Skip to main content

Tag: malware operations

619 articles

Network server room with out-of-focus laptop in foreground.

Akira Ransomware Actors Exploit Safe Mode to Evade EDR Protections

Cyber attackers have found a sneaky way to bypass EDR protections by exploiting Safe Mode, leaving security systems blind to their malicious activities. In one recent incident, an exposed SonicWall VPN with no multi-factor authentication was all it took for hackers to gain entry and start wreaking havoc.

Analyst 207
Smartphone lies on a park bench with cracked screen, near a faint shadow of a hand.

Armored Likho Expands Cyber-Espionage Arsenal

Meet the Armored Likho group, a cyber-espionage mastermind that's just leveled up its game with a suite of sneaky new implants that can hijack Telegram sessions and eavesdrop on conversations. The latest campaign, uncovered in May 2026, uses a cunning fake donation app to infiltrate targets across Russia.

Analyst 207
Blurred laptop on reception desk in brightly-lit office lobby with large window.

Ransomware Attacks Pivot to Identity-Based Exploits

Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Analyst 207
Laptop on a desk near a window with a blurred Chrome browser window on the screen.

Malicious Chrome Extensions Route Traffic Through Proxies

Hundreds of malicious Chrome extensions have been found to secretly route users' traffic through proxy servers controlled by hackers, allowing them to intercept and spy on sensitive information. This sneaky tactic puts users at risk of having their online activity monitored and exploited.

Analyst 207
Aeternum Botnet Exploits Blockchain for Decentralized Command Structure

Aeternum Botnet Exploits Blockchain for Decentralized Command Structure

Meet Aeternum, a sneaky botnet loader that's exploiting the Polygon blockchain's smart contracts to operate with a decentralized command structure, making it a formidable and harder-to-stop threat. This innovative approach allows Aeternum to shift parts of its malware operations onto a decentralized infrastructure, giving it a unique advantage.

Analyst 207
Network operations center with rows of servers and a laptop in the foreground.

Kimwolf Botnet Evolves to Evade Takedowns and DDoS Defenses

The Kimwolf Botnet has upgraded its tactics, now using the Ethereum Name Service to evade detection and launching sophisticated HTTP/2 floods that mimic real Chrome traffic, making it harder to distinguish from legitimate visitors. This new approach allows infected devices to blend in with normal web traffic, bypassing traditional DDoS defenses.

Analyst 207
Modern cityscape with sleek buildings and subtle tech infrastructure.

DeadLock Ransomware Leverages Blockchain to Evade Takedown

DeadLock Ransomware is taking a disturbingly clever approach to evade shutdown by leveraging the Polygon blockchain to conceal its operational addresses, making it a formidable foe for cybersecurity efforts. By cleverly using decentralized building blocks, the group has already amassed a shocking 80 victims, mostly in Europe.

Analyst 207
A laptop sits alone on a table in front of a blurred background of computer workstations and servers.

CAV3RN Espionage Framework Evolves With Google Apps Script C2 Relay

Meet the sneaky CAV3RN Espionage Framework, which just got a clever upgrade - it can now use Google Apps Script as a relay to secretly communicate with its controllers, all while hiding in plain sight within DNS traffic. This clever tactic lets the malware decide on a per-transaction basis whether to connect directly to its masters or take a detour through Google's services.

Analyst 207
Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Analyst 207
Technicians walk by rows of server racks and networking equipment in a modern network operations center.

Kimwolf Botnet Evolves with Enhanced DDoS Capabilities

Meet Kimwolf v7, a highly evolved botnet that's taken DDoS capabilities to the next level with its cutting-edge command-and-control resolution via Ethereum's blockchain naming system, ENS. First discovered in February 2026, this malware has been quietly building its arsenal since August 2024, targeting a range of devices from Linux IoT gadgets to Android TV boxes.

Analyst 207
Employees work at computer desks in a brightly-lit tech facility with city view.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

Analyst 207
A coding workstation with a laptop, programming books, and notes on a quiet office desk.

Malware Packages Exploit Ethereum for C2 Communications

Malicious actors have cleverly exploited Ethereum to spread malware, with six suspicious npm packages found querying an attacker-controlled wallet to fetch additional malicious payloads. This sneaky tactic was uncovered by Sonatype Research Labs on August 10, revealing a new level of sophistication in cyber attacks.

Analyst 207
Concerned officials stand outside partially closed city hall entrance.

