Skip to main content

Tag: windows malware

11 articles

Windows laptop screen showing highlighted 64-bit DLL file dpapi.dll in system file explorer.

Malware researcher uncovers Sleepwalker Windows backdoor with custom command language

Meet Sleepwalker, a sneaky new Windows backdoor discovered by malware researcher Dominik Reichel, featuring a custom command language that allows it to hide in plain sight. This clever malware masquerades as a Microsoft system component, making it a formidable foe in the world of cyber threats.

Analyst 207
Out-of-focus FTP server device sits on a rack amidst cables in a brightly-lit server room with rows of equipment in the…

Hackers Exploit FTP Server Banners to Deliver Windows Malware

Hackers have been cleverly using FTP server banners to spread Windows malware since July 2026, embedding commands in the greeting text that triggers an infection chain. This sneaky tactic, known as a dead-drop resolver, allows attackers to deliver malware via PowerShell scripts and other files.

Analyst 207
Laptop screen displays blurred Microsoft 365 calendar in office setting with notebook and pen nearby.

HollowGraph Malware Exploits Microsoft 365 Calendars for Covert C2 Communications

Meet HollowGraph, a sneaky new Windows malware that's exploiting Microsoft 365 calendars to secretly communicate with hackers, using trusted services to hide in plain sight. This highly targeted threat can turn a compromised calendar into a covert channel for stolen data and malicious instructions.

Analyst 207
Person working on laptop at bank desk with papers, surrounded by calm environment and natural daylight.

Ousaban Trojan Targets Iberian Bank Users with Sophisticated PDF Lures

Meet the Ousaban Trojan, a sneaky malware targeting banking customers in Spain and Portugal with clever PDF tricks. This sophisticated threat steals logins, hijacks sessions, and even takes remote control of infected computers.

Analyst 207
A cluttered home office workspace with a USB drive on the desk and a laptop in the background.

Malware Spreads via USB, Targets Crypto Wallets with Clipboard Theft

Beware of a sneaky malware that's spreading through USB drives and targeting crypto wallets by stealing sensitive info from your clipboard every half a second. This cunning threat replaces wallet addresses, harvests seed phrases and private keys, and even takes rapid screenshots to get its hands on your digital assets.

Analyst 207
Government agency office interior with computer workstations and a desk, featuring soft natural light and muted colors.

China-Linked Backdoor Expands to Windows with Kernel Stealth

A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.

Analyst 207
Laptop screen displays a blurred CMS interface with a cityscape background.

Ghost CMS Flaw Exploited to Hijack Over 700 Sites in ClickFix Attacks

Over 700 websites were hijacked in a massive campaign that exploited a critical Ghost CMS vulnerability, turning legitimate pages into gateways for Windows malware. This alarming attack was made possible by CVE-2026-26980, an SQL injection flaw with a near-perfect CVSS score of 9.4.

Analyst 207
Cluttered home office workstation with laptop displaying coding interface.

Malicious Hugging Face repository targets Windows users with infostealer malware

Malicious actors on Hugging Face tricked Windows users into downloading infostealer malware by creating a fake repository that mimicked OpenAI's popular Privacy Filter release. The rogue repository briefly shot to the top of Hugging Face's trending list, racking up 244,000 downloads before being swiftly removed.

Analyst 207
Cluttered office desk with laptop and smartphone, screens blurred.

Malicious Site Exploits AI Interest to Deploy Beagle Backdoor

Beware of a fake website masquerading as Anthropic's Claude interface, tricking users into downloading a 505 MB ZIP archive that unleashes a new, previously undocumented Windows backdoor called Beagle. This malicious campaign uses a convincing imitation of the legitimate site to spread the infection.

Analyst 207
Laptop on a plain surface with open screen and blurred display, beside a partially unzipped archive file.

Fake Claude AI site delivers Beagle Windows backdoor malware

Beware of a fake Claude AI site that's really a malware trap: a 505MB archive disguised as a legitimate installer delivers a sneaky Windows backdoor called Beagle. Clicking the download button on the site leads to trouble, not the AI tool you might be expecting.

Analyst 207
Windows laptop on cluttered desk with smartphone nearby, displaying blurred login screen.

CloudZ Malware Exploits Phone Link to Harvest SMS OTPs

Beware of CloudZ malware, a sneaky Windows threat that's been stealing SMS messages and one-time passwords since January 2026 by exploiting Microsoft's Phone Link app. This malicious duo, paired with the Pheno plugin, can capture mobile authentication data without ever touching your smartphone.

Analyst 207