Tag: malware operations
621 articles

Malware Hidden in Hentai Games Exposes Users to Full System Compromise
Beware of hentai games that seem too good to be true - a new malware campaign has been discovered that hides in these games and can fully compromise your system. Hundreds of users, mainly in Russia, Brazil, Germany, and Vietnam, have already fallen victim to this threat, dubbed Argamal.

WeedHack Malware Targets 116,000 Minecraft Systems Worldwide
Over 116,000 Minecraft systems worldwide have fallen victim to the WeedHack malware campaign since January, with an alarming rate of 2,000 to 3,000 infections daily. This massive operation has spread its reach across the US, Germany, India, and the UK, affecting a staggering number of users.

Ransomware Operator Flouts Unwritten Rule, Hits Russia
A shocking move by a ransomware operator has sent shockwaves through the cybercrime underworld: they've brazenly targeted Russia, flouting an unwritten rule that's long been observed by hackers. This bold - and some might say, boneheaded - decision has left many in the cybersecurity community scratching their heads.

WeedHack Malware Infects 116,000 Minecraft Systems Worldwide
A massive malware campaign, dubbed WeedHack, has infected a staggering 116,464 Minecraft systems worldwide since January, with a whopping 2,000 to 3,000 new infections occurring daily. The widespread attack has hit the US, Germany, India, and the UK the hardest.

AI-Built Ransomware Toolkit Evades EDR Solutions with Automated Attacks
Sophos researchers uncovered a sophisticated AI-built ransomware toolkit that cleverly evades detection by automated security solutions, triggering alerts only after it had already compromised a customer system. The toolkit's sinister purpose was revealed through investigation, which found references to a ransom note and a list of targeted organizations on a dark web leak site.

Gamaredon Exploits WinRAR Flaw to Deliver GammaWorm, GammaSteel Malware
Cyber attackers have cleverly exploited a WinRAR flaw to unleash a potent malware duo, GammaWorm and GammaSteel, with the goal of taking control of infected systems and executing malicious scripts. This sneaky tactic, spotted by French cybersecurity firm Sekoia, allows hackers to fingerprint host systems, manipulate network settings, and fetch additional payloads from command and control servers.

Malvertising Campaign Targets macOS with FlutterShell Backdoor
Google swiftly suspended advertiser accounts linked to a massive malvertising campaign that spread a new macOS backdoor, known as FlutterShell, after researchers sounded the alarm. The culprits, tracked by Palo Alto Networks as CL-CRI-1089, used hundreds of verified Google ads and a web of shell companies to deceive ad networks.

Threat Actor Leverages AI to Craft EDR Evasion Tools
Sophos X-Ops stumbled upon a secret laboratory while investigating a routine endpoint alert, uncovering a trove of AI-powered tools designed to sneak past modern EDR agents. The surprising discovery revealed a sophisticated operation using partly AI-generated Python scripts to craft evasive tools.

Red Hat npm Scope Hijacked to Spread Cloud Credential Malware
In a shocking 72 seconds, an attacker hijacked Red Hat's npm scope to spread malware, publishing 32 malicious packages that racked up nearly 10 million downloads. The sneaky move exploited the trust developers have in Red Hat's official namespace, turning it into a conduit for cloud credential malware.

SideCopy Targets Afghan Finance Ministry with Xeno RAT Malware
Seqrite Labs researchers uncovered a sneaky malware attack, dubbed Operation XENOFISCAL, where the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance and government officials with a cleverly crafted phishing lure written in Pashto. The attack used Xeno RAT Malware, delivered through a ZIP archive with a malicious LNK file, to infiltrate its targets.

Malware Worms Red Hat npm Packages, Targets Cloud Credentials
A single compromised Red Hat employee's GitHub account was used to seed dozens of Red Hat npm package releases with a self-propagating credential-stealer, putting cloud credentials at risk. The malicious packages, downloaded around 80,000 times a week, are still considered a live threat.

WordPress Sites Targeted in Steam Profile Malware Campaign
A massive malware campaign has infected nearly 2,000 WordPress websites, using a sneaky tactic of hiding command-and-control data within Steam Community profile comments. The attack, first detected in July 2025, has left security experts scrambling to uncover its entry point.

