Tag: malware operations
619 articles

Windows Stealer Malware Targets 300+ Apps with AI-Powered Profiler
Meet Dolphin X, a sneaky Windows malware that's taking the cybercrime world by storm with its AI-powered profiler and unparalleled ability to infiltrate over 300 apps, swiping sensitive info like browser passwords, crypto wallets, and cloud tokens. This info-stealer is being sold on the dark web as a potent tool for hackers to get their hands on valuable data.

Law Enforcement Disrupts Kratos Phishing Kit Targeting Microsoft 365 Sessions
In a major win for cybersecurity, law enforcement agencies have dismantled the notorious Kratos Phishing Kit, pulling over 200 servers offline and disrupting thousands of phishing campaigns targeting Microsoft 365 sessions. The operation, coordinated with Indonesian authorities, is estimated to have impacted around 1,800 paying customers who were using Kratos to run approximately 15,000 phishing campaigns monthly.

JADEPUFFER Evolves to Target AI Models with Ransomware
JADEPUFFER's latest move is a game-changer: they're now using ransomware to destroy AI models, leaving encrypted artifacts irretrievable. This devastating attack can cost victims up to $500,000 or more in training and computing losses.

FakeGit Campaign Exploits GitHub Repos to Spread SmartLoader Malware
Malicious actors have unleashed a massive campaign, using 7,600 fake GitHub repositories to spread the notorious SmartLoader malware, tricking victims into downloading malicious files disguised as popular tools like Gmail and Docker. The operation's convincing fake artifacts and manipulated repository metrics made it a highly effective and long-running threat.

Project CAV3RN Exploits Outlook Calendar for Covert C2 Communications
Meet the sneaky CAV3RN communication module that's hiding in plain sight, using Outlook calendar events and DNS AAAA records to secretly communicate with its command-and-control center. Its clever disguise is courtesy of AzureCommunication.dll, a .NET Native AOT module that's got experts curious.

WordPress Sites Targeted as Hackers Exploit Critical wp2shell Flaws
Hackers are actively exploiting critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to inject malicious plugins and PHP webshells, putting countless sites at risk. Attackers are using mass-scanning and plugin upload abuse to gain control, making it essential for WordPress users to take immediate action.

Ransomware Landscape Fractures as New Groups Proliferate
The ransomware landscape is shattering into more factions than ever, with over one new group emerging every week in 2026, according to the Black Kite Ransomware Report. This explosion of new players has led to a surge in attacks, with 61 new groups appearing in just one year alone.

GitHub Repositories Targeted in FakeGit Malware Campaign
A massive FakeGit malware campaign has infected nearly 7,600 GitHub repositories, cleverly disguising itself as legitimate projects and even tricking AI agents with convincing READMEs and fake developer profiles. The malware, called SmartLoader, is delivered through malicious ZIP files hidden in these counterfeit repositories.

AI-Assisted Phishing Toolkit Exposed in WebDAV Malware Campaign
Meet the AI-assisted phishing toolkit that was left wide open, complete with 1,048 files, including testing notes and live delivery logs - a rare glimpse into a hacker's playbook. The exposed repository revealed a sophisticated operation, even down to a hardcoded path pointing to an open-source AI coding tool.

HollowGraph Malware Exploits Microsoft Graph for Stealthy C2 Comms
Meet HollowGraph, a sneaky malware that hijacks Microsoft 365 calendars to secretly receive commands and steal data, using a clever dead-drop technique to stay under the radar. It creates seemingly innocuous calendar events with cryptic titles and attachments to covertly communicate with its masters.

HollowGraph Malware Exploits Microsoft 365 Calendar for Covert C2 Channel
Meet HollowGraph, a sneaky espionage implant that hijacks Microsoft 365 calendars to secretly communicate with its operators, never even touching an attacker-controlled server. By masquerading as a harmless calendar event, HollowGraph quietly receives instructions and sends stolen data under the radar.

