Skip to main content

Tag: malware operations

629 articles

Laptop on a plain surface with open screen and blurred display, beside a partially unzipped archive file.

Fake Claude AI site delivers Beagle Windows backdoor malware

Beware of a fake Claude AI site that's really a malware trap: a 505MB archive disguised as a legitimate installer delivers a sneaky Windows backdoor called Beagle. Clicking the download button on the site leads to trouble, not the AI tool you might be expecting.

Analyst 207
Software development workstation with subtle signs of compromise.

Daemon Tools Software Trojanized in Supply Chain Attack

Malware was discovered hidden in certain Daemon Tools Lite installers, prompting developer Disc Soft to issue a clean build and confirm a supply chain attack had compromised their system. A malware-free version was released within 12 hours of notification.

Analyst 207
Laptop screen displays PyPI webpage with developer workspace and team chat app in background.

PyPI Packages Deliver ZiChatBot Malware via Zulip APIs

Malicious Python packages on PyPI were found to be secretly delivering a new malware called ZiChatBot, which uses Zulip APIs to receive instructions. These seemingly harmless packages covertly dropped malicious components, highlighting the importance of vigilance when downloading code from public repositories.

Analyst 207
Windows laptop on cluttered desk with smartphone nearby, displaying blurred login screen.

CloudZ Malware Exploits Phone Link to Harvest SMS OTPs

Beware of CloudZ malware, a sneaky Windows threat that's been stealing SMS messages and one-time passwords since January 2026 by exploiting Microsoft's Phone Link app. This malicious duo, paired with the Pheno plugin, can capture mobile authentication data without ever touching your smartphone.

Analyst 207
Darkened server room with damaged server rack and scattered cables, backup storage system blurred in background.

Ransomware Attacks Expose Backup Vulnerabilities

Ransomware attackers often destroy backup systems before encrypting data, rendering your recovery plan useless. This deliberate tactic follows a predictable sequence, allowing attackers to systematically dismantle your defenses and leave you with limited options.

Analyst 207
Software development environment with laptop, PyPI webpage, and tools on a cluttered desk near a window.

OceanLotus Exploits PyPI to Deliver ZiChatBot Malware

Kaspersky's analysis uncovered a sneaky malware attack on PyPI, where OceanLotus hackers uploaded fake packages that looked like harmless libraries, tricking users into installing the ZiChatBot malware. The malicious packages, uploaded in July 2025, masqueraded as legitimate tools like uuid32-utils, colorinal, and termncolor.

Analyst 207
Laptop on a desk with Phone Link app open, smartphone nearby, in a home office setting with subtle network device hint.

CloudZ RAT Exploits Windows Phone Link for Credential Theft

Cyber attackers have cleverly exploited the Microsoft Phone Link feature to steal sensitive credentials and one-time passwords, all without needing to infect mobile devices with malware. By targeting this built-in Windows application, hackers can access synced phone data and extract valuable information.

Analyst 207
Cluttered developer's workstation with laptop and tools in a softly lit open-plan office.

Quasar Linux Malware Targets Developers with Stealthy Implant

Meet Quasar Linux, a sneaky new malware targeting developers with a potent blend of stealth, persistence, and credential theft capabilities that can compromise software supply chains. This Linux implant is quietly infiltrating dev and DevOps environments, putting cloud toolchains at risk.

Analyst 207
Software installation on a laptop in an office setting with a hint of logistics background.

Kaspersky Uncovers DAEMON Tools Supply Chain Attack

Kaspersky researchers have uncovered a sneaky supply chain attack that used compromised DAEMON Tools installers, downloaded directly from the official website, to deliver a malicious payload - and what's even scarier is that these installers were digitally signed by the very developers of DAEMON Tools themselves.

Analyst 207
Formal government building exterior with architectural columns and facade details.

China-Linked UAT-8302 Exploits Shared Malware to Target Global Governments

Meet UAT-8302, a sophisticated China-linked threat group that's been secretly targeting governments worldwide, deploying custom malware to infiltrate and gather intel. Its recent attacks have hit government entities in South America and southeastern Europe, raising global cybersecurity concerns.

Analyst 207
Windows laptop with Phone Link app open, connected to smartphone via USB, on a cluttered home office desk.

CloudZ Malware Exploits Microsoft Phone Link to Harvest SMS and OTPs

Beware: CloudZ malware is exploiting Microsoft's Phone Link feature to intercept SMS and OTPs, putting your sensitive info at risk. This sneaky attack uses a plugin called Pheno to tap into your Phone Link activity and steal your private messages.

Analyst 207
Brightly lit computer workstation with generic gaming peripherals and cables against a neutral background.

ScarCruft Expands Malware Arsenal with Multi-Platform BirdCall Backdoor

ScarCruft hackers have launched a sneaky attack on a popular video game platform, infecting both Windows and Android users with a new backdoor called BirdCall. The multi-platform threat has been targeting ethnic Koreans in China since late 2024, allowing hackers to gain unauthorized access.

