Skip to main content

Tag: malware operations

619 articles

Laptop screen shows a WordPress backend dashboard with a compromised website's source code on a messy desk.

MaaS Operators Combine ErrTraffic, ClickFix to Evade Endpoint Security

Cyber attackers have launched a sneaky campaign that combines ErrTraffic and ClickFix to outsmart endpoint security, starting with compromised WordPress sites that inject obfuscated JavaScript to evade detection. This clever tactic uses the Ethereum blockchain to stay one step ahead of security tools.

Analyst 207
Cluttered desk with out-of-focus laptop near a window in a small urban office or home workspace.

Grandoreiro Malware Resurfaces with DLL Sideloading in Mexico

Mexico is in the crosshairs of a revived Grandoreiro malware campaign, accounting for 40% of detections in May 2026, with attackers using clever tactics like DLL sideloading to execute the banking trojan through legitimate software. The malware is abusing a trusted application, Duplicate Files Finder, by loading a malicious library alongside its legitimate dependencies.

Analyst 207
Office worker scrutinizes phone and laptop with concern in a modern office setting.

AI-Powered Phishing Attacks Force Defenders to Deploy Counter-Agents

Get ready for Phishing 3.0, where AI-powered attacks are revolutionizing the game, forcing defenders to level up their security strategies with cutting-edge counter-agents. AI-driven phishing is no longer just about malicious links and emails - it's a sophisticated, multi-channel threat that's researching, adapting, and striking with precision.

Analyst 207
Compromised server room with interconnected devices and scattered cables.

Hackers Exploit 2,000 WordPress Sites in StopAndProtect Malware Campaign

This sneaky malware campaign, known as StopAndProtect, has already hacked nearly 2,000 WordPress sites, using a powerful toolkit that encrypts files, steals sensitive documents, and even lets attackers chat with their victims in real-time. The damage is widespread, with over 6,000 unique IP addresses affected worldwide.

Analyst 207
Windows Defender error message on laptop screen in cluttered home office setting.

Microsoft Fixes Bug Disrupting Windows Defender Scans

Windows Defender was acting up, causing scans to fail and crashes with annoying error messages - but thankfully, Microsoft has swooped in to fix the problem. The update resolves issues with 0xc0000005 access violation errors and pesky "Threat service has stopped" messages on Windows 10 and 11 devices.

Analyst 207
Dimly lit server room with multiple computer servers, network equipment, and monitors.

Microsoft Uncovers 30+ Domains Linked to MacSync Stealer Infrastructure

Microsoft's investigation has uncovered a sneaky operation: over 30 domains are secretly linked to MacSync Stealer, a notorious macOS information stealer, and are actively siphoning off sensitive data. The company confirmed that data exfiltration is happening in real-time, not just sending out distress signals.

Analyst 207
Server room with computer equipment and a monitor displaying lines of code in the foreground.

Clop Ransomware Gang Crafts Custom Web Shell for Windchill Attacks

The Clop ransomware gang has taken its attacks to the next level by crafting a custom Java web shell that specifically targets PTC Windchill and FlexPLM servers, allowing them to harvest sensitive data with ease. This tailored tool is a significant evolution of their mass-exploitation tactics, making it a major concern for businesses using these applications.

Analyst 207
Researchers study AI network vulnerability on large screen display.

Researchers Expose AI 'Mind Virus' Propagation Risks

Imagine a "mind virus" spreading rapidly through AI systems, with agents infecting each other 55% of the time simply by editing system files like SOUL.md. In experiments, these self-propagating payloads proved alarmingly effective, with 88% of infected agents attempting to spread the virus to others.

Analyst 207
Cluttered software development workspace with laptop, coding materials, and RubyGems packages in a bright, neutral-colored…

Typosquatting Campaign Targets RubyGems Users with Windows Stealer

Beware of a sneaky typosquatting campaign targeting RubyGems users: 16 malicious packages were used to spread a Windows stealer that harvests sensitive data, including browser credentials, cryptocurrency wallets, and Telegram info. This malware can strike when you least expect it, putting your online security at risk.

Analyst 207
Empty office interior with cubicles, private offices, and scattered papers, lit by soft daylight through windows.

Ransomware Attacks Singly Target Mid-Market Firms

Ransomware attacks are hitting mid-market firms with alarming frequency, and the threat is only escalating as AI-powered tools rapidly uncover new vulnerabilities at an overwhelming pace. Mid-market companies, with revenues between $10m and $1bn, now account for nearly three-quarters of ransomware attack victims.

Analyst 207
Laptop screen shows coding interface with blurred script, set against office backdrop.

Iranian Hackers Evolve Cavern C2 with Google Apps Script Evasion

Meet the sneaky new tactic Iranian hackers are using to evade detection: blending malicious traffic with everyday services like Google Apps Script. By leveraging DNS A-record responses, they're able to switch between direct HTTPS channels and Google Apps Script relays, making it harder to track their moves.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with concerned businesspeople in the background.

