Skip to main content

Tag: malware operations

619 articles

Young gamer sits in cluttered bedroom with laptop showing Roblox game and nearby screen with Discord chat or gaming forum.

Malware Campaign Targets Roblox with RAT and Infostealer via Fake Xeno Script Launcher

Roblox players beware: a sneaky malware campaign has been targeting gamers with a fake Xeno Script Launcher, infecting them with a RAT and infostealer since the start of the year. The malware was cleverly spread through gaming forums, Discord, and compromised accounts, masquerading as an "undetected" cheat to evade Roblox's anti-cheat protections.

Analyst 207
Laptop and smartphone on cluttered desk with blurred screen and malware code on nearby paper.

Malware Exploits Google Passkey Ecosystem for Account Takeover

Malware is now exploiting Google's Passkey ecosystem to hijack accounts, with researchers uncovering three new attack classes that allow hackers to take control of passkey-protected accounts. This alarming vulnerability lets malware running on a victim's device authenticate without needing user interaction or elevated permissions.

Analyst 207
Server equipment in a neutral setting with ambient daylight and empty screens.

AI Emerges as Dual Threat in Cyberattacks

Artificial intelligence has taken a dark turn, now serving as both a powerful tool and prime target for cyber attackers, with AI-driven malicious activity skyrocketing 89% in just one year. This emerging threat landscape demands attention, as adversaries harness AI to supercharge their attacks.

Analyst 207
Windows laptop on a neutral surface with a blurred background and a blank desktop screen.

Malware Exploits Google Password Manager Flaws to Hijack Passkey Accounts

Malware on a Windows machine can secretly hijack your passkey-protected accounts, allowing hackers to sign in without needing your fingerprint, PIN, or any other verification. This shocking exploit targets Google Password Manager, revealing a vulnerability that puts your digital security at risk.

Analyst 207
Darkened room with multiple screens and devices, individuals huddled around cluttered table with notes and papers.

BTMOB Malware Ecosystem Fractures as Resellers Exploit Source Code

The BTMOB malware ecosystem has shattered into a patchwork of fragmented offerings, morphing from a single, centrally operated service to a chaotic mix of official releases, private servers, and reseller panels. This dramatic shift comes after the source code was exploited, sending the once-coordinated operation into a tailspin.

Analyst 207
Law firm's office interior with scattered papers and out-of-focus laptop screen.

HollowFrame Loader Evades Defender with Fake Python DLL Tactic

Clever attackers have found a way to slip past Microsoft Defender by using a fake Python DLL, effectively creating a trusted execution lane that evades detection. They set the stage for this trick by first gaining elevated access through a sneaky spear-phishing link.

Analyst 207
Bitcoin hardware wallet with blank screen and scattered coins on neutral surface.

Coldcard Hardware Wallet Flaw Enables $70 Million Bitcoin Heist

A sneaky attacker just pulled off a massive $70 million Bitcoin heist by exploiting a flaw in a popular hardware wallet, draining 1,196 addresses in a lightning-fast 41 minutes. The thief's clever move has left experts warning of a potential vulnerability in the widely-used Coldcard wallet.

Analyst 207
Person at desk with laptop and papers, hands paused over keyboard in cautious unease.

Hackers Exploit Adform Script to Swap Crypto Wallet Addresses

Beware: hackers have cleverly manipulated a popular ad script to swap crypto wallet addresses, allowing them to intercept your transactions even if you double-check and recopy the address. This sneaky tactic uses a cleverly hidden code to override your wallet details in real-time.

Analyst 207
Guest on laptop in hotel lobby with authentication prompt on screen.

Hotel Wi-Fi Hijacked to Deliver Surveillance Malware

Hackers have found a sneaky way to hijack hotel Wi-Fi, using a simple trick to redirect guests to a fake login page that can deliver surveillance malware and even bypass multi-factor authentication. This clever hack starts with attackers taking control of a hotel's Wi-Fi gateway, allowing them to forge DNS answers and route traffic to their own servers.

Analyst 207
Person walking down city street with laptop screen reflecting abstract webpage.

Adform Script Compromised to Steal Cryptocurrency

A security breach at Adform has led to a malicious script that can compromise your device with cryptocurrency-stealing malware, simply by visiting a website that uses their ad tech. This sneaky malware can infiltrate your device through seemingly harmless websites, just by embedding a compromised Adform script.

Analyst 207
A dimly lit server room with rows of computer servers and network equipment on racks, surrounded by neatly organized cables…

Kaspersky's Network Anomaly Detection Exposes Stealthy Attacks

Stay one step ahead of sneaky attackers with Network Anomaly Detection, a powerful tool that uncovers stealthy threats like Kerberoasting and DNS tunneling that often evade signature-based security tools. By spotting unusual network activity, you can shut down hidden attacks before they cause damage.

Analyst 207
Government ministry building with office desk and computer in foreground.

Chinese Hackers Target Central Asian Governments with OctLurk and SilkLurk Malware

Chinese hackers have launched a stealthy cyberattack on government organizations across six Central Asian countries, infiltrating ministries, hospitals, and schools with sophisticated malware. The targeted countries include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.

Analyst 207
Cluttered developer workstation with Xcode project on screen amidst papers and coffee cups in soft daylight.

