Skip to main content

Tag: malware operations

619 articles

Cramped network closet with rows of equipment, patch panels, and tangled cables.

China-Linked APT Expands ORB Network with LONGLEASH Malware

Meet UAT-7810, a Chinese threat actor with a mission to build and expand Operational Relay Box (ORB) networks, which can be hijacked by other malicious groups to launch targeted attacks on high-value targets. Their latest move involves deploying the LONGLEASH malware to supercharge their ORB network.

Analyst 207
A dimly lit industrial control room with a clean, empty workstation and unoccupied chair in front of computer screens and…

Malicious Activity on Industrial Systems Declines to 3-Year Low

Malicious activity on industrial systems has hit a 3-year low, with only 19.6% of ICS computers encountering malicious objects in Q1 2026 - a significant drop of 1.4 times from Q2 2023. However, beneath the calm surface, localized spikes of threats persist, warranting close attention.

Analyst 207
Cracked software package on laptop screen with archive being extracted in background.

Vidar Stealer Campaign Exposes Code Signing Abuse and Evasion Tactics

In a clever April 2026 campaign, cyber attackers used malvertising to trick victims into downloading seemingly cracked software versions, which actually unleashed the Vidar stealer and XMRig malware via a sneaky loader called Factory-v3. The attackers cleverly hid their malware in password-protected .bin archives to evade detection.

Analyst 207
Dimly lit storefront at night with scattered neon signs and a blank smartphone screen on a cluttered counter.

RedWing Malware Targets Android Users with Bank Fraud as a Service

A new, ready-to-use bank-fraud tool called RedWing is being rented on Telegram, allowing even novice criminals to hijack Android users' phones and steal their banking information. This malicious kit is sold as a complete package, complete with step-by-step guides and how-to videos, making it alarmingly easy for scammers to get started.

Analyst 207
Dimly lit server room with rows of computer servers and networking equipment in disarray.

Cloud Worm CAI Disrupts Rivals, Steals Secrets and Mines Crypto

Meet CAI, a malicious botnet that's disrupting rival operations, swiping sensitive secrets, and mining cryptocurrency - all while eliminating competing malware to maintain its grip on compromised targets. This centralized worm is a powerhouse of credential theft and cryptomining, making it a force to be reckoned with.

Analyst 207
Person at computer looks concerned with Microsoft Teams interface blurred, suspicious message in background.

Microsoft Teams Users Targeted by Fake IT Support Scam

Beware of fake IT support scammers on Microsoft Teams who are tricking unsuspecting workers into installing malware by posing as tech support staff. These impostors are using the popular collaboration platform to deceive and compromise employee devices.

Analyst 207
Laptop screen displays Microsoft Teams call on a home office desk with a phone and headset nearby.

Microsoft Teams Abused to Deploy EtherRAT Malware via Fake IT Support Calls

Beware of fake IT support calls on Microsoft Teams - hackers are using convincing tactics, including a phishing email with a malicious PDF, to trick victims into downloading the potent EtherRAT malware. They impersonate system administrators to gain your trust, making it crucial to stay vigilant.

Analyst 207
Server room with equipment racks and monitors, a lone blank laptop screen in foreground.

Ransomware Operators Leverage AI for Autonomous Attacks

Meet JADEPUFFER, a pioneering threat actor that's harnessing AI to launch autonomous ransomware attacks - and adapting in real-time to get the job done. This groundbreaking tactic has been observed by researchers, who spotted JADEPUFFER's lightning-fast 31-second pivot from a failed login to a successful exploit.

Analyst 207
Person sits at cluttered desk with laptop and financial documents, surrounded by papers.

China-nexus Hackers Deploy DcRAT via Fake Indian Tax Utility

Cyber attackers with ties to China are pulling out all the stops to scam Indian taxpayers, using a sophisticated fake tax utility to deploy malware and pilfer sensitive info. Their precision-crafted phishing campaign, dubbed Operation DragonReturn, sends convincing emails and PDFs that even cite real laws to trick victims.

Analyst 207
Close-up of a video cable connected to a monitor with blurred background.

TrojPix Exploits Video Cables to Leak Air-Gapped Data

Meet TrojPix, a sneaky technique that can stealthily siphon air-gapped data at lightning-fast speeds of up to 1 megabyte per second - fast enough to exfiltrate a 100MB file in under two minutes while the monitor appears dark and inactive.

Analyst 207
Cluttered software development workspace with computer screens and terminals, one central laptop lid slightly ajar.

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign

North Korean hackers have unleashed a massive wave of malware, publishing 108 malicious packages and web browser extensions across popular platforms like npm, Packagist, Go, and Google Chrome as part of their sneaky PolinRider campaign. This ongoing operation has already produced 162 malicious release artifacts and compromised thousands of systems worldwide.

Analyst 207
Smart devices like TVs and streaming boxes scattered in a brightly-lit living room.

