Tag: malware
-
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East, and Canada. The malware combines fake Google Play pages, Android Accessibility Service abuse, credential-stealing overlays, real-time screen streaming, and remote-control functions to compromise mobile banking sessions. The company tracks the operator behind the…
-
CLOSEDQUORUM, the malware that asks four AI models what to do next
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote before deciding what to steal from you. Four AI models vote on its next move, without any human interaction. CLOSEDQUORUM is the first Windows…
-
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/
-
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
RatHat Android malware uses generative AI to navigate infected devices, steal banking credentials, intercept OTP codes and reinstall itself after removal again. First seen on hackread.com Jump to article: hackread.com/rathat-android-malware-ai-banking-credentials/
-
MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
MovieReaper malware spreads through compromised Odyssey torrents, infecting hundreds of victims while using Solana to locate command-and-control infrastructure. First seen on hackread.com Jump to article: hackread.com/moviereaper-malware-odyssey-torrents-infect-users/
-
Researchers uncover malware that uses AI to choose its next move
To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/22/cairn-open-source-framework-ai-malware-closedquorum/
-
Warum Sicherheitsverantwortliche Microsoft-365 verstärkt in den Blick nehmen sollten
Cyberkriminelle zielen immer häufiger direkt auf den Microsoft-365-Tenant ab. Sie manipulieren Identitäten, verschlüsseln Daten in der Cloud und erpressen Unternehmen, ohne auch nur eine einzige Zeile herkömmlicher Malware einzusetzen. Für Banken, Versicherungen und andere regulierte Unternehmen ist dies kein düsteres Zukunftsszenario. Es ist die Realität im Jahr 2026 und den meisten Unternehmen fehlt die […]…
-
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell commands, and transfer files through broker-mediated topics. Analysis of a statically linked x86-64 ELF sample shows that its configuration, task routing, and network payloads are obfuscated with separate XOR routines. The examined sample, SHA-256…
-
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/
-
Introducing CAIRN: Frontier tracking for AI-integrated malware
Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/
-
A New Tool Found Malware That’s Guided by an AI Hive Mind”, No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots”, and quickly discovered something unusual. First seen on wired.com Jump to article: www.wired.com/story/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system/
-
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the…
-
Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation
Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising the cost of static detection and automated reverse engineering. First observed in 2018, Vidar remains a widely tracked credential-stealing malware family. Its operators continually alter internal protections without necessarily changing the malware’s broader operational purpose:…
-
Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation
Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising the cost of static detection and automated reverse engineering. First observed in 2018, Vidar remains a widely tracked credential-stealing malware family. Its operators continually alter internal protections without necessarily changing the malware’s broader operational purpose:…
-
Meta’s Muse AI 0-Day Lets Hackers Hijack Dictation Traffic and Inject Malicious Prompts
A recent proof-of-concept (PoC) developed by security researcher Patrick Wardle reveals a local zero-day vulnerability in the Muse application. This vulnerability allows malware running under the logged-in user’s account to redirect dictation traffic to a server controlled by an attacker. Meta’s Muse AI 0-Day The issue is documented in Wardle’s >>not-a-mused<< research repository. It focuses…
-
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Victims have been identified in Africa, including in Kenya and Uganda. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/cybercriminals-hiding-new-malware-torrents-popular-films
-
10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassing npm’s lifecycle-script protections. The operation centers on a counterfeit package named indexed-btree, which impersonates the legitimate sorted-btree library and executes its malware only when an application uses the package at runtime. Unlike conventional npm…
-
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware running on endpoints. In April 2026, the attackers accessed a FortiGate SSL VPN using compromised domain credentials, then gained domain-admin-equivalent rights. PAYLOAD Ransomware On April 13, Kaspersky’s Global Emergency Response Team (GERT) created…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installing malware, granting remote access, and stealing Windows credentials. These attacks exploit a simple vulnerability: employees tend to distrust suspicious emails but often do not apply the same caution to collaboration platforms like Teams. Attackers…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot…

