Tag: malware
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba…
-
Odysseus-Film: Homer dichtet Malware
Hacker nutzen Fake-Angebote für Christopher Nolans Odysseus-Film, um Malware mit LummaStealer auszuspielen. Laut der renommierten Althistorikerin Mary Beard hat Christopher Nolan in seiner aktuellen Odysseus-Verfilmung von 2026 Erotik und Witz zugunsten von Gewalt weggekürzt. Hacker transportieren ihrerseits aktuell illegal die LummaStealer-Malware zum Informationsdiebstahl als Angebot vermeintlicher Downloads des Films. Die Experten der Bitdefender Labs… First…
-
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/09/week-in-review-cisco-fixes-imc-bug-patch-tuesday-forecast-black-hat-usa-2026/
-
Roblox-Cheater werden selbst zu Betrogenen
Cyberkriminelle nutzen die Suche vieler Gamer nach Cheats und Hilfsprogrammen gezielt aus. Nach Erkenntnissen der Bitdefender Labs verbreiten Angreifer manipulierte Roblox-Tools, die Schadsoftware installieren und den vollständigen Zugriff auf infizierte Computer ermöglichen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malware-roblox-cheater-betrug
-
Detecting Cobalt Strike beacons with JA3 and JARM fingerprinting
Cobalt Strike remains a common post-compromise tool in intrusion sets because it gives an operator a flexible command-and-control channel, tasking framework, and a way to blend into normal network traffic. For defenders, the challenge is not just spotting malware on an endpoint. It is identifying the beaconing pattern that sits behind the traffic, especially when……
-
Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on both macOS and Windows machines. Documented by Jamf, unlike most macOS malware, which typically relies on Go or Rust for cross-platform reach, this campaign’s first-stage downloader, a macOS ARM64 Mach-O binary named ZoomMeetings,…
-
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.”These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,”…
-
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.”…
-
Real emails, hijacked payments: Two H1 2026 attack chains
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
-
Homer dichtet Malware
Hacker nutzen Fake-Angebote für Christopher Nolans Odysseus-Film, um Malware mit Lummastealer auszuspielen. Laut der renommierten Althistorikerin Mary Beard hat Christopher Nolan in seiner aktuellen Odysseus-Verfilmung von 2026 Erotik und Witz zugunsten von Gewalt weggekürzt. Hacker transportieren ihrerseits aktuell illegal die Lummastealer-Malware zum Informationsdiebstahl als Angebot vermeintlicher Downloads des Films. Die Experten der Bitdefender Labs beobachten…
-
Google Begins Restoring Blogger Sites After False Malware Alerts
Google is restoring Blogger sites wrongly flagged for malware after hundreds of publishers reported locked or unavailable blogs and false-positive alerts. The post Google Begins Restoring Blogger Sites After False Malware Alerts appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-blogger-malware-false-positive/
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Tags: attack, cybercrime, group, infrastructure, Internet, malware, software, supply-chain, threat, trainingA new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.”The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend…
-
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
-
How Agentic AI Scales Cybercrime
Google’s Hultquist on Autonomous Attacks and Behavioral Defense. Cybercriminals are using agentic AI to automate intrusions, rewrite malware and scale operations with stolen access to artificial intelligence services. Google’s John Hultquist explains why signature-based defenses are losing ground and how behavioral detection can help security teams respond. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-agentic-ai-scales-cybercrime-a-32449
-
250+ ClickFix Domains Hide macOS Malware From Security Scanners
A ClickFix campaign uses browser fingerprinting across more than 250 domains to hide macOS infostealer lures from scanners and security researchers. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-clickfix-domains-browser-fingerprinting-macos-malware/
-
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an infection back to a fake CAPTCHA scam known as ClickFix. The incident came to light during a retrospective threat hunt in June 2026, when a Huntress analyst discovered remnants of a Mac-specific…
-
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.We observed production websites embedding hidden prompt injection payloads inside “Ask AI” buttons on marketing and competitor comparison pages.…
-
Vanta Stealer Uses PyArmor to Steal Browser Passwords, Crypto Wallets and Discord Tokens
Vanta Stealer is a Python”‘based, cross”‘platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller”‘packed executable to harvest browser passwords, crypto wallet data, Discord tokens, gaming accounts, VPN configs, and sensitive documents. Vanta Stealer exemplifies the current shift toward Python for modular, easily maintainable malware, while abusing commercial protection frameworks like PyArmor…
-
Blogger: Google sperrt Hunderte Blogs mit falscher Malware-Warnung
Bei Googles Bloggingdienst Blogger löst die Malware-Erkennung reihenweise Fehlalarme aus. Hunderte von Blogs wurden unverhofft gesperrt. First seen on golem.de Jump to article: www.golem.de/news/blogger-google-sperrt-mit-falscher-malware-warnung-hunderte-blogs-2608-211651.html
-
Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware
Hackers are abusing an Ethereum smart contract as a dead”‘drop resolver to dynamically steer victims’ browsers to rotating command”‘and”‘control (C2) infrastructure in a new Remus infostealer campaign that weaponizes fake cracked software lures and Turkish”‘language SEO poisoning. In this campaign, Remus no longer relies on a static C2 domain or legacy dead-drop platforms like Steam…
-
Neue Shai Hulud-Variante befällt Hunderte npm-Pakete
Tags: malwareIm npm-Ökosystem ist eine neue Angriffswelle aufgetaucht. Die Schadsoftware trägt den Namen “Chaindrop” und gehört zur Familie der Shai-Hulud-Malware, die Sicherheitsforschern bereits seit längerer Zeit bekannt ist. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/neue-shai-hulud-variante-npm
-
South Korea’s government overtakes telcos as top cyber attack target
Kaspersky researcher Sojun Ryu says ransomware crews have joined nation-state groups in going after South Korean organisations, as traces of LLM output start turning up inside malware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647735/South-Koreas-government-overtakes-telcos-as-top-cyber-attack-target
-
Sicherheitstest mit Mythos 5 – KI-Agent wollte Malware in Open-Source-Projekt einschleusen
Bei einem Sicherheitstest versuchte ein auf Mythos 5 basierender Agent, Malware in ein echtes Open-Source-Projekt einzuschleusen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/sicherheitstest-mit-mythos-5-ki-agent-wollte-malware-in-open-source-projekt-einschleusen.98721
-
Blogger: Google sperrt mit falscher Malware-Warnung Hunderte Blogs
Bei Googles Bloggingdienst Blogger löst die Malware-Erkennung reihenweise Fehlalarme aus. Hunderte von Blogs wurden unverhofft gesperrt. First seen on golem.de Jump to article: www.golem.de/news/blogger-google-sperrt-mit-falscher-malware-warnung-hunderte-blogs-2608-211651.html
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/
-
Stairwell Launches Backstory to Map Malware Blast Radius Beyond the First Alert
Stairwell has launched Backstory, an agentic investigation platform designed to trace related malware variants, identify affected systems and map an incident’s full blast radius. The platform was announced July 29 as Stairwell prepared to showcase it at Black Hat USA 2026. Backstory is built to answer what happened, where an incident spread and what needs..…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software…

