Skip to main content

Tag: malware operations

619 articles

Laptop on cluttered desk with scattered papers and office supplies.

Windows Stealer Malware Targets 300+ Apps with AI-Powered Profiler

Meet Dolphin X, a sneaky Windows malware that's taking the cybercrime world by storm with its AI-powered profiler and unparalleled ability to infiltrate over 300 apps, swiping sensitive info like browser passwords, crypto wallets, and cloud tokens. This info-stealer is being sold on the dark web as a potent tool for hackers to get their hands on valuable data.

Analyst 207
Law enforcement officers and investigators gather around a table with laptops and papers in a briefing room with a global…

Law Enforcement Disrupts Kratos Phishing Kit Targeting Microsoft 365 Sessions

In a major win for cybersecurity, law enforcement agencies have dismantled the notorious Kratos Phishing Kit, pulling over 200 servers offline and disrupting thousands of phishing campaigns targeting Microsoft 365 sessions. The operation, coordinated with Indonesian authorities, is estimated to have impacted around 1,800 paying customers who were using Kratos to run approximately 15,000 phishing campaigns monthly.

Analyst 207
Damaged server equipment in a data center with concerned technicians in the background.

JADEPUFFER Evolves to Target AI Models with Ransomware

JADEPUFFER's latest move is a game-changer: they're now using ransomware to destroy AI models, leaving encrypted artifacts irretrievable. This devastating attack can cost victims up to $500,000 or more in training and computing losses.

Analyst 207
Laptop screen displays GitHub repository page amidst cluttered home office workspace.

FakeGit Campaign Exploits GitHub Repos to Spread SmartLoader Malware

Malicious actors have unleashed a massive campaign, using 7,600 fake GitHub repositories to spread the notorious SmartLoader malware, tricking victims into downloading malicious files disguised as popular tools like Gmail and Docker. The operation's convincing fake artifacts and manipulated repository metrics made it a highly effective and long-running threat.

Analyst 207
Empty office with laptop and router on shelf, cables neatly arranged.

Project CAV3RN Exploits Outlook Calendar for Covert C2 Communications

Meet the sneaky CAV3RN communication module that's hiding in plain sight, using Outlook calendar events and DNS AAAA records to secretly communicate with its command-and-control center. Its clever disguise is courtesy of AzureCommunication.dll, a .NET Native AOT module that's got experts curious.

Analyst 207
WordPress website backend interface on a laptop screen with a cityscape background.

WordPress Sites Targeted as Hackers Exploit Critical wp2shell Flaws

Hackers are actively exploiting critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to inject malicious plugins and PHP webshells, putting countless sites at risk. Attackers are using mass-scanning and plugin upload abuse to gain control, making it essential for WordPress users to take immediate action.

Analyst 207
City street with busy storefronts and office buildings, hinting at disruption.

Ransomware Landscape Fractures as New Groups Proliferate

The ransomware landscape is shattering into more factions than ever, with over one new group emerging every week in 2026, according to the Black Kite Ransomware Report. This explosion of new players has led to a surge in attacks, with 61 new groups appearing in just one year alone.

Analyst 207
Cluttered software development workspace with laptop showing blurred GitHub page.

GitHub Repositories Targeted in FakeGit Malware Campaign

A massive FakeGit malware campaign has infected nearly 7,600 GitHub repositories, cleverly disguising itself as legitimate projects and even tricking AI agents with convincing READMEs and fake developer profiles. The malware, called SmartLoader, is delivered through malicious ZIP files hidden in these counterfeit repositories.

Analyst 207
Dimly lit server room with exposed directory structure on open workstation screen.

AI-Assisted Phishing Toolkit Exposed in WebDAV Malware Campaign

Meet the AI-assisted phishing toolkit that was left wide open, complete with 1,048 files, including testing notes and live delivery logs - a rare glimpse into a hacker's playbook. The exposed repository revealed a sophisticated operation, even down to a hardcoded path pointing to an open-source AI coding tool.

Analyst 207
Brightly-lit office setting with computer workstation and calendar showing May 13, 2050 date.

HollowGraph Malware Exploits Microsoft Graph for Stealthy C2 Comms

Meet HollowGraph, a sneaky malware that hijacks Microsoft 365 calendars to secretly receive commands and steal data, using a clever dead-drop technique to stay under the radar. It creates seemingly innocuous calendar events with cryptic titles and attachments to covertly communicate with its masters.

Analyst 207
Empty office with laptop on desk, blurred screen, in front of cityscape window and subtle calendar display.

HollowGraph Malware Exploits Microsoft 365 Calendar for Covert C2 Channel

Meet HollowGraph, a sneaky espionage implant that hijacks Microsoft 365 calendars to secretly communicate with its operators, never even touching an attacker-controlled server. By masquerading as a harmless calendar event, HollowGraph quietly receives instructions and sends stolen data under the radar.

Analyst 207
Dimly lit computer workstation with laptop, empty screens, and a glowing USB drive.

Cruciferra Crypter Evades Detection With Advanced Obfuscation Tactics

Meet Cruciferra, the notorious crypter dubbed the underground's most lethal tool, and learn how its creators are using advanced obfuscation tactics to evade detection across dozens of malware campaigns. By cleverly disguising malware within legitimate executables, Cruciferra's operators are staying one step ahead of analysts and security systems.

