Tag: backdoor
-
MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/25/macsync-info-stealing-malware-for-macos/
-
TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands
A Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell, Scheduled Tasks, and runtime C# compilation to establish resilient persistence and continuously steal business documents. The implant also captures screenshots, extracts saved Wi-Fi passwords, harvests clipboard data, and executes arbitrary commands received from its operators. While the original delivery method is unconfirmed, the location is consistent…
-
New TASK#STOMP Windows Backdoor Enables Continuous Document Theft
TASK#STOMP Windows backdoor uses PowerShell, scheduled tasks and runtime C# compilation to steal business documents and maintain remote access. First seen on hackread.com Jump to article: hackread.com/taskstomp-windows-backdoor-document-theft/
-
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell commands, and transfer files through broker-mediated topics. Analysis of a statically linked x86-64 ELF sample shows that its configuration, task routing, and network payloads are obfuscated with separate XOR routines. The examined sample, SHA-256…
-
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-north-korean-terraform-malware/
-
Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a stealthy backdoor through a legitimate package. The malicious package was identified as @dforge-core/dforge-mcp, an MCP-related npm package whose maintainer account was abused for roughly 105 minutes on September 9. Attackers initially pushed…
-
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the…
-
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools. First seen on hackread.com Jump to article: hackread.com/china-famoussparrow-sparrowocky-backdoor-latin-america/
-
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary First seen on thehackernews.com…
-
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/taskstomp-windows-backdoor/
-
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform lock files in fake job-interview repositories to infect DevOps engineers with macOS backdoors. SentinelOne identified an Indian IT services provider compromised with the same FLATROOF and ROOFDECK implants previously linked to the April 2026 KelpDAO-LayerZero attack. The campaign…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot…
-
China Hackers Hit Latin American Governments With Backdoor
ESET Says FamousSparrow Shifted Nearly All Targeting to Latin America. A Chinese espionage group has deployed a previously undocumented backdoor against government entities in eight Latin American countries and territories, including Puerto Rico, in a campaign researchers say tracks with U.S. pressure on Chinese investments across the region. First seen on govinfosecurity.com Jump to article:…
-
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation…
-
Home Office challenged on ‘farcical’ secrecy over Apple ‘backdoor’ order
UK government argues that national security would be damaged if it departs from ‘neither confirm nor deny policy’ on Apple ‘backdoor’ notice First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650612/Home-Office-challenged-on-farcical-secrecy-over-Apple-backdoor-order
-
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.”HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, First seen on thehackernews.com Jump to article:…
-
China’s FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China’s fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
-
China’s FamousSparrow hackers target Latin America with new backdoor
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.” First seen on therecord.media Jump to article: therecord.media/china-hackers-latin-america-espionage
-
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
Tags: backdoorESET said FamousSparrow has replaced SparrowDoor with SparroWocky First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/famoussparrow-sparrowocky-latin/
-
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025.”SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News…
-
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
-
FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments
China-aligned advanced persistent threat group FamousSparrow has replaced its long-running SparrowDoor implant with a new modular C++ backdoor, SparroWocky, in a sustained cyberespionage campaign against government entities across Latin America. ESET says the malware has been active in the region since at least August 2025, following a sharp shift in the group’s victim targeting that…
-
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/
-
NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…

