Tag: malware operations
619 articles

Malware Campaign Targets Roblox with RAT and Infostealer via Fake Xeno Script Launcher
Roblox players beware: a sneaky malware campaign has been targeting gamers with a fake Xeno Script Launcher, infecting them with a RAT and infostealer since the start of the year. The malware was cleverly spread through gaming forums, Discord, and compromised accounts, masquerading as an "undetected" cheat to evade Roblox's anti-cheat protections.

Malware Exploits Google Passkey Ecosystem for Account Takeover
Malware is now exploiting Google's Passkey ecosystem to hijack accounts, with researchers uncovering three new attack classes that allow hackers to take control of passkey-protected accounts. This alarming vulnerability lets malware running on a victim's device authenticate without needing user interaction or elevated permissions.

AI Emerges as Dual Threat in Cyberattacks
Artificial intelligence has taken a dark turn, now serving as both a powerful tool and prime target for cyber attackers, with AI-driven malicious activity skyrocketing 89% in just one year. This emerging threat landscape demands attention, as adversaries harness AI to supercharge their attacks.

Malware Exploits Google Password Manager Flaws to Hijack Passkey Accounts
Malware on a Windows machine can secretly hijack your passkey-protected accounts, allowing hackers to sign in without needing your fingerprint, PIN, or any other verification. This shocking exploit targets Google Password Manager, revealing a vulnerability that puts your digital security at risk.

BTMOB Malware Ecosystem Fractures as Resellers Exploit Source Code
The BTMOB malware ecosystem has shattered into a patchwork of fragmented offerings, morphing from a single, centrally operated service to a chaotic mix of official releases, private servers, and reseller panels. This dramatic shift comes after the source code was exploited, sending the once-coordinated operation into a tailspin.

HollowFrame Loader Evades Defender with Fake Python DLL Tactic
Clever attackers have found a way to slip past Microsoft Defender by using a fake Python DLL, effectively creating a trusted execution lane that evades detection. They set the stage for this trick by first gaining elevated access through a sneaky spear-phishing link.

Coldcard Hardware Wallet Flaw Enables $70 Million Bitcoin Heist
A sneaky attacker just pulled off a massive $70 million Bitcoin heist by exploiting a flaw in a popular hardware wallet, draining 1,196 addresses in a lightning-fast 41 minutes. The thief's clever move has left experts warning of a potential vulnerability in the widely-used Coldcard wallet.

Hackers Exploit Adform Script to Swap Crypto Wallet Addresses
Beware: hackers have cleverly manipulated a popular ad script to swap crypto wallet addresses, allowing them to intercept your transactions even if you double-check and recopy the address. This sneaky tactic uses a cleverly hidden code to override your wallet details in real-time.

Hotel Wi-Fi Hijacked to Deliver Surveillance Malware
Hackers have found a sneaky way to hijack hotel Wi-Fi, using a simple trick to redirect guests to a fake login page that can deliver surveillance malware and even bypass multi-factor authentication. This clever hack starts with attackers taking control of a hotel's Wi-Fi gateway, allowing them to forge DNS answers and route traffic to their own servers.

Adform Script Compromised to Steal Cryptocurrency
A security breach at Adform has led to a malicious script that can compromise your device with cryptocurrency-stealing malware, simply by visiting a website that uses their ad tech. This sneaky malware can infiltrate your device through seemingly harmless websites, just by embedding a compromised Adform script.

Kaspersky's Network Anomaly Detection Exposes Stealthy Attacks
Stay one step ahead of sneaky attackers with Network Anomaly Detection, a powerful tool that uncovers stealthy threats like Kerberoasting and DNS tunneling that often evade signature-based security tools. By spotting unusual network activity, you can shut down hidden attacks before they cause damage.

Chinese Hackers Target Central Asian Governments with OctLurk and SilkLurk Malware
Chinese hackers have launched a stealthy cyberattack on government organizations across six Central Asian countries, infiltrating ministries, hospitals, and schools with sophisticated malware. The targeted countries include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.