Analyst 207
Laptop on office desk shows Microsoft 365 calendar with blurred cityscape in background.

Malware Hides in Microsoft 365 Calendars via HOLLOWGRAPH Campaign

Meet HOLLOWGRAPH, a sneaky malware that's hiding in plain sight - using Microsoft 365 calendars to pull off a highly targeted espionage threat. This compact implant is reading and writing secret messages, all while masquerading as a harmless calendar event.

Analyst 207
Laptop screen displays blurred Microsoft 365 calendar in office setting with notebook and pen nearby.

HollowGraph Malware Exploits Microsoft 365 Calendars for Covert C2 Communications

Meet HollowGraph, a sneaky new Windows malware that's exploiting Microsoft 365 calendars to secretly communicate with hackers, using trusted services to hide in plain sight. This highly targeted threat can turn a compromised calendar into a covert channel for stolen data and malicious instructions.

Analyst 207
Modern tech facility with a lone computer workstation in the foreground.

Russian Hacker Exploits Google AI to Control Botnet

A solo Russian hacker, going by the name "bandcampro", cleverly exploited Google's AI tool to build a sneaky botnet operation that was incredibly lightweight, consisting of just three plaintext files totaling 5 KB. This made it easy to replicate and dispose of, allowing the hacker to stay one step ahead.

Analyst 207
Developer workstation with laptop and terminal window amidst RubyGems packages, hinting at a supply chain breach.

RubyGems Packages Targeted in SleeperGem Supply Chain Attack

Researchers have uncovered a sneaky supply chain attack, dubbed SleeperGem, that uses malicious RubyGems packages to infiltrate developer machines and download additional payloads. The attack relies on three rogue packages, each acting as a loader to fetch a second-stage payload.

Analyst 207
Dimly lit workstation with worn laptop showing distorted CAPTCHA prompt amidst clutter and broken office supplies.

Russian Hackers Exploit ClickFix CAPTCHAs to Spread Malware in Ukraine

Ukraine's Computer Emergency Response Team (CERT-UA) warns that Russian hackers, part of the notorious Sandworm group, are using manipulated CAPTCHAs to trick victims into downloading malware, specifically targeting Ukraine with data-stealing attacks. They've been linked to a series of social engineering scams that spread malware through legitimate websites.

Analyst 207
Security analysts examine a laptop screen in a brightly-lit security operations center with rows of computer servers in the…

GoldenEyeDog Exploits DigiCert Breach for Code-Signing Certificates

In a chilling example of malware mastery, the GoldenEyeDog group exploited a DigiCert breach to snag code-signing certificates, which they then used to cloak their malicious software in a veneer of legitimacy. This brazen heist highlights the group's cunning and capabilities, which have been under scrutiny since at least 2015.

Analyst 207
Dimly lit server room with rows of racked servers and networking gear.

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials

Meet NadMesh, a sneaky botnet on the hunt for cloud credentials, with its operators claiming to have already amassed 3,811 unique AWS keys; but is its reported success just a facade?

Analyst 207
Office email workstation with laptop, papers, and supplies under ordinary lighting.

AI Spam Filters Vulnerable to Text Salting Attacks

Over 1 million retail-themed phishing emails have been detected using a sneaky technique called text salting to evade AI spam filters since April. This clever trick hides harmless words in malicious messages, fooling automated scanners but not the human eye.

Analyst 207
Government office with a barricaded door and encrypted computer screen.

Ransomware Targets Government Agencies Daily, Study Reveals

Government agencies are under attack, with ransomware hitting a staggering 187 organizations in just six months - that's one body disrupted every single day, on average. This alarming trend is up 13% from the previous half-year, leaving public services vulnerable and citizens at risk.

Analyst 207
A coding test setup in a brightly-lit computer lab with a laptop and blank screen.

North Korean Hackers Exploit Coding Tests with Steganography-Laced Malware

North Korean hackers are targeting software developers with a sneaky malware attack, hiding steganography-laced payloads in coding tests to steal sensitive data and cryptocurrency. This latest campaign, tracked as REF9403, is just another example of the DPRK's relentless pursuit of valuable information.

Analyst 207
Formal office setting with laptop, papers, and pen on a desk near a window overlooking a cityscape.

GoSerpent Malware Targets Southeast Asian Governments for Espionage

A stealthy cyber threat, known as GoSerpent, has been secretly targeting Southeast Asian governments and diplomats since late 2025, with the goal of gathering sensitive intelligence. This sophisticated malware has been evolving, with a new set of malicious tools deployed as recently as May 2026.

Analyst 207
Office setting with laptop showing Microsoft 365 interface and scattered papers.

ACR Stealer Exploits ClickFix Lures to Target Microsoft 365 Files

Microsoft's Defender Experts team uncovered a sneaky ACR Stealer campaign that uses ClickFix lures to swipe sensitive Microsoft 365 files, browser passwords, and authentication tokens from unsuspecting users. This stealthy attack leaves enterprise environments vulnerable, with stolen data including PDFs, synced OneDrive and SharePoint folders, and more.

Analyst 207