Google Disrupts NetNut Residential Proxy Network

Google's Threat Intelligence Group has disrupted NetNut, a massive residential proxy network controlling at least 2 million infected devices worldwide, including smart TVs and streaming boxes. This botnet, powered by trojanized apps and malicious software like Badbox 2.0, was used for cybercrime and espionage activities.

Analyst 207
Developer workspace with laptop, monitor, and notes, overlooking cityscape through window.

North Korea-Linked npm Packages Target Developers with Stealthy Data Theft

Malicious npm packages, linked to North Korean threat actors, are impersonating popular tools to trick developers into handing over sensitive data. These sneaky packages masquerade as legitimate polyfill tools, making them hard to spot during a quick review.

Analyst 207
Modern office buildings with subtle network infrastructure in foreground.

Qilin Consolidates Lead in Ransomware Market

Qilin is tightening its grip on the ransomware market, emerging as a leading player after a recent wave of consolidation, with an estimated 16% share of the cybercriminal market. This surge in power is a result of its technically mature infrastructure and strategic positioning in the ransomware-as-a-service (RaaS) market.

Analyst 207
Technicians investigate a large screen displaying a map of the internet in a network operations center with rows of servers…

Google and FBI dismantle 2-million device NetNut botnet

In a major win for cybersecurity, Google and the FBI have joined forces to dismantle the massive NetNut botnet, a network of 2 million devices used by cybercriminals and espionage groups to hide their malicious activities. This significant disruption is the latest in a series of efforts to take down tools used to conceal online threats.

Analyst 207
Cramped warehouse storage area with industrial computer equipment and tangled cables.

Ransomware Gang Exploits Supply Chain Attacks in New Partnership

Ransomware gangs are now operating like businesses, forming partnerships to supercharge their attacks - and a new alliance between Vect and TeamPCP is a prime example, combining massive credential theft with devastating ransomware-as-a-service operations. This unprecedented pairing puts organizations directly in the crosshairs.

Analyst 207
Cluttered home office workspace with Mac computer on desk displaying a blurred download page, with cityscape visible…

PamStealer Targets Mac Users with Fake Maccy Sites and PAM Checks

Researchers have uncovered PamStealer, a sneaky macOS information stealer that tricks users into downloading it from fake Maccy sites, and it can even slip past Apple's security measures. This clever malware uses a two-stage delivery method to steal sensitive info from unsuspecting Mac users.

Analyst 207
Law enforcement officials surround a computer server setup in a secure facility.

FBI Disrupts NetNut Proxy Platform Tied to Popa Botnet

In a major cybercrime crackdown, the FBI has seized hundreds of domains linked to NetNut, a residential proxy service allegedly tied to the massive Popa botnet, which controls at least two million devices. This disruption, made possible with the help of industry partners like Google and Lumen, marks a significant blow to the network's operations.

Analyst 207
Modern server room with rows of computer servers and a softly glowing laptop screen on a technician's workstation.

AI-Driven Ransomware Executes End-to-End Extortion Attack

Meet JadePuffer, the AI-powered ransomware agent that pulled off a brazen end-to-end extortion attack, autonomously executing every step from initial compromise to data destruction. This groundbreaking attack, detected by Sysdig researchers, marks a chilling new era in AI-driven cyber threats.

Analyst 207
Blurred malware interface on a computer screen in an office setting with coworkers in the background.

AI Compute Hijacking Exposes New Security Risks

A shocking 62,289 devices have fallen prey to the Millenium RAT, a malicious threat that's being spread through clever social engineering tactics and sold as a cheap, subscription-based service on the dark web. This alarming infection rate highlights the growing risk of small, seemingly harmless actions becoming gateways to devastating cyber attacks.

Analyst 207
Corporate office setting with laptop on desk and cityscape through window.

ToddyCat APT Exploits OAuth to Breach Gmail via Google API

Meet ToddyCat, a sneaky APT group that's been exploiting OAuth and the Google API to secretly breach corporate Gmail accounts since 2020. Their latest trick involves a cunning malware called Umbrij, which lets them hijack email communications with ease.

Analyst 207
Person at desk looks concerned while staring at laptop in a brightly-lit office setting with blurred law enforcement logo…

Ransomware Attacks Targeted via Fake Interpol Emails

Beware of fake Interpol emails that could be ransomware traps! Cybercriminals are impersonating the law enforcement agency, sending unsolicited emails with suspicious links and password-protected files, trying to trick organizations into compromising their security.

Analyst 207
Person sitting at desk with laptop, hands paused over keyboard, conveying caution.

Opera Introduces Paste Protect to Thwart ClickFix Attacks

Opera's new Paste Protect feature helps keep you safe from sneaky ClickFix attacks by automatically blocking suspicious copy actions that could land malware on your device. This clever tool outsmarts scammers who try to trick you into pasting malicious commands, protecting you from unwanted surprises.

Analyst 207
Network operations room with computer servers and equipment showing signs of affected infrastructure.

FortiBleed Exposes Link to Ransomware Ops

A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.

Analyst 207