Tag: malware operations
619 articles

Akira Ransomware Actors Exploit Safe Mode to Evade EDR Protections
Cyber attackers have found a sneaky way to bypass EDR protections by exploiting Safe Mode, leaving security systems blind to their malicious activities. In one recent incident, an exposed SonicWall VPN with no multi-factor authentication was all it took for hackers to gain entry and start wreaking havoc.

Armored Likho Expands Cyber-Espionage Arsenal
Meet the Armored Likho group, a cyber-espionage mastermind that's just leveled up its game with a suite of sneaky new implants that can hijack Telegram sessions and eavesdrop on conversations. The latest campaign, uncovered in May 2026, uses a cunning fake donation app to infiltrate targets across Russia.

Ransomware Attacks Pivot to Identity-Based Exploits
Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Malicious Chrome Extensions Route Traffic Through Proxies
Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

Aeternum Botnet Exploits Blockchain for Decentralized Command Structure
Meet Aeternum, a sneaky botnet loader that's exploiting the Polygon blockchain's smart contracts to operate with a decentralized command structure, making it a formidable and harder-to-stop threat. This innovative approach allows Aeternum to shift parts of its malware operations onto a decentralized infrastructure, giving it a unique advantage.

Kimwolf Botnet Evolves to Evade Takedowns and DDoS Defenses
The Kimwolf Botnet has upgraded its tactics, now using the Ethereum Name Service to evade detection and launching sophisticated HTTP/2 floods that mimic real Chrome traffic, making it harder to distinguish from legitimate visitors. This new approach allows infected devices to blend in with normal web traffic, bypassing traditional DDoS defenses.

DeadLock Ransomware Leverages Blockchain to Evade Takedown
DeadLock Ransomware is taking a disturbingly clever approach to evade shutdown by leveraging the Polygon blockchain to conceal its operational addresses, making it a formidable foe for cybersecurity efforts. By cleverly using decentralized building blocks, the group has already amassed a shocking 80 victims, mostly in Europe.

CAV3RN Espionage Framework Evolves With Google Apps Script C2 Relay
Meet the sneaky CAV3RN Espionage Framework, which just got a clever upgrade - it can now use Google Apps Script as a relay to secretly communicate with its controllers, all while hiding in plain sight within DNS traffic. This clever tactic lets the malware decide on a per-transaction basis whether to connect directly to its masters or take a detour through Google's services.

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware
In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Kimwolf Botnet Evolves with Enhanced DDoS Capabilities
Meet Kimwolf v7, a highly evolved botnet that's taken DDoS capabilities to the next level with its cutting-edge command-and-control resolution via Ethereum's blockchain naming system, ENS. First discovered in February 2026, this malware has been quietly building its arsenal since August 2024, targeting a range of devices from Linux IoT gadgets to Android TV boxes.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

Malware Packages Exploit Ethereum for C2 Communications
Malicious actors have cleverly exploited Ethereum to spread malware, with six suspicious npm packages found querying an attacker-controlled wallet to fetch additional malicious payloads. This sneaky tactic was uncovered by Sonatype Research Labs on August 10, revealing a new level of sophistication in cyber attacks.

US Local Governments Targeted in Wave of Cyber Attacks
Local governments are under siege, with a growing wave of cyber attacks crippling their operations - just like Suisun City, which was forced to declare a state of emergency after a malicious software attack shut down its entire IT network. The attacks are leaving communities vulnerable, with city services and internal operations grinding to a halt.

BdThemes plugins compromised in supply-chain attack
A stealthy supply-chain attack on BdThemes plugins has turned into a high-stakes problem, putting over 350,000 active WordPress installations at risk. The breach affects popular plugins like Element Pack, Prime Slider, and others, prompting the WordPress Plugins team to swiftly pull them from download.

Mobile Malware Attacks Decline, Banking Trojans Persist
Mobile malware attacks may be on the decline, but don't let your guard down - over 1.99 million mobile devices were still threatened by malware, adware, or unwanted software in the second quarter alone. Banking Trojans, in particular, remain a persistent threat, with over 93,000 malicious packages detected.

Ransomware Attacks Surge as Qilin Targets Vulnerabilities
Malicious activity is on the rise, with nearly 400 million attacks blocked by Kaspersky products in Q2 2026 alone, showcasing a surge in large-scale web exploitation and targeted ransomware operations. This alarming trend highlights the need for robust online protection.

TrueConf Server Flaws Targeted to Deploy PhantomCore Backdoor
Security researchers at Kaspersky have uncovered a sneaky plot by threat actor Head Mare to exploit unpatched TrueConf servers and deploy the PhantomCore backdoor to unsuspecting users. The attack relies on a two-stage vulnerability chain that allows attackers to run malicious commands with high-level privileges.

Go-Based Malware Targets macOS Crypto Wallets
Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

Malware Exploits ClickFix Attacks to Drain macOS Crypto Wallets
Beware: a sneaky malware called ClickFix is targeting macOS crypto wallets, slowly draining their contents into the pockets of cyber thieves. This cunning attack starts with a simple trick: victims are duped into pasting a malicious command into the Terminal app, unleashing a stealthy thief that siphons off cryptocurrency.

Malicious npm Packages Deliver Cross-Platform Malware
Nearly 800 malicious npm packages have been discovered delivering a potent cross-platform malware payload, including a remote access trojan and infostealer, via a sneaky trick that tricks developers into loading the malicious code. These packages use cleverly crafted names and README instructions to evade detection and deploy the WEL1DROPPER downloader.

Cyberattackers Hijack Legitimate Emails, Payments in Twin 2026 Campaigns
Cyberattackers are sneaking into legitimate emails and payments, exploiting our trust in everyday business communications to pull off scams that now account for almost 46% of all threat detections. They're using ordinary emails like shipment notices and invoice prompts, often sent from compromised corporate mailboxes, to carry out banking malware campaigns.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access
Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

Ransomware Attacks Spike 19% in July, Targeting Finance, Tech, and Healthcare
Ransomware attacks surged 19% in July, with 799 claimed incidents targeting key sectors like finance, tech, and healthcare. To stay safe, experts stress the importance of regular backups - and backups of those backups - to quickly restore systems and data in case of an attack.

TeamPCP Exploits Redis in Years-Long Supply Chain Campaign
Researchers have uncovered a clever and patient hacking group, TeamPCP, that exploited Redis servers in a years-long supply chain campaign, with roots tracing back to 2020. This group's sophisticated tactics involved compromising internet-facing infrastructure and deploying malware, showcasing a highly evolved operational tradecraft.