Skip to main content

Tag: malware operations

619 articles

Person working at desk with laptop and phone, surrounded by papers and office supplies, with blank screens, in a blurred…

Phishing Attacks Propel Cyber Incidents to New Highs

Phishing attacks are now the top threat, making up over half of all cyber incidents - a significant jump from the previous quarter when they accounted for just one-third of cases. This resurgence in phishing has propelled cyber incidents to new highs, putting organizations on high alert.

Analyst 207
Technicians monitor a world map on a large screen in a network operations center, surrounded by rows of routers and servers.

Dysphoria Botnet Spreads to 200k Devices, Enables Global DDoS Attacks

A rapidly growing botnet called Dysphoria has infected over 200,000 devices worldwide, enabling massive global DDoS attacks. This sneaky threat uses blockchain technology to hide its tracks and evade detection.

Analyst 207
Person sits at laptop in quiet workspace, face downcast, focused on blurred screen.

SourTrade Malvertising Campaign Builds Malware in Browser

Meet SourTrade, a sneaky malvertising campaign that's assembling malware right in your browser - all while security tools and network logs show nothing out of the ordinary. Its operators impersonate popular trading and crypto platforms to trick victims into a stealthy malware delivery process.

Analyst 207
Brightly-lit Middle Eastern cityscape with subtle tech hints.

TELESHIM Malware Exploits Telegram for C2 in Middle East Attacks

TELESHIM malware has launched a sophisticated attack in the Middle East, using a multi-stage chain to infect systems and cleverly leveraging Telegram's API to disguise its command-and-control communications as legitimate internet traffic. This sneaky tactic allows the malware to blend in seamlessly, making it a formidable threat.

Analyst 207
Modern computer workstation with security software dashboard and office background.

Ransomware Groups Master EDR Kill Techniques

Ransomware groups have mastered the art of disabling endpoint detection and response (EDR) tools, making it standard practice to shut them down before encryption begins. This sinister tactic has significantly shortened defenders' response time, leaving them with limited opportunities to detect and contain attacks.

Analyst 207
Concerned gamer sits at desk surrounded by peripherals, puzzled by laptop screen showing Steam forum page.

Steam Forum Abused in ClickFix Attacks Spreading XMRig Cryptominers

Cyber attackers are exploiting Steam's forum by creating fake accounts that offer 'helpful' fixes to users with game issues, tricking them into downloading and installing a notorious XMRig cryptominer. This sneaky tactic uses a PowerShell script to quietly install the malware as a persistent Windows service.

Analyst 207
City transit platform with people in background, foreground computer screen blurred, hinting at malware threat.

Malvertising Campaign SourTrade Exploits Browsers to Deliver Malware

Meet SourTrade, a sneaky malvertising campaign that's exploiting browsers to deliver malware - without leaving a single piece of malware on the network. This clever attack uses a complex web of code to assemble Windows executables right inside your browser.

Analyst 207
Laptop on a city transit platform bench with everyday objects nearby.

Malvertising Campaign Exploits Browsers to Assemble Malware in Memory

Meet the sneaky malvertising campaign that's turning web browsers into malware factories, assembling attacks entirely in memory using fake pages for popular services like Solana, Luno, and TradingView. This stealthy operation has been active since late 2024, targeting users across 12 countries and 25 languages.

Analyst 207
Cluttered server room with stacked routers, switches, and servers, and cables snaking across floor and walls.

Botnets Persist Despite Takedowns, Fueled by Residential Proxy Networks

Botnets just won't quit, and it's no surprise why - there's a thriving market for access to millions of IPs, making it easy for them to keep growing and snaring more victims. Residential proxy networks are fueling this expansion, with nearly 60 million victim IP addresses globally and a significant chunk of them right here in the US.

Analyst 207
Person working at desk with laptop and smartphone, surrounded by papers and notes.

BlueNoroff Phishing Kit Targets Crypto Wallets with Zoom Lures

BlueNoroff's phishing kit is a masterclass in deception, using Zoom lures and compromised industry contacts to trick victims into divulging their crypto wallet info. This sophisticated scam combines social engineering and malware to selectively target high-value victims.

Analyst 207
Dimly lit server room with rows of equipment and a single bright laptop in the foreground.

Golden Chickens Malware Evolves With Modular Implants

The Golden Chickens malware has taken a significant leap forward with the emergence of four new, highly modular malware families, signaling a major evolution in the threat landscape. This development is a red flag, as it suggests a more sophisticated and adaptable attack strategy from the financially motivated malware-as-a-service developer behind it.

Analyst 207
Laptop open on a plain surface with a blank screen showing soft glow.

Dolphin X Malware Exploits AI to Prioritize High-Value Targets

Meet Dolphin X Malware, a sneaky threat that uses AI to help attackers zero in on their most prized targets - and it's equipped with an impressive 329 features to do so. Its AI Profiler tool can sort and rank infected computers, giving hackers a daily summary of the most valuable victims.

Analyst 207
Person sitting at a laptop in a blurred office or coffee shop setting.