XCSSET Malware Evolves With Advanced Evasion Tactics

Malicious hackers have unleashed a powerful new version of XCSSET malware that can turn unsuspecting developer workstations into launchpads for supply-chain attacks, infecting thousands of users through poisoned Xcode projects. This latest variant, XCSSET v40, uses advanced evasion tactics to spread rapidly and quietly.

Analyst 207
Law firm's office interior with desk, chair, and subtle computer setup.

HollowFrame Loader Deploys Matryoshka Backdoor in Targeted Law Firm Attacks

Cyber attackers have deployed a sneaky duo, HollowFrame and Matryoshka, to gain a persistent foothold in targeted law firm attacks, allowing them to execute remote commands, snoop on Active Directory, and transfer files. It all started with a cleverly crafted spear-phishing message containing a malicious link that set off a multi-stage chain of events.

Analyst 207
Modern lab with workstations and instruments, featuring a projected neural network diagram.

Malware Evolves with AI-Driven Tactics

Malware is getting a scary upgrade: attackers are harnessing AI-driven tactics to create a surge in suspicious and malicious activity, with tens of thousands of dubious AI "skills" already detected. This emerging threat landscape is multiplying opportunities for hackers to exploit, making it a critical concern for anyone online.

Analyst 207
Rack-mounted router or industrial controller with indicator lights and cables in an urban industrial setting.

Chinese Hackers Leverage DeepSeek for Autonomous Exploits

Meet the sneaky Chinese hackers who've been using an AI-powered tool called DeepSeek to launch autonomous cyber attacks on over 460 targets - and get a glimpse into their clever tactics. With just a single Telegram instruction, DeepSeek can infiltrate and exploit systems all on its own.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit data center with a single unoccupied workstation in the…

Cryptominer Exploits Linux PAM to Evade Detection

Cybercriminals have found a sneaky way to evade detection by exploiting Linux PAM, using a trusted third-party relationship as a backdoor to spread a Monero mining campaign. By abusing the pam_rootok policy, they can impersonate multiple standard accounts without needing passwords, creating a forensic smokescreen.

Analyst 207
Industrial control panel and laptop in a Japanese manufacturing facility.

SilverFox Exploits New Drivers in BYOVD Attacks on Japanese Manufacturer

Meet the sneaky SilverFox hackers who've been exploiting new drivers to launch BYOVD attacks on a Japanese industrial manufacturer, using clever tactics like DLL sideloading and defense evasion to stay one step ahead. Their attack began with a simple yet effective invoice-themed phishing lure, delivered via popular Chinese services QQ and Tencent Cloud.

Analyst 207
Cluttered desk with laptop and open-source software development materials.

Amazon Exposes North Korean Hacking Campaign Targeting Open-Source Software

A North Korea-linked hacking group has been exploiting widely-used open-source software, infecting millions of users through compromised packages like axios, which alone receives over 100 million downloads weekly. This campaign, linked to a single financially motivated actor, has been targeting major JavaScript packages since March 2025.

Analyst 207
Cluttered coding workspace with laptop, notes, and coffee cups, with a blurred world map in the background.

Amazon Ties npm Hijack to North Korea's Sapphire Sleet

In a shocking supply-chain hijack, North Korea's Sapphire Sleet group compromised over 2 billion weekly downloads of popular npm packages, including debug and chalk, in a brazen attack tied to multiple other malicious campaigns. Amazon Threat Intelligence has linked this September 2025 incident to a string of attacks dating back to March 2025.

Analyst 207
Empty coding workspace with laptop, notes, and coffee cups on a cluttered desk in a daytime office setting.

North Korea Targets Low-Profile Packages in Warm-Up for Axios Hack

Amazon's chief information security officer CJ Moses reveals that a March 2025 crypto campaign was likely a rehearsal for a more significant attack, specifically targeting low-profile packages. This campaign was linked to a notorious hacking group also responsible for the recent axios library compromise.

Analyst 207
Dimly lit server room with exposed circuit boards and tangled cables.

Flying Eagle Android RAT Source Code Circulates, 170 Servers Compromised

Researchers have uncovered a massive operation linked to the Flying Eagle Android RAT, with 170 internet servers compromised, allowing hackers to capture sensitive info, record screens, and even impersonate legitimate apps. This powerful toolkit can be used to create customized malware that steals payment passwords, keystrokes, and more.

Analyst 207
Node.js package on a developer's workstation with code editor open, subtle blockchain diagram in background.

Compromised npm Packages Deliver DEV#POPPER Malware via Blockchain

Malicious npm packages have been discovered delivering DEV#POPPER malware via blockchain, with two beta releases in the @joyfill namespace containing a sneaky JavaScript implant that springs into action the moment Node.js loads the package. This stealthy implant can execute in any process that requires the compromised package, making it a serious threat.

Analyst 207
Dimly lit server room with rows of computer servers and networking equipment.

Mirage Kitten Unveils New Malware Arsenal for Middle East Espionage

Mirage Kitten hackers have unleashed a potent new malware arsenal targeting the Middle East, threatening aerospace, aviation, defense, and telecom organizations with stealthy backdoors and tunnelers that enable covert surveillance and data relay. Their latest Windows backdoor, NightLedger, masquerades as a legitimate system file to infiltrate and gather intel.

Analyst 207