Tag: malware operations
619 articles

ChocoPoC Malware Targets Vulnerability Researchers via Fake PoC Repos
Beware of fake proof-of-concept repositories on GitHub - a new malware called ChocoPoC is hiding in plain sight, stealing data from vulnerability researchers through a cleverly designed trap. This sneaky malware uses a dependency chain to infect systems, masquerading as a harmless Python proof-of-concept exploit.

Malware Exploits GitHub PoCs to Target Cybersecurity Researchers
Cybersecurity researchers are being targeted by a sneaky new campaign that uses malicious GitHub proof-of-concept exploits to deliver a remote access trojan, with over 2,400 downloads of a trojanized Python package already recorded. The attack unfolds through a multi-stage supply-chain trick involving compromised PyPI packages.

AI Model DeepSeek Enables Browser-Only Ransomware With Simple Prompts
Researchers have uncovered a concerning trend: nearly half of the files generated by the DeepSeek AI model - over 1,300 out of 3,000 - have been flagged as malicious or dangerous, including some that can launch browser-only ransomware with just a few simple prompts.

Malware Delivered via Trojanized GitHub Exploits Targets Security Researchers
Security researchers have been targeted by a sneaky malware campaign that uses trojanized GitHub exploits to deliver a Python-based remote access trojan, hiding in plain sight within popular proof-of-concept code repositories. The malware, downloaded over 2,400 times mostly on Linux-based systems, was spread through malicious packages cleverly concealed in dependency lists on GitHub.

Blogger Platform Exploited in VEIL#DROP Malware Attack Chain
The VEIL#DROP malware attack chain starts with a sneaky JavaScript file, cleverly disguised as a harmless document, which executes through Windows Script Host and launches PowerShell with execution policy bypasses enabled. This multi-stage threat can be triggered by spear-phishing or a simple visit to a compromised website.

Kaspersky Exposes AsyncRAT Campaign Using ScreenConnect
Malicious actors have launched a massive campaign using fake software downloads to spread the AsyncRAT malware, disguising it as popular utilities like OBS Studio and DNS Jumper. Kaspersky uncovered over 90 spoofed domains in 10 languages, hinting at a sophisticated and widespread threat.

ScreenConnect Exploited in Large-Scale Campaign Disguised as Freeware
Cybercriminals have launched a massive campaign disguising a malicious ScreenConnect installer as freeware, tricking users into downloading it from over 90 fake websites in 10 languages. The scam starts with a bogus OBS Studio download that secretly installs the ScreenConnect utility, ultimately delivering a nasty AsyncRAT payload.

Ousaban Trojan Targets Iberian Bank Users with Sophisticated PDF Lures
Meet the Ousaban Trojan, a sneaky malware targeting banking customers in Spain and Portugal with clever PDF tricks. This sophisticated threat steals logins, hijacks sessions, and even takes remote control of infected computers.

AI-Generated Ransomware Exploits Chromium API in Browser Attacks
A groundbreaking AI-generated ransomware attack has been detected, cleverly exploiting the Chromium API to launch a devastating browser-based assault, stealing credentials, exfiltrating data, and holding files hostage. This alarming first-of-its-kind threat, dubbed InfernoGrabber v9.0, marks a chilling new frontier in cybercrime.

Ousaban Trojan Expands to Spain, Portugal with Advanced Evasion Tactics
Meet Ousaban, a sneaky banking Trojan that's evolved from decade-old tactics to target unsuspecting customers in Spain and Portugal, starting with a clever phishing PDF disguised as a broken file. This highly optimized threat profiles its victims before striking, making it a force to be reckoned with.

Google Blogspot Abused to Deploy Fileless Infostealer
Cybercriminals are selling stolen credentials on underground marketplaces, giving other threat actors easy access to compromised accounts and environments. This latest threat, known as Veil#Drop, uses a sneaky fileless chain to infect victims who unknowingly download a malicious script disguised as a harmless document.

Researcher Exposes API-Driven Malware Delivery in ClickFix Campaigns
Security researcher Bert-Jan Pals' in-depth analysis of 3,000 live payloads reveals that the ClickFix campaign's API-driven malware delivery method is rapidly evolving, making it a persistent threat that's hard to defend against. This sneaky tactic moves malicious actions off the page and into backend services, issuing commands on demand with fresh disguises on every request.