US Local Governments Targeted in Wave of Cyber Attacks

Local governments are under siege, with a growing wave of cyber attacks crippling their operations - just like Suisun City, which was forced to declare a state of emergency after a malicious software attack shut down its entire IT network. The attacks are leaving communities vulnerable, with city services and internal operations grinding to a halt.

Analyst 207
WordPress plugin developer's workspace with flagged plugins on screen.

BdThemes plugins compromised in supply-chain attack

A stealthy supply-chain attack on BdThemes plugins has turned into a high-stakes problem, putting over 350,000 active WordPress installations at risk. The breach affects popular plugins like Element Pack, Prime Slider, and others, prompting the WordPress Plugins team to swiftly pull them from download.

Analyst 207
Smartphone on cluttered desk with blank screen in soft daylight.

Mobile Malware Attacks Decline, Banking Trojans Persist

Mobile malware attacks may be on the decline, but don't let your guard down - over 1.99 million mobile devices were still threatened by malware, adware, or unwanted software in the second quarter alone. Banking Trojans, in particular, remain a persistent threat, with over 93,000 malicious packages detected.

Analyst 207
A brightly-lit office workspace with a computer workstation and blank screens.

Ransomware Attacks Surge as Qilin Targets Vulnerabilities

Malicious activity is on the rise, with nearly 400 million attacks blocked by Kaspersky products in Q2 2026 alone, showcasing a surge in large-scale web exploitation and targeted ransomware operations. This alarming trend highlights the need for robust online protection.

Analyst 207
Rack-mounted servers and cables in a brightly-lit server room, with one isolated rack showing subtle signs of tampering.

TrueConf Server Flaws Targeted to Deploy PhantomCore Backdoor

Security researchers at Kaspersky have uncovered a sneaky plot by threat actor Head Mare to exploit unpatched TrueConf servers and deploy the PhantomCore backdoor to unsuspecting users. The attack relies on a two-stage vulnerability chain that allows attackers to run malicious commands with high-level privileges.

Analyst 207
Cluttered home office desk with MacBook displaying suspicious popup window.

Go-Based Malware Targets macOS Crypto Wallets

Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

Analyst 207
Empty cryptocurrency trading desk with laptop and smartphone on a wooden surface in a modern office space with city view.

Malware Exploits ClickFix Attacks to Drain macOS Crypto Wallets

Beware: a sneaky malware called ClickFix is targeting macOS crypto wallets, slowly draining their contents into the pockets of cyber thieves. This cunning attack starts with a simple trick: victims are duped into pasting a malicious command into the Terminal app, unleashing a stealthy thief that siphons off cryptocurrency.

Analyst 207
Cluttered software development workspace with laptop and terminal on a desk.

Malicious npm Packages Deliver Cross-Platform Malware

Nearly 800 malicious npm packages have been discovered delivering a potent cross-platform malware payload, including a remote access trojan and infostealer, via a sneaky trick that tricks developers into loading the malicious code. These packages use cleverly crafted names and README instructions to evade detection and deploy the WEL1DROPPER downloader.

Analyst 207
Person at desk looks concerned while checking emails on computer screen.

Cyberattackers Hijack Legitimate Emails, Payments in Twin 2026 Campaigns

Cyberattackers are sneaking into legitimate emails and payments, exploiting our trust in everyday business communications to pull off scams that now account for almost 46% of all threat detections. They're using ordinary emails like shipment notices and invoice prompts, often sent from compromised corporate mailboxes, to carry out banking malware campaigns.

Analyst 207
Laptop on a beige office desk with a blurred screen in a cubicle near a window.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access

Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

Analyst 207
Hospital IT room with scattered papers, locked cabinet, and medical equipment in background, hinting at disruption.

Ransomware Attacks Spike 19% in July, Targeting Finance, Tech, and Healthcare

Ransomware attacks surged 19% in July, with 799 claimed incidents targeting key sectors like finance, tech, and healthcare. To stay safe, experts stress the importance of regular backups - and backups of those backups - to quickly restore systems and data in case of an attack.

Analyst 207
Rows of servers and cables in a data center with a Redis server infrastructure in focus.

TeamPCP Exploits Redis in Years-Long Supply Chain Campaign

Researchers have uncovered a clever and patient hacking group, TeamPCP, that exploited Redis servers in a years-long supply chain campaign, with roots tracing back to 2020. This group's sophisticated tactics involved compromising internet-facing infrastructure and deploying malware, showcasing a highly evolved operational tradecraft.

Analyst 207