Skip to main content

Tag: malware operations

619 articles

Cluttered workspace with laptop showing code on screen, surrounded by papers and coffee cups.

ChocoPoC Malware Targets Vulnerability Researchers via Fake PoC Repos

Beware of fake proof-of-concept repositories on GitHub - a new malware called ChocoPoC is hiding in plain sight, stealing data from vulnerability researchers through a cleverly designed trap. This sneaky malware uses a dependency chain to infect systems, masquerading as a harmless Python proof-of-concept exploit.

Analyst 207
Cybersecurity researcher sits at cluttered desk with laptop and papers, looking concerned.

Malware Exploits GitHub PoCs to Target Cybersecurity Researchers

Cybersecurity researchers are being targeted by a sneaky new campaign that uses malicious GitHub proof-of-concept exploits to deliver a remote access trojan, with over 2,400 downloads of a trojanized Python package already recorded. The attack unfolds through a multi-stage supply-chain trick involving compromised PyPI packages.

Analyst 207
Laptop on cluttered desk shows ransomware warning on browser window.

AI Model DeepSeek Enables Browser-Only Ransomware With Simple Prompts

Researchers have uncovered a concerning trend: nearly half of the files generated by the DeepSeek AI model - over 1,300 out of 3,000 - have been flagged as malicious or dangerous, including some that can launch browser-only ransomware with just a few simple prompts.

Analyst 207
Cybersecurity researcher working at cluttered desk with laptop and Linux devices nearby.

Malware Delivered via Trojanized GitHub Exploits Targets Security Researchers

Security researchers have been targeted by a sneaky malware campaign that uses trojanized GitHub exploits to deliver a Python-based remote access trojan, hiding in plain sight within popular proof-of-concept code repositories. The malware, downloaded over 2,400 times mostly on Linux-based systems, was spread through malicious packages cleverly concealed in dependency lists on GitHub.

Analyst 207
Laptop on a simple desk in a home office setting with a notepad and pen nearby.

Blogger Platform Exploited in VEIL#DROP Malware Attack Chain

The VEIL#DROP malware attack chain starts with a sneaky JavaScript file, cleverly disguised as a harmless document, which executes through Windows Script Host and launches PowerShell with execution policy bypasses enabled. This multi-stage threat can be triggered by spear-phishing or a simple visit to a compromised website.

Analyst 207
Cluttered office desk with laptop, papers, and storage devices.

Kaspersky Exposes AsyncRAT Campaign Using ScreenConnect

Malicious actors have launched a massive campaign using fake software downloads to spread the AsyncRAT malware, disguising it as popular utilities like OBS Studio and DNS Jumper. Kaspersky uncovered over 90 spoofed domains in 10 languages, hinting at a sophisticated and widespread threat.

Analyst 207
User downloads software from computer in home office, with fake website and zip file in foreground.

ScreenConnect Exploited in Large-Scale Campaign Disguised as Freeware

Cybercriminals have launched a massive campaign disguising a malicious ScreenConnect installer as freeware, tricking users into downloading it from over 90 fake websites in 10 languages. The scam starts with a bogus OBS Studio download that secretly installs the ScreenConnect utility, ultimately delivering a nasty AsyncRAT payload.

Analyst 207
Person working on laptop at bank desk with papers, surrounded by calm environment and natural daylight.

Ousaban Trojan Targets Iberian Bank Users with Sophisticated PDF Lures

Meet the Ousaban Trojan, a sneaky malware targeting banking customers in Spain and Portugal with clever PDF tricks. This sophisticated threat steals logins, hijacks sessions, and even takes remote control of infected computers.

Analyst 207
City office building with a laptop in foreground, hint of concern, abstract browser window.

AI-Generated Ransomware Exploits Chromium API in Browser Attacks

A groundbreaking AI-generated ransomware attack has been detected, cleverly exploiting the Chromium API to launch a devastating browser-based assault, stealing credentials, exfiltrating data, and holding files hostage. This alarming first-of-its-kind threat, dubbed InfernoGrabber v9.0, marks a chilling new frontier in cybercrime.

Analyst 207
Southern European city street with a blurred laptop on a desk in a small business district.

Ousaban Trojan Expands to Spain, Portugal with Advanced Evasion Tactics

Meet Ousaban, a sneaky banking Trojan that's evolved from decade-old tactics to target unsuspecting customers in Spain and Portugal, starting with a clever phishing PDF disguised as a broken file. This highly optimized threat profiles its victims before striking, making it a force to be reckoned with.

Analyst 207
Person sitting at laptop in dimly lit space, looking concerned.

Google Blogspot Abused to Deploy Fileless Infostealer

Cybercriminals are selling stolen credentials on underground marketplaces, giving other threat actors easy access to compromised accounts and environments. This latest threat, known as Veil#Drop, uses a sneaky fileless chain to infect victims who unknowingly download a malicious script disguised as a harmless document.

Analyst 207
Security researcher analyzing a small device under a focused light in a lab.

Researcher Exposes API-Driven Malware Delivery in ClickFix Campaigns

Security researcher Bert-Jan Pals' in-depth analysis of 3,000 live payloads reveals that the ClickFix campaign's API-driven malware delivery method is rapidly evolving, making it a persistent threat that's hard to defend against. This sneaky tactic moves malicious actions off the page and into backend services, issuing commands on demand with fresh disguises on every request.