Analyst 207
Person sitting at desk in dimly lit office, looking at laptop screen with phishing email, surrounded by papers and…

Silver Fox Targets India, Russia with ABCDoor Malware via Tax Phishing

Meet Silver Fox, a China-based cybercrime group that's using tax phishing scams to deliver a sneaky new malware called ABCDoor, targeting India and Russia with cleverly crafted emails that masquerade as official tax notices. The group's tactics involve PDFs with links to infected archives, tricking victims into downloading the malware.

Analyst 207
Smartphone displaying a blurred Telegram app screen on a neutral surface with a cityscape in the background.

Telegram Abused for Crypto Scams and Android Malware Delivery

Researchers uncovered a massive scam operation, dubbed FEMITBOT, that uses Telegram's Mini Apps to spread fake crypto platforms, brand impersonations, and Android malware, with a single API string tying it all together. Victims are lured in with a convincing, app-like interface that tricks them into divulging sensitive info.

Analyst 207
Ransomware incident responder sits at desk with laptop and papers, highlighting vulnerability.

Ransomware Negotiator Exposed as Insider for Gang

A shocking case reveals a glaring weakness in ransomware incident response: organizations often put blind trust in single negotiators, leaving them vulnerable to exploitation by attackers. This human error, not a technical bug, can turn a trusted role into a gateway for cybercriminals.

Analyst 207
Person working at desk with laptop in a well-lit office setting.

Malicious AI Browser Extensions Exfiltrate User Data

Beware of AI browser extensions that promise to boost productivity but secretly steal your data. Researchers uncovered 18 malicious extensions that masquerade as helpful tools but deliver spyware, Trojans, and other threats that can hijack your online activity.

Analyst 207
Formal courthouse interior with podium and blurred emblem in background.

Ex-Incident Responders Sentenced for Ransomware Extortion Scheme

Two former cybersecurity pros, Ryan Clifford Goldberg and Kevin Tyler Martin, have been sentenced to four years in prison for using their specialized knowledge to orchestrate a string of devastating ransomware attacks, extorting victims instead of protecting them. The pair, who once worked in incident response, now face the consequences of their crimes.

Analyst 207
Office worker sits at desk with laptop and papers, surrounded by ordinary office atmosphere.

Phishing campaigns increasingly harness AI to evade detection

Phishing campaigns are getting smarter by the minute, with a whopping 86% of recent attempts leveraging AI to sneak past detection. This marks a significant jump from just two years ago, when AI was used in 80% of phishing ops.

Analyst 207
Modern office setting with laptop and notepad in foreground, blurred workstations in background.

Phishing Kit Bluekit Incorporates AI to Streamline Attacks

Meet Bluekit, a cutting-edge phishing kit that's revolutionizing the game with an AI Assistant panel, pairing traditional templates with advanced AI models to help cybercriminals quickly draft campaign materials. This innovative tool is streamlining attacks, making it easier for malicious actors to launch sophisticated phishing campaigns.

Analyst 207
A cluttered office workspace with laptop and papers on a desk in a brightly-lit room.

Silver Fox APT Targets Russia, India with ABCDoor Backdoor

Over 1,600 malicious emails, disguised as tax-audit notices, were sent to targets in India and Russia between January and February 2026, aiming to trick recipients into downloading a backdoor or clicking on a malicious link. The cleverly crafted phishing campaign unfolded in two waves, using PDFs and archives to spread the ABCDoor backdoor.

Analyst 207
Researchers Uncover Fast16 Malware's Stealthy Industrial Sabotage Role

Researchers Uncover Fast16 Malware's Stealthy Industrial Sabotage Role

Researchers have uncovered a highly sophisticated malware, Fast16, designed to secretly sabotage industrial operations by subtly manipulating critical calculations, leading to potentially catastrophic failures. This stealthy threat can silently spread across networks, altering results in high-precision applications and causing damage to real-world equipment.

Analyst 207
Windows computer workstation in an office with a blank laptop screen and notepad.

Python Backdoor Evades Detection on Windows with Advanced Evasion Techniques

Meet Deep#Door, a sneaky Python-based backdoor framework that hides its malicious payload inside a batch dropper, making it super hard to detect on Windows systems. By embedding its code, it dodges network-based detection and slips into restricted environments with ease.

Analyst 207
Cluttered home office workspace with laptop and faint GitHub logo.

GitHub Facades Used to Disguise EtherRAT Malware Distribution

Malicious actors have been using 44 cleverly disguised GitHub facades to spread EtherRAT malware, masquerading as legitimate admin and dev tools between December 2025 and April 2026. These fake repositories were designed to manipulate search results, leading victims to download a malicious MSI installer hidden in a second, secret GitHub account.

Analyst 207
Windows computer workstation in an office setting with router and cables, and a blank laptop screen on the desk.

Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials

Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security controls and ends with a fully featured Remote Access Trojan (RAT).

Analyst 207