room with bright laptop screen displaying a blurred network map.

Iranian Hacker Group Expands Arsenal with Advanced Backdoor, SSH Tunneler

Meet the Iranian Hacker Group that's expanding its cyber espionage arsenal with advanced tools, potentially setting its sights on a broader target list that includes Middle Eastern and European countries. Their latest moves suggest a more aggressive and sophisticated approach to digital spying.

Analyst 207
Empty workstation in front of rows of computer servers in a brightly-lit data center.

Tortoiseshell Malware Toolkit Expands with New Backdoor, SSH Tunneling

Meet Tortoiseshell, a stealthy malware toolkit that's been lurking in the shadows since 2018, and just got a nasty upgrade with a new backdoor and SSH tunneling capabilities. This cyber-espionage group's toolkit expansion could spell trouble for defense, aerospace, and military organizations worldwide.

Analyst 207
Windows desktop with laptop, notebook, and scattered papers.

SLEEPWALKER Backdoor Exploits Windows for Stealthy Command Execution

Meet SLEEPWALKER, a sneaky new Windows backdoor that's been flying under the radar, allowing attackers to execute commands stealthily. This highly sophisticated malware is designed to evade detection, suggesting a targeted and well-resourced operation.

Analyst 207
Web developer's laptop open to npm registry page in coffee shop with notes and empty browser windows nearby.

Hackers Exploit npm Mirrors to Host Phishing Pages

Hackers are exploiting npm mirrors to host phishing pages by uploading malicious HTML files to the npm registry, which are then mirrored and can be accessed directly in a browser. This clever tactic turns the trusted registry into a free web host for malware, allowing threat actors to spread phishing pages under the guise of legitimate content.

Analyst 207
Empty workstation area in a cybersecurity operations center with laptops and network equipment.

AI-Enabled Malware Detected but Not Dominant

The surprising truth about AI-enabled malware: despite collecting 405 samples, only 12 actually appeared on customer endpoints, revealing a significant gap in detection. This finding highlights the limited presence of AI-powered threats in the wild.

Analyst 207
Dimly lit server room with dusty equipment and flickering fluorescent light.

Malware Campaign Exploits FTP Banners to Deliver E4del and PINHOLE RATs

Malware attackers have found a sneaky way to control infected computers by hiding commands in plain sight - specifically, within the welcome messages that FTP servers send when you log in. This clever trick lets hackers use FTP server banners as secret instructions for their malicious software, E4del and PINHOLE.

Analyst 207
Developer workstation with laptop showing npm package page amidst coffee cups and notes, hinting at CAPTCHA scam.

npm Packages Host Fake Cloudflare CAPTCHA Pages via Unpkg Mirrors

Researchers uncovered a sneaky scam where attackers hide a fake Cloudflare CAPTCHA page inside harmless-looking npm packages, using mirrors to trick victims into revealing sensitive info. This clever tactic relies on exploiting trusted domains to deploy a ClickFix-style scam that redirects users to attacker-controlled infrastructure.

Analyst 207