LLMs Expose Software Supply Chain to Phantom Squatting Threat
Imagine a hidden threat lurking in the software supply chain, where 250,000 "phantom" domains lie waiting to be claimed by malicious actors - a vulnerability uncovered in a staggering 2.1 million URLs generated by LLMs. This phantom squatting threat has the potential to compromise security, and it's essential to understand its scope and impact.

RustDuck Botnet Evolves with Rust Rewrite to Evade Detection
Meet RustDuck, a sneaky botnet that's been evolving to evade detection since February 2026, tracked by researchers at QiAnXin's XLab. It gains a foothold by exploiting weak passwords, unpatched vulnerabilities, and targeting specific web software.

Ransomware Groups Adopt Corporate Structure to Extort Victims
Meet Black Basta, a ransomware group that operated like a corporate powerhouse, launching attacks on 520 victims across 39 industries and raking in at least $107 million in bitcoin payments. With a structured team, set schedules, and outsourced tasks, this syndicate's business model was surprisingly sophisticated.

ToddyCat APT Group Exploits Google API for Email Access
Meet ToddyCat, a sneaky APT group that's taken automation to the next level with its new tool, Umbrij - allowing it to secretly tap into corporate email and cloud resources by exploiting Google API. This stealthy move has helped ToddyCat remain undetected by monitoring systems, leaving organizations vulnerable to attack.

Malware Exploits Google Notes Extension to Steal Crypto Wallet Addresses
Malware actors are using a fake Google Notes extension to secretly steal cryptocurrency wallet addresses, and it's being delivered through sneaky unsigned installers that disguise the threat as a harmless utility. This stealthy operation, dubbed Silent Swap, uses a malicious Chromium extension to gain broad access to your browsing data and clipboard.

Malicious Chrome Extension Exploits Perplexity AI Brand for Data Collection
Beware of a fake Chrome extension hiding in plain sight: masquerading as Perplexity AI, it secretly intercepts your searches and reroutes them through attacker-controlled servers. This sneaky impostor uses a similar name and branding to the real deal, but its true intentions are far from AI-powered assistance.

CVE-2026-48558 Exploitation Deploys TaskWeaver, Djinn Stealer Malware
A critical vulnerability, CVE-2026-48558, with a maximum severity score of 10.0 is being exploited to spread two new malware families, TaskWeaver and Djinn Stealer, by turning remote monitoring servers into malware distribution points. This flaw allows attackers to bypass OpenID Connect authentication in SimpleHelp and gain a fully authenticated session.

Hackers Exploit Blockchain to Target Japan Hotels via Phishing
TrendAI Research uncovered a sneaky phishing campaign in late May 2026 that targeted hotel staff in Japan, cleverly disguising emails as guest complaints or review requests to trick employees into divulging sensitive info. The attackers stayed one step ahead, constantly updating their tactics to maximize their success.

Blackfield Ransomware Targets Nidec with $2 Million Extortion Demand
Nidec Corporation revealed that its Taiwanese subsidiary was hit by a Blackfield ransomware attack, prompting swift emergency measures to contain the breach and prevent further damage. The hackers are now demanding a whopping $2 million in extortion, threatening to leak sensitive data if their demands aren't met.

Millenium RAT Infects 60,000 Devices in Global Cyber Campaign
A new iteration of the Millenium RAT malware has infected 62,289 devices worldwide, with a staggering 39,730 compromises occurring in just the first quarter of 2026, thanks to its upgraded native C++ architecture that helps it evade detection. This powerful Telegram-controlled remote access trojan has become even more elusive in its latest version.

Hackers Exploit SimpleHelp Flaw to Deploy Djinn Stealer Malware
Hackers have found a way to exploit a flaw in SimpleHelp, using it as a trusted channel to deploy the Djinn Stealer malware and wreak havoc on managed systems. This critical vulnerability, CVE-2026-48558, allows attackers to create highly privileged accounts without authentication, putting thousands of systems at risk.

DCloud Uni-App Framework Fuels 236,000 Scam Sites
Over the past two years, a staggering 236,000 scam sites have sprouted up using the DCloud Uni-App Framework, with operators continually launching sophisticated schemes to deceive victims. These sites are being used for a wide range of fraudulent activities, from fake cryptocurrency exchanges to crypto wallet drainers.