China-Aligned Hackers Target Czech Republic, Taiwan in Cyber Espionage Push
China-aligned hackers have launched a sneaky cyber espionage campaign, dubbed Operation Dragon Weave, targeting officials and citizens in the Czech Republic and Taiwan with a cunning malware that masquerades as a legitimate cloud storage service. The malware ultimately delivers an AdaptixC2 agent, putting sensitive information at risk.

FSB-Linked Worm Exploits Windows Flaw to Evade Detection
Cyber attackers have cleverly exploited a known Windows flaw, CVE-2025-8088, to sneak a malicious payload into victims' systems, allowing them to gain access and lay the groundwork for further attacks. This stealthy move was uncovered by Sekoia, which tracked the initial access stage as GammaPhish.

Dutch Police Disrupt Major Botnet Linked to 17 Million Infected Devices
Dutch authorities have successfully dismantled a massive botnet that had infected a staggering 17 million devices worldwide, turning everyday gadgets into a global attack platform. The operation, led by the Dutch Police and National Cyber Security Center, seized key servers and brought the botnet's infrastructure offline.

Dutch Police Disrupt Mystery Botnet, Seize 17M Devices
Dutch police have successfully dismantled a massive mystery botnet, freeing a staggering 17 million devices from its control. This significant disruption was made possible by tracing around 200 servers to the Netherlands and having the hosting provider shut them down.

Russia-Linked GREYVIBE Exploits AI in Ukraine Cyberattacks
Discover how the Russia-linked group GREYVIBE is using AI to launch sophisticated cyberattacks on Ukraine, leveraging tactics like spear-phishing emails and fake websites to spread malware. WithSecure researchers have tracked GREYVIBE's activities back to August 2025, revealing a pattern of attacks targeting Ukraine's military, government, and civilian sectors.

AI-Generated Malware Exposes Operator's GitHub Token
A malicious npm package, disguised as a harmless sync utility called "mouse5212-super-formatter", was downloaded 676 times before it was caught stealing sensitive data and exposing its creator's GitHub token. This AI-generated malware cleverly hid its true intentions, uploading stolen files to a fake repository and covering its tracks.

Kimsuky Expands Malware Arsenal with HTTPSpy, HelloDoor
Kimsuky, a notorious North Korean hacking group, has upgraded its malware arsenal with HTTPSpy and HelloDoor, using clever tactics like fake installation pages and a spoofed Webex meeting to infiltrate targets. The group's latest attacks involve highly tailored social engineering and real-time infection verification to maximize success.

Cybercrime Gang Targets Fans with Miner Malware via Pirated Media Sites
Millions of fans are unwittingly getting hacked when they visit popular pirated media sites, with a staggering 40 million visits to infected sites in April alone. A sneaky malware campaign is using fake video player updates to infect devices with cryptomining and remote-access malware.

GreyVibe hackers wield AI tools to fuel multi-sector cyberattacks
Meet GreyVibe, a likely Russian threat group that's been wreaking havoc across multiple sectors in Ukraine since at least August 2025, using AI-generated social engineering and custom malware to fuel its attacks. WithSecure researchers uncovered the group's activities, revealing a surprisingly unsophisticated approach despite its use of advanced AI tools like ChatGPT and Google Gemini.

Jinx-0164 Targets Crypto Developers with Custom macOS Malware
Beware of fake meetings on LinkedIn - cyber attackers are using them to trick crypto developers into installing custom macOS malware called Audiofix, which can steal sensitive info like passwords, SSH keys, and cryptocurrency wallet details. This sneaky malware is disguised as an audio fix, but its real goal is to harvest your valuable data.

GPU mining malware spreads via SEO poisoning and AI chatbot manipulation
Beware of a sneaky malware that's spreading through manipulated AI chatbot responses and search engine poisoning, tricking users into downloading GPU mining malware. Victims unknowingly stumble upon malicious links while searching for popular software or getting recommendations from AI assistants.

CrowdStrike disrupts Glassworm botnet with global takedown
In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet in a global takedown, cutting off its operators from infected machines worldwide. The infected machines now harmlessly connect to a CrowdStrike-controlled IP address, rendering the botnet useless.