Skip to main content

Tag: malware operations

629 articles

A researcher examines computer equipment in a dimly lit, cluttered forensics lab.

Researchers Uncover Pre-Stuxnet Cyber-Sabotage Malware

Meet fast16, a stealthy cyber-sabotage malware that went undetected until now, marking a new era in covert statecraft. Discovered by SentinelOne researchers, this silent threat has been hiding in plain sight since 2016.

Analyst 207
Control room of a water treatment plant with a computer workstation in the foreground and blurred equipment in the…

New Malware ZionSiphon Targets Water Plants, Falls Flat

A new piece of malware called ZionSiphon, reportedly targeting Israeli water facilities, has been found to be surprisingly inept, with experts describing it as broken and showing little understanding of its supposed targets. The malware's code includes strings referencing the Israeli water sector and politically charged messaging, but its overall incompetence has downplayed initial alarm.

Analyst 207
Close-up of Cisco network security device with outer casing removed, revealing internal components on a laboratory bench.

Hackers Exploit Cisco Firewalls with Persistent Backdoor

A custom implant called Firestarter can infiltrate Cisco network security devices, evading patches and routine reboots by manipulating device boot configuration to restore itself. Only a hard reboot, physically disconnecting the device from its power supply, can clear the persistence mechanism from memory.

Analyst 207
Developer workstation with laptop and coding peripherals in a shared office space with a subtle hint of network compromise.

Vercel Breach Exposes Wider Fallout in Developer Ecosystem

A recent Vercel breach has sent shockwaves through the developer ecosystem, with threat intel revealing a sophisticated attack that distributed malware to hunt for valuable tokens and keys. The incident has had far-reaching consequences, impacting multiple downstream environments and a small number of accounts.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit server room.

Trigona Ransomware Exploits Custom Tool for Swift Data Exfiltration

Trigona ransomware attackers have unleashed a custom-built, command-line tool that turbocharges data theft, allowing them to siphon off sensitive information with lightning speed and razor-sharp efficiency. This potent tool is the latest weapon in their arsenal, enabling faster and more efficient data exfiltration from compromised environments.

Analyst 207
Docker Hub repository page on a developer's workstation screen shows a manipulated image warning.

Checkmarx KICS Tool Compromised in Supply-Chain Breach

A critical vulnerability was discovered in the Checkmarx KICS tool due to a supply-chain breach, where a malicious Docker image was briefly hosted on DockerHub, exposing users to potential security risks between April 22, 2026, 14:17:59 UTC and 15:41:31 UTC. The breach was quickly identified and rectified, with affected tags restored and malicious images removed.

Analyst 207
Vulnerable computer servers and networking equipment in a dimly lit data center.

Cyberattacks Exploit Known Flaws in Supply Chain, AI Tools

A recent cyberattack exploited weaknesses in a company's infrastructure, resulting in a staggering $290 million heist from KelpDAO, highlighting the vulnerability of supply chains to targeted attacks. The attackers manipulated key nodes to gain control and siphon off funds.

Analyst 207
Cluttered office desk with computer, papers, and open smartphone showing an email inbox.

UNC6692 Exposes Custom Malware Suite via Social Engineering

In a clever social engineering ploy, UNC6692 launched a massive email campaign in late December 2025, flooding targets with messages to create a sense of urgency and distraction, before following up with a convincing Microsoft Teams message that pushed a malicious link. The attackers then cleverly disguised their malware as a legitimate "Mailbox Repair and Sync Utility" patch, hosted on an Amazon S3 page.

Analyst 207
Modern office setting with subtle digital communication hints.

China-Linked APT Group Exploits Legitimate Services for Covert Ops

ESET researchers have uncovered a treasure trove of clues, analyzing 6,044 Slack messages and 3,005 Discord messages that reveal the covert operations of a China-linked APT group, dubbed GopherWhisper, which has been active since at least 2023. The recovered logs provide a rare glimpse into the group's tactics, thanks to hardcoded credentials in Go-based backdoors that gave investigators access to the group's command and control channels.

Analyst 207
Breach scene in a brightly-lit tech office with a computer workstation in the foreground.

Vercel Breach Exposes Additional Customer Accounts

A recent Vercel breach exposed additional customer accounts after a malicious chain of events began with a compromised employee account at Context.ai, which was likely triggered by a simple online search for Roblox scripts. The breach highlights the risks of malware distribution and token theft, with threat intel pointing to a sophisticated attack targeting valuable keys and account credentials.

Analyst 207
Cluttered developer workstation with multiple monitors, laptop, and coding materials under bright fluorescent lighting.

npm Worm Targets Dev Environments, Exploits Supply Chain

A newly discovered npm malware attack has infected multiple packages, using sneaky tactics like install-time execution and credential theft to compromise developer environments and spread through the supply chain. This self-propagating malware strain appears to be targeting specialized developer workflows, putting a spotlight on vulnerabilities in the software development process.

Analyst 207
Person sitting at desk with phone, surrounded by computer monitors and notes, in a dimly lit room with a cityscape visible…

Cybercrime Shifts to Caller-as-a-Service Model

US elderly citizens alone lost a staggering $3.4B in 2023 to phone-based scams, highlighting the alarming rise of a highly organized and profitable fraud economy. This Caller-as-a-Service model has made it easier for scammers to specialize and scale their operations, putting even more people at risk.