XCSSET Malware Evolves With Advanced Evasion Tactics
Malicious hackers have unleashed a powerful new version of XCSSET malware that can turn unsuspecting developer workstations into launchpads for supply-chain attacks, infecting thousands of users through poisoned Xcode projects. This latest variant, XCSSET v40, uses advanced evasion tactics to spread rapidly and quietly.

HollowFrame Loader Deploys Matryoshka Backdoor in Targeted Law Firm Attacks
Cyber attackers have deployed a sneaky duo, HollowFrame and Matryoshka, to gain a persistent foothold in targeted law firm attacks, allowing them to execute remote commands, snoop on Active Directory, and transfer files. It all started with a cleverly crafted spear-phishing message containing a malicious link that set off a multi-stage chain of events.

Malware Evolves with AI-Driven Tactics
Malware is getting a scary upgrade: attackers are harnessing AI-driven tactics to create a surge in suspicious and malicious activity, with tens of thousands of dubious AI "skills" already detected. This emerging threat landscape is multiplying opportunities for hackers to exploit, making it a critical concern for anyone online.

Chinese Hackers Leverage DeepSeek for Autonomous Exploits
Meet the sneaky Chinese hackers who've been using an AI-powered tool called DeepSeek to launch autonomous cyber attacks on over 460 targets - and get a glimpse into their clever tactics. With just a single Telegram instruction, DeepSeek can infiltrate and exploit systems all on its own.

Cryptominer Exploits Linux PAM to Evade Detection
Cybercriminals have found a sneaky way to evade detection by exploiting Linux PAM, using a trusted third-party relationship as a backdoor to spread a Monero mining campaign. By abusing the pam_rootok policy, they can impersonate multiple standard accounts without needing passwords, creating a forensic smokescreen.

SilverFox Exploits New Drivers in BYOVD Attacks on Japanese Manufacturer
Meet the sneaky SilverFox hackers who've been exploiting new drivers to launch BYOVD attacks on a Japanese industrial manufacturer, using clever tactics like DLL sideloading and defense evasion to stay one step ahead. Their attack began with a simple yet effective invoice-themed phishing lure, delivered via popular Chinese services QQ and Tencent Cloud.

Amazon Exposes North Korean Hacking Campaign Targeting Open-Source Software
A North Korea-linked hacking group has been exploiting widely-used open-source software, infecting millions of users through compromised packages like axios, which alone receives over 100 million downloads weekly. This campaign, linked to a single financially motivated actor, has been targeting major JavaScript packages since March 2025.

Amazon Ties npm Hijack to North Korea's Sapphire Sleet
In a shocking supply-chain hijack, North Korea's Sapphire Sleet group compromised over 2 billion weekly downloads of popular npm packages, including debug and chalk, in a brazen attack tied to multiple other malicious campaigns. Amazon Threat Intelligence has linked this September 2025 incident to a string of attacks dating back to March 2025.

North Korea Targets Low-Profile Packages in Warm-Up for Axios Hack
Amazon's chief information security officer CJ Moses reveals that a March 2025 crypto campaign was likely a rehearsal for a more significant attack, specifically targeting low-profile packages. This campaign was linked to a notorious hacking group also responsible for the recent axios library compromise.

Flying Eagle Android RAT Source Code Circulates, 170 Servers Compromised
Researchers have uncovered a massive operation linked to the Flying Eagle Android RAT, with 170 internet servers compromised, allowing hackers to capture sensitive info, record screens, and even impersonate legitimate apps. This powerful toolkit can be used to create customized malware that steals payment passwords, keystrokes, and more.

Compromised npm Packages Deliver DEV#POPPER Malware via Blockchain
Malicious npm packages have been discovered delivering DEV#POPPER malware via blockchain, with two beta releases in the @joyfill namespace containing a sneaky JavaScript implant that springs into action the moment Node.js loads the package. This stealthy implant can execute in any process that requires the compromised package, making it a serious threat.

Mirage Kitten Unveils New Malware Arsenal for Middle East Espionage
Mirage Kitten hackers have unleashed a potent new malware arsenal targeting the Middle East, threatening aerospace, aviation, defense, and telecom organizations with stealthy backdoors and tunnelers that enable covert surveillance and data relay. Their latest Windows backdoor, NightLedger, masquerades as a legitimate system file to infiltrate and gather intel.