Clop Ransomware Targets GE, Philips in Data Theft Attacks

Major companies like Philips, General Electric, and Shell are investigating claims by the Clop ransomware gang that their systems were breached, with Philips confirming a contained breach of an internal server that didn't affect customers. The incidents are a stark reminder of the growing threat of ransomware attacks on businesses.

Analyst 207
A cluttered computer workstation with a blank laptop screen sits unoccupied in a dimly lit server room with rows of…

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware

Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Analyst 207
Mac computer on a desk with screen sharing active in a home office setting.

macOS Screen Sharing Flaw Exploited to Install Monero Miner

Apple just released emergency updates to fix a critical flaw in macOS Screen Sharing that hackers were using to secretly install Monero miners on vulnerable Macs. The updates, available for macOS Tahoe, Sequoia, and Sonoma, patch a vulnerability that allowed attackers to bypass authentication and gain unauthorized access.

Analyst 207
Network equipment room with rows of routers and switches, one device prominently displayed in the foreground.

Evooo1Bot Linux Botnet Exploits Flaws to Hijack Edge Devices as SOCKS5 Proxies

Meet Evooo1Bot, a sneaky new Linux botnet that's been quietly hijacking edge devices since July 2026, turning them into SOCKS5 proxies by exploiting known vulnerabilities. This cunning botnet is built on the Mirai codebase, but with a range of upgraded capabilities that make it a formidable foe.

Analyst 207
Server room interior with technicians and rows of computer equipment.

Infostealers Harvest 1.7 Billion Credentials in Six Months

Cybercriminals have supercharged their credential-harvesting capabilities, with infostealer malware infecting 7.4 million devices and snagging a staggering 1.7 billion credentials in just six short months. This automated threat landscape redefines the speed and scale of a breach.

Analyst 207
Person sits at desk with open laptop displaying empty, blurred screen.

AmnesiaStealer Malware Hijacks macOS Browser Sessions with Remote Control

This sneaky malware takes remote control of your macOS browser sessions, allowing hackers to live-stream your screen and even drive your cursor - all without you knowing. They can basically take the reins, controlling your keyboard, mouse, and navigation.

Analyst 207
Person walking dog looks at smartwatch on their wrist.

AI Security Startup Corma Targets Defensive Gap with Agent Deployment

Imagine receiving a notification while walking your dog that a live attack is underway - and being able to instantly approve a block, stopping the threat in its tracks in under 10 minutes. Corma's AI agents make it possible, proactively defending networks and giving customers peace of mind.

Analyst 207
Network equipment and routers in a server room with a prominent router in the foreground.

Evooo1Bot Malware Targets Routers in Global Traffic Relay Botnet

Meet Evooo1Bot, a sneaky malware that's turning routers worldwide into unwitting traffic relays, harvesting credentials, and launching devastating DDoS attacks. This modular Linux botnet is packed with powerful tools, including encrypted communication, SSH brute-forcing, and exploit arsenals to take down vulnerable devices.

Analyst 207
Software development workspace with laptop, papers, and coffee cups, surrounded by technical books and equipment.

ChainDrop Worm Infiltrates npm Supply Chain, Evades Defenses

A sneaky new worm called ChainDrop has infiltrated the npm supply chain, infecting 444 packages that are downloaded a whopping 2 billion times each month. This stealthy attack uses a clever tactic, targeting package tarballs rather than repository source commits to evade defenses.

Analyst 207
A clutter-free laboratory workbench with a computer and scientific instruments.

HoneyMyte APT Group Upgrades CoolClient Backdoor with Kernel-Level Rootkit

Meet the upgraded CoolClient Backdoor, now packing a kernel-level rootkit courtesy of the sneaky HoneyMyte APT Group - and it's hiding in plain sight with a legit digital signature. This clever malware uses a Windows service and a kernel-mode driver to evade detection.

Analyst 207
Modern office workspace with Mac computer and network router on shelf.

Hackers exploit macOS flaw to deploy Monero miners

Hackers are exploiting a recently fixed macOS security flaw to secretly deploy Monero miners, and experts warn that public exploit code is now available, putting users at risk. This vulnerability, affecting macOS's built-in Screen Sharing feature, allows attackers to gain access without valid credentials.

Analyst 207
Mac user poised to copy malware command into Terminal on fake GitHub download page.

AmnesiaStealer Targets macOS via ClickFix Social Engineering

Mac users beware: a new threat called AmnesiaStealer is targeting macOS devices through clever social engineering tactics known as ClickFix, tricking victims into installing malware via a fake GitHub download page. One wrong click could compromise your entire system.

Analyst 207
Empty server room with rows of equipment racks and monitoring stations.

Jewelbug APT Exploits Dual Agenda with Espionage and Crypto Fraud

Meet Jewelbug, a notorious APT group that's been pulling off a double heist - stealing sensitive info and swindling victims out of crypto - all from the same interconnected operation. Their massive haul includes over 1 million implant check-ins and 580,000 stolen cookies, with targets spanning government systems and service providers across the Middle East, Southeast Asia, and South Asia.

Analyst 207