Analyst 207
Dimly lit coding environment with multiple screens and laptops, notes, and diagrams, showing signs of disarray.

npm Ecosystem Targets New Supply-Chain Attack to Steal Auth Tokens

Researchers have uncovered a sneaky supply-chain worm that can hijack auth tokens and spread malware through the npm ecosystem, putting countless packages at risk. This stealthy threat can inject itself into every package it can publish, creating a ripple effect of compromised code.

Analyst 207
Abandoned study with laptop displaying ransomware warning, eerie blue glow, and ghostly suit-clad figure in background.

Gentlemen Ransomware Operation Exposes 1,570 Victims Through SystemBC Malware

A shocking 1,570 networks worldwide have been compromised by the sneaky SystemBC malware, which has been quietly building a massive botnet of victims across the globe. This stealthy threat can even download and execute additional malware, putting your security at risk.

Analyst 207
Destroyed electrical substation at dusk with rubble, shattered phone, and scattered papers amidst ominous cityscape.

Lotus Malware Targets Venezuelan Energy Firms with Data-Wiping Attacks

A new, highly destructive malware called Lotus has been targeting Venezuela's energy sector, leaving systems completely unrecoverable after wiping data and disabling recovery mechanisms. This devastating attack systematically deletes files and overwrites physical drives, causing irreversible damage.

Analyst 207
Person sitting in dark room with laptop showing fake login prompt and nearby smartphone and torn paper with credentials.

macOS ClickFix Attacks Harvest Credentials via AppleScript Stealers

macOS users beware: a sneaky ClickFix campaign is using AppleScript stealers to harvest credentials from 14 browsers, 16 cryptocurrency wallets, and over 200 extensions. This targeted attack has already made off with a staggering amount of sensitive info - and it's still on the loose.

Analyst 207
Cracked smartphone screen next to discarded smart card with eerie interface and cursor on sensitive file in background.

Malware Exploits Android App to Harvest NFC Card Data

A new malware called NGate is putting NFC payment card users in Brazil at risk, exploiting the popular HandyPay app to steal sensitive card data and PINs. This sneaky attack leaves cardholders vulnerable to financial loss and compromised personal info.

Analyst 207
Suited figure in shadows surrounded by devices with encrypted screens.

Gentlemen Ransomware Spreads Rapidly Through Affiliate Network

Gentlemen Ransomware is spreading rapidly through its affiliate network, fueling a surge in multi-platform attacks and infections linked to the malicious tool SystemBC. This ransomware-as-a-service operation is making it alarmingly easy for cybercriminals to join the fray and wreak havoc.

Analyst 207
Gloved hands hover over a cracked smartphone with eerie glow and payment terminal reflection.

NGate Malware Targets Brazil, Trojanizes HandyPay for NFC Data Theft

Security researchers have uncovered a sneaky new Android malware, NGate, that has been hiding in plain sight by infecting a legitimate app called HandyPay, used for NFC data relay, and using AI-generated code to steal payment credentials. This cleverly crafted malware has set its sights on Brazil, putting unsuspecting users at risk of NFC data theft.

Analyst 207
Dark cityscape with broken smartphone, credit card and lock on screen, and shadowy figure near public transit terminal with…

NGate Malware Exploits HandyPay App to Steal Android NFC Payment Data

Malicious NGate malware has been discovered hiding inside a fake version of the HandyPay app, putting Android users' NFC payment data at risk. This sneaky malware exploits a trusted payments tool to steal sensitive information, leaving users vulnerable to financial theft.

Analyst 207

Malware Disguised as Roblox Cheats Fuels Vercel Breach

Malware masquerading as Roblox cheats sparked a chain reaction, leading to a significant security breach at Vercel and exposing vulnerabilities in modern cloud and SaaS ecosystems. This incident highlights how a seemingly harmless piece of malware can wreak havoc across connected services.

Analyst 207
Smartphone with cracked screen on cluttered desk, cityscape with Chinese architecture in background, hints of wallet and…

Malicious Apps Infiltrate Apple's China Store, Target Crypto Wallets

Scammers have infiltrated Apple's China App Store with 26 fake cryptocurrency wallet apps, cleverly disguised as popular wallets like Metamask and Coinbase, to steal sensitive recovery phrases and drain users' digital assets. These malicious apps put unsuspecting crypto investors at risk of losing their hard-earned money.

Analyst 207
Dimly lit server room with eerie laptop screen glow showing shadowy suited figure.

Gentlemen Ransomware Gang Taps SystemBC for Botnet Attacks

Imagine your business's infrastructure being hijacked and turned into a fleet of malicious proxies - it's a harsh reality that's now hitting home for over 1,570 corporate victims who've fallen prey to the Gentlemen ransomware gang's SystemBC botnet attacks. Their compromised systems are being used to run proxy services for the malware, leaving defenders scrambling to respond.

Analyst 207
Shadowy figure looms behind a laptop displaying maze-like code, with a torn template and tangled wire in the foreground.

Formbook Malware Exploits Obfuscation to Evade Detection

Staying one step ahead of threats just got tougher: Formbook malware's latest campaign combines DLL side-loading and obfuscated JavaScript to expertly evade detection. This sneaky tactic allows it to remain hidden, making it a formidable foe in the cybersecurity landscape.

Analyst 207