Tag: malware
-
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first documented malware infection chain purpose-built for automotive head units and has been attributed with high confidence to the MoYu…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111
Tags: banking, botnet, edr, infrastructure, international, linux, malware, ransomware, spyware, windowsSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]…
-
ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/
-
Security Affairs newsletter Round 591 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries Malware Hijacks Android Car Head Units…
-
New Agent Tesla malware version uses emoji obfuscation to evade detection
First seen on scworld.com Jump to article: www.scworld.com/brief/new-agent-tesla-malware-version-uses-emoji-obfuscation-to-evade-detection
-
New Agent Tesla malware version uses emoji obfuscation to evade detection
First seen on scworld.com Jump to article: www.scworld.com/brief/new-agent-tesla-malware-version-uses-emoji-obfuscation-to-evade-detection
-
New malware targets Android car head units for ad fraud and botnet creation
First seen on scworld.com Jump to article: www.scworld.com/brief/new-malware-targets-android-car-head-units-for-ad-fraud-and-botnet-creation
-
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/
-
Neue Android-Malware kombiniert Fernzugriff und NFC für Kontodiebstahl in Echtzeit
First seen on t3n.de Jump to article: t3n.de/news/android-malware-nfc-betrug-spynote-windrelay-1759120/
-
Malware Hijacks Android Car Head Units
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any ordinary app but making zero effort to disguise itself as…
-
New Manic Android Malware Uses Offline Networks to Drain Bank Accounts
Manic Android malware steals banking credentials and can relay stolen data through nearby infected phones, complicating traditional device isolation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/
-
New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/
-
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.”The malware spread through the…
-
Attackers impersonate popular AI brands to spread malware
Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/21/ai-brand-impersonation-malware-malware-research/
-
New Agent Tesla Malware Variant Boosts Evasion Capabilities
An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/agent-tesla-malware-evasion/
-
Malware-Kampagne gegen Fahrzeug-Headunits des Herstellers DoFun
Kaspersky-Experten haben eine neuartige Android-Malware entdeckt, die gezielt Fahrzeug-Headunits des Herstellers DoFun angreift. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malware-kampagne-dofun
-
Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing bank-payment lure with a fileless execution chain that keeps the final malware payload out of sight of traditional disk-based scanning. The messages masquerade as internal forwarded…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Supply-Chain-Angriff: Backdoor in millionenfach geladene Rust Crates eingeschleust
Angreifern ist es gelungen, mehrere populäre Rust Crates mit einer Backdoor-Malware zu verseuchen. Entwickler sollten dringend handeln. First seen on golem.de Jump to article: www.golem.de/news/supply-chain-angriff-backdoor-in-millionenfach-geladene-rust-crates-eingeschleust-2608-212158.html
-
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers and implants emerging in late May. Manic has rapidly evolved through July, incorporating stronger anti-analysis protections, in-memory DEX loading, lock-screen phishing, and…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit, and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
SilkParasite Uses Google Drive as C2 to Hide RAT Traffic Inside Trusted Cloud Services
SilkParasite, a long-running cyberespionage operation targeting government bodies across Central Asia through a compact but highly mature arsenal of remote access trojans. Assessed with medium confidence as China-nexus activity, the campaign stands out for using Google Drive as a command-and-control channel, allowing malware traffic to blend into cloud activity that many enterprises inherently trust. The…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…