Bing Ads Deliver SectopRAT Malware via Fake Claude App

Malvertising on Bing Ads led to a massive attack, compromising at least 29 organizations in just two days with SectopRAT malware via a fake Claude app installer. A malicious artifact on Claude's own domain was downloaded over 7,100 times before being taken down.

Analyst 207
Developer workstation with laptop, monitor, and notes, surrounded by empty coffee cups in a brightly lit room.

Malware Exploits Trust In Ordinary Systems

This week's ThreatsDay bulletin revealed a disturbing trend: hackers are disguising malware as ordinary tools and features, using familiar names and routine functions to infiltrate code repositories, desktop systems, mobile apps, and more. Even trusted platforms like GitHub and PyPI are being exploited, with GitHub announcing a security update to block vulnerable support bundle uploads.

Analyst 207
Notepad++ installation package and archive files on a cluttered office desk surrounded by papers and supplies.

Hackers Exploit Notepad++ Plugins to Install Stealthy Malware

Beware of a sneaky malware attack that's using a harmless-looking PDF to trick victims into installing stealthy malware through a fake Notepad++ plugin. The malware is delivered through a cleverly disguised ZIP file that sets off a chain of events, ultimately leading to a malicious DLL being installed on your device.

Analyst 207
Windows host computer on a cluttered desk with an open, idle browser window.

Chaos Ransomware Exploits Headless Browsers for Covert C2 Traffic

Cisco Talos uncovered a sneaky tactic used by Chaos Ransomware, where a Rust implant called msaRAT hijacks a victim's browser to disguise its communications, making it look like they're coming from a legitimate browser process. This clever trick lets the malware fly under the radar by using the Chrome DevTools Protocol to control the browser.

Analyst 207
Dimly lit server room with rows of computer servers and GitHub-branded devices.

GitHub Actions Abused to Target cPanel, WHM Servers

Malicious actors have cleverly exploited GitHub Actions to launch attacks on cPanel and WHM servers, using compromised source repositories to unleash a wave of automated exploits. By adding dozens of malicious workflows, attackers can scan and exploit vulnerable systems with alarming ease.

Analyst 207
Cybercrime investigator's lab workbench with laptop, notes, and equipment.

Dolphin X Stealer Uses AI to Target High-Value Victims

Meet Dolphin X Stealer, a sneaky new Windows malware that's packing some serious AI-powered punch, allowing cybercriminals to zero in on high-value targets with ease. Its operator panel boasts an impressive 329 features, giving attackers an unprecedented level of control and insight.

Analyst 207
Person sits at desk with laptop, surrounded by empty office space, browser window open.

Chaos Ransomware Gang Exploits Browsers for Stealthy C2 Communications

Cisco Talos researchers have uncovered a sneaky new backdoor, msaRAT, that hijacks Chrome or Microsoft Edge to secretly communicate with its command center, avoiding direct network connections. This stealthy tactic uses the browser's remote debugging interface to inject JavaScript and stay under the radar.

Analyst 207
Concerned office worker holding a smartphone at their desk surrounded by papers and office supplies.

Ransomware Attacks Intensify as AI Enhances Phishing Tactics

Ransomware attacks are getting smarter and more effective, with AI-powered phishing tactics leading to a significant increase in successful breaches. In fact, 65% of organizations hit by ransomware say AI tools made the attack more convincing and effective.

Analyst 207
Developer workstation with laptop and monitor displaying code, surrounded by notes and sticky notes in a modern office…

Malware Targets AI Tools in Software Development Environments

A new wave of malware is targeting the very tools developers rely on to build and deploy software, with a recently discovered worm, Sandworm_Mode, capable of stealing sensitive credentials and accessing critical systems. This emerging threat could compromise the entire AI development stack, from AI assistants to cloud providers and API keys.

Analyst 207
Dimly lit movie theater or cluttered home workspace with laptop and movie-watching paraphernalia.

Scammers Exploit 'Odyssey' Release with Rapid-Fire Pirated Movie Scams

Scammers wasted no time in exploiting the release of Christopher Nolan's highly anticipated film, The Odyssey, using rapid-fire pirated movie scams to target unsuspecting users just hours after its debut. These scams cleverily avoided software vulnerabilities, instead relying on fake browser warnings and malicious downloads to compromise victims' devices.

Analyst 207
Corporate office interior with employees working, featuring a large blank whiteboard in the foreground.

Ransomware Risk Amplified by Enterprise GenAI Deployments

With enterprise GenAI deployments on the rise, the ransomware risk is skyrocketing - after all, Microsoft alone detects over 38 million identity risk signals daily, a stark reminder that AI-enabled attacks can strike at any moment. As attackers supercharge their ops with AI, businesses are unwittingly increasing their vulnerability by deploying AI systems that can be exploited.

Analyst 207
Network equipment on a rack with a blurred, abstract representation of a threat in the background.

TrickBot Adopts DNS Tunneling in Latest Evolution

TrickBot's latest evolution uses DNS tunneling to evade detection, with FortiGuard Labs spotting the malware moving a 1.2 MB file in just 40 seconds. This sneaky new tactic lets TrickBot fly under the radar, routing encrypted data to a public resolver via DNS packets.

Analyst 207