Analyst 207
LLMs Expose Software Supply Chain to Phantom Squatting Threat

LLMs Expose Software Supply Chain to Phantom Squatting Threat

Imagine a hidden threat lurking in the software supply chain, where 250,000 "phantom" domains lie waiting to be claimed by malicious actors - a vulnerability uncovered in a staggering 2.1 million URLs generated by LLMs. This phantom squatting threat has the potential to compromise security, and it's essential to understand its scope and impact.

Analyst 207
Dimly lit network closet with scattered outdated devices and cables.

RustDuck Botnet Evolves with Rust Rewrite to Evade Detection

Meet RustDuck, a sneaky botnet that's been evolving to evade detection since February 2026, tracked by researchers at QiAnXin's XLab. It gains a foothold by exploiting weak passwords, unpatched vulnerabilities, and targeting specific web software.

Analyst 207
Cramped office with people at desks surrounded by clutter and technology.

Ransomware Groups Adopt Corporate Structure to Extort Victims

Meet Black Basta, a ransomware group that operated like a corporate powerhouse, launching attacks on 520 victims across 39 industries and raking in at least $107 million in bitcoin payments. With a structured team, set schedules, and outsourced tasks, this syndicate's business model was surprisingly sophisticated.

Analyst 207
Blurred computer screen at a corporate office workstation in bright daylight.

ToddyCat APT Group Exploits Google API for Email Access

Meet ToddyCat, a sneaky APT group that's taken automation to the next level with its new tool, Umbrij - allowing it to secretly tap into corporate email and cloud resources by exploiting Google API. This stealthy move has helped ToddyCat remain undetected by monitoring systems, leaving organizations vulnerable to attack.

Analyst 207
Browser window with generic extension interface on a laptop screen in a home office setting.

Malware Exploits Google Notes Extension to Steal Crypto Wallet Addresses

Malware actors are using a fake Google Notes extension to secretly steal cryptocurrency wallet addresses, and it's being delivered through sneaky unsigned installers that disguise the threat as a harmless utility. This stealthy operation, dubbed Silent Swap, uses a malicious Chromium extension to gain broad access to your browsing data and clipboard.

Analyst 207
Laptop on a desk with a Chromium browser window open, displaying a search results page.

Malicious Chrome Extension Exploits Perplexity AI Brand for Data Collection

Beware of a fake Chrome extension hiding in plain sight: masquerading as Perplexity AI, it secretly intercepts your searches and reroutes them through attacker-controlled servers. This sneaky impostor uses a similar name and branding to the real deal, but its true intentions are far from AI-powered assistance.

Analyst 207
Technicians work in a server room with rows of computer equipment, a laptop in the foreground with a blurred screen and…

CVE-2026-48558 Exploitation Deploys TaskWeaver, Djinn Stealer Malware

A critical vulnerability, CVE-2026-48558, with a maximum severity score of 10.0 is being exploited to spread two new malware families, TaskWeaver and Djinn Stealer, by turning remote monitoring servers into malware distribution points. This flaw allows attackers to bypass OpenID Connect authentication in SimpleHelp and gain a fully authenticated session.

Analyst 207
Hotel staff room with laptop on desk showing suspicious email on blurred screen.

Hackers Exploit Blockchain to Target Japan Hotels via Phishing

TrendAI Research uncovered a sneaky phishing campaign in late May 2026 that targeted hotel staff in Japan, cleverly disguising emails as guest complaints or review requests to trick employees into divulging sensitive info. The attackers stayed one step ahead, constantly updating their tactics to maximize their success.

Analyst 207
Industrial setting with disrupted computer screens and muted colors.

Blackfield Ransomware Targets Nidec with $2 Million Extortion Demand

Nidec Corporation revealed that its Taiwanese subsidiary was hit by a Blackfield ransomware attack, prompting swift emergency measures to contain the breach and prevent further damage. The hackers are now demanding a whopping $2 million in extortion, threatening to leak sensitive data if their demands aren't met.

Analyst 207
Smartphone on a city transit platform with blurred screen and abstract cyber threat representation.

Millenium RAT Infects 60,000 Devices in Global Cyber Campaign

A new iteration of the Millenium RAT malware has infected 62,289 devices worldwide, with a staggering 39,730 compromises occurring in just the first quarter of 2026, thanks to its upgraded native C++ architecture that helps it evade detection. This powerful Telegram-controlled remote access trojan has become even more elusive in its latest version.

Analyst 207
Technicians work in a server room with rows of computer equipment, focusing on a specific server with a blurred screen.

Hackers Exploit SimpleHelp Flaw to Deploy Djinn Stealer Malware

Hackers have found a way to exploit a flaw in SimpleHelp, using it as a trusted channel to deploy the Djinn Stealer malware and wreak havoc on managed systems. This critical vulnerability, CVE-2026-48558, allows attackers to create highly privileged accounts without authentication, putting thousands of systems at risk.

Analyst 207
Rows of servers and computers in a brightly-lit tech facility with a cityscape in the background.

DCloud Uni-App Framework Fuels 236,000 Scam Sites

Over the past two years, a staggering 236,000 scam sites have sprouted up using the DCloud Uni-App Framework, with operators continually launching sophisticated schemes to deceive victims. These sites are being used for a wide range of fraudulent activities, from fake cryptocurrency exchanges to crypto wallet drainers.

Analyst 207