Cruciferra Crypter Evades Detection With Advanced Obfuscation Tactics
Meet Cruciferra, the notorious crypter dubbed the underground's most lethal tool, and learn how its creators are using advanced obfuscation tactics to evade detection across dozens of malware campaigns. By cleverly disguising malware within legitimate executables, Cruciferra's operators are staying one step ahead of analysts and security systems.

Malware Hides in Microsoft 365 Calendars via HOLLOWGRAPH Campaign
Meet HOLLOWGRAPH, a sneaky malware that's hiding in plain sight - using Microsoft 365 calendars to pull off a highly targeted espionage threat. This compact implant is reading and writing secret messages, all while masquerading as a harmless calendar event.

HollowGraph Malware Exploits Microsoft 365 Calendars for Covert C2 Communications
Meet HollowGraph, a sneaky new Windows malware that's exploiting Microsoft 365 calendars to secretly communicate with hackers, using trusted services to hide in plain sight. This highly targeted threat can turn a compromised calendar into a covert channel for stolen data and malicious instructions.

Russian Hacker Exploits Google AI to Control Botnet
A solo Russian hacker, going by the name "bandcampro", cleverly exploited Google's AI tool to build a sneaky botnet operation that was incredibly lightweight, consisting of just three plaintext files totaling 5 KB. This made it easy to replicate and dispose of, allowing the hacker to stay one step ahead.

RubyGems Packages Targeted in SleeperGem Supply Chain Attack
Researchers have uncovered a sneaky supply chain attack, dubbed SleeperGem, that uses malicious RubyGems packages to infiltrate developer machines and download additional payloads. The attack relies on three rogue packages, each acting as a loader to fetch a second-stage payload.

Russian Hackers Exploit ClickFix CAPTCHAs to Spread Malware in Ukraine
Ukraine's Computer Emergency Response Team (CERT-UA) warns that Russian hackers, part of the notorious Sandworm group, are using manipulated CAPTCHAs to trick victims into downloading malware, specifically targeting Ukraine with data-stealing attacks. They've been linked to a series of social engineering scams that spread malware through legitimate websites.

GoldenEyeDog Exploits DigiCert Breach for Code-Signing Certificates
In a chilling example of malware mastery, the GoldenEyeDog group exploited a DigiCert breach to snag code-signing certificates, which they then used to cloak their malicious software in a veneer of legitimacy. This brazen heist highlights the group's cunning and capabilities, which have been under scrutiny since at least 2015.

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials
Meet NadMesh, a sneaky botnet on the hunt for cloud credentials, with its operators claiming to have already amassed 3,811 unique AWS keys; but is its reported success just a facade?

AI Spam Filters Vulnerable to Text Salting Attacks
Over 1 million retail-themed phishing emails have been detected using a sneaky technique called text salting to evade AI spam filters since April. This clever trick hides harmless words in malicious messages, fooling automated scanners but not the human eye.

Ransomware Targets Government Agencies Daily, Study Reveals
Government agencies are under attack, with ransomware hitting a staggering 187 organizations in just six months - that's one body disrupted every single day, on average. This alarming trend is up 13% from the previous half-year, leaving public services vulnerable and citizens at risk.

North Korean Hackers Exploit Coding Tests with Steganography-Laced Malware
North Korean hackers are targeting software developers with a sneaky malware attack, hiding steganography-laced payloads in coding tests to steal sensitive data and cryptocurrency. This latest campaign, tracked as REF9403, is just another example of the DPRK's relentless pursuit of valuable information.

GoSerpent Malware Targets Southeast Asian Governments for Espionage
A stealthy cyber threat, known as GoSerpent, has been secretly targeting Southeast Asian governments and diplomats since late 2025, with the goal of gathering sensitive intelligence. This sophisticated malware has been evolving, with a new set of malicious tools deployed as recently as May 2026.

ACR Stealer Exploits ClickFix Lures to Target Microsoft 365 Files
Microsoft's Defender Experts team uncovered a sneaky ACR Stealer campaign that uses ClickFix lures to swipe sensitive Microsoft 365 files, browser passwords, and authentication tokens from unsuspecting users. This stealthy attack leaves enterprise environments vulnerable, with stolen data including PDFs, synced OneDrive and SharePoint folders, and more.