Tag: malware operations
619 articles

Microsoft Exposes TerminalFix Attacks Deploying Reverse Tunnels
Beware of TerminalFix attacks that use fake Cloudflare CAPTCHA prompts on compromised websites to trick you into executing malicious PowerShell commands in Windows Terminal. These sneaky attacks can lead to more complex threats, making it crucial to stay vigilant online.

Microsoft Warns of TerminalFix Malware Hiding in PNGs
Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Anthropic Disrupts AI Token Mining by Hijacked User Accounts
Anthropic swiftly took action against compromised accounts, logging users out and removing payment methods to prevent stolen sessions from being exploited for paid AI usage. The company assured users that its investigation found no link between the malware and its AI model, Claude.

Silver Fox Exploits Adware to Deploy ValleyRAT Backdoor
Meet Silver Fox, a sneaky threat actor that's been using adware to disguise a powerful backdoor called ValleyRAT, which can give attackers full control over your computer. They've even hijacked a legitimate Chinese desktop wallpaper tool to spread their malicious software.

ValleyRAT Exploits Adware to Evade Detection
Meet ValleyRAT, a sneaky backdoor that's been evading detection with the help of adware, infecting over 1500 users in China and India with a staggering 100,000 detections in 2026 alone. Its clever disguise was uncovered when researchers dug deeper into a suspicious installer initially labeled as ordinary adware.

Anthropic Warns of Infostealer Malware Hijacking Claude Sessions
Beware of infostealer malware that's hijacking Claude sessions! Anthropic is taking swift action to protect users, including signing them out of compromised accounts, removing saved payment methods, and offering refunds for unauthorized charges.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs
Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Malicious Extensions Target Chrome, Edge Users With Crypto-Draining Code
Beware: malicious Chrome extensions have been discovered that can secretly drain your cryptocurrency wallet! Security researchers uncovered a sneaky campaign that uses 19 extensions to steal wallet secrets and drain crypto funds.

SVG Attachments Fuel Large-Scale Phishing with JavaScript Smuggling
A massive phishing campaign, detected in over 5,500 organizations, used sneaky JavaScript smuggling tactics to evade native defenses, with a whopping 26,589 messages sent over just two months. The attackers cleverly exploited SVG attachments and voicemail lures to spread executable code.

Ransomware Actors Exploit AI Tool in Sophisticated Attacks
Ransomware attackers are now using AI tools like Claude Sonnet to supercharge their assaults, with one group successfully exploiting the technology to target 10 victims in just a few weeks. By leveraging advanced tools like SpaceX's Cursor Agent, these cybercriminals are refining their tactics and getting bolder.

CRPx0 Ransomware Service Rapidly Expands, Targets 48 Organizations
CRPx0's ransomware service has exploded onto the scene, rapidly expanding its reach to target a staggering 48 organizations - a number that's skyrocketed from fewer than 10 just a few months ago. This alarming growth follows the group's shift from a basic hacking service to a full-fledged, white-label ransomware operation.

China Exploits US Infrastructure in Widespread Hacking Campaign
The US Department of Justice has taken a major stand against China's widespread hacking campaign, disabling malicious software and seizing two key hacking platforms, QScan and QTRouter, to protect America's critical infrastructure. This decisive action is a significant blow to state-sponsored hackers preying on the US, with the Attorney General vowing to use every tool at their disposal to keep the American people safe.

ICS Threats Decline, But Biometrics Sector Remains Vulnerable
The threat landscape for industrial control systems (ICS) is showing a welcome decline, with only 19.15% of ICS computers encountering blocked malicious objects in Q2 2026 - the lowest level since 2022. However, amidst this positive trend, one sector remains alarmingly vulnerable: biometrics.

Australia Charges Two in TeamPCP Cybercrime Case Tied to Supply Chain Attacks
In a major breakthrough, the Australian Federal Police charged two men with 14 offences for their alleged roles in the notorious TeamPCP cybercrime syndicate, which compromised over 1,000 organizations worldwide and stole more than 500,000 credentials. The suspects, aged 23 and 21, were arrested and appeared in court after a joint operation seized electronic devices for forensic analysis.

Spark RAT Campaign Targets Cambodia, Abuses OPSWAT Driver to Disable Security Tools
A new Spark RAT campaign is targeting Cambodia, using clever tactics like phishing emails and signed DLLs to disable security tools and sneak malicious payloads into victims' systems. The attackers are casting a wide net with diverse lure themes, trying to catch as many unsuspecting victims as possible.

GoCaracal Malware Exploits Ethereum for Covert C2 Communications
Researchers have uncovered a sneaky new malware, GoCaracal, that uses Ethereum to secretly communicate with its controllers, and with medium confidence, they've linked it to the notorious Dark Caracal group. This clever malware was used in a recent attack on a Venezuelan communications organization.

FBI Disrupts Chinese Hacking Tools Targeting US Critical Networks
The FBI has successfully disrupted a Chinese hacking operation, seizing two malicious platforms - QScan and QTRouter - used to target high-value US networks and critical infrastructure. This significant takedown thwarts a major threat to US security, thanks to the Justice Department's court-authorized seizures of key domains.

Iranian Hacker Group Expands Arsenal with Advanced Backdoor, SSH Tunneler
Meet the Iranian Hacker Group that's expanding its cyber espionage arsenal with advanced tools, potentially setting its sights on a broader target list that includes Middle Eastern and European countries. Their latest moves suggest a more aggressive and sophisticated approach to digital spying.

Tortoiseshell Malware Toolkit Expands with New Backdoor, SSH Tunneling
Meet Tortoiseshell, a stealthy malware toolkit that's been lurking in the shadows since 2018, and just got a nasty upgrade with a new backdoor and SSH tunneling capabilities. This cyber-espionage group's toolkit expansion could spell trouble for defense, aerospace, and military organizations worldwide.

SLEEPWALKER Backdoor Exploits Windows for Stealthy Command Execution
Meet SLEEPWALKER, a sneaky new Windows backdoor that's been flying under the radar, allowing attackers to execute commands stealthily. This highly sophisticated malware is designed to evade detection, suggesting a targeted and well-resourced operation.

Hackers Exploit npm Mirrors to Host Phishing Pages
Hackers are exploiting npm mirrors to host phishing pages by uploading malicious HTML files to the npm registry, which are then mirrored and can be accessed directly in a browser. This clever tactic turns the trusted registry into a free web host for malware, allowing threat actors to spread phishing pages under the guise of legitimate content.

AI-Enabled Malware Detected but Not Dominant
The surprising truth about AI-enabled malware: despite collecting 405 samples, only 12 actually appeared on customer endpoints, revealing a significant gap in detection. This finding highlights the limited presence of AI-powered threats in the wild.

Malware Campaign Exploits FTP Banners to Deliver E4del and PINHOLE RATs
Malware attackers have found a sneaky way to control infected computers by hiding commands in plain sight - specifically, within the welcome messages that FTP servers send when you log in. This clever trick lets hackers use FTP server banners as secret instructions for their malicious software, E4del and PINHOLE.

npm Packages Host Fake Cloudflare CAPTCHA Pages via Unpkg Mirrors
Researchers uncovered a sneaky scam where attackers hide a fake Cloudflare CAPTCHA page inside harmless-looking npm packages, using mirrors to trick victims into revealing sensitive info. This clever tactic relies on exploiting trusted domains to deploy a ClickFix-style scam that redirects users to attacker-controlled infrastructure.