Tag: malware
-
Hackers compromise Rust crate arrayref to inject malware
First seen on scworld.com Jump to article: www.scworld.com/brief/hackers-compromise-rust-crate-arrayref-to-inject-malware
-
Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure
First seen on scworld.com Jump to article: www.scworld.com/news/black-hat-def-con-attendees-targeted-in-malware-scheme-with-google-doc-lure
-
Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation.The affected releases are arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, all published from the same owner First…
-
China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments. First seen on therecord.media Jump to article: therecord.media/china-cyber-espionage-central-asia
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development…
-
ThreatsDay: Gogs 10.0 RCE, n8n WorkflowRCE, $10M Reward, GLM-5.3 AI Exploit and More
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort…
-
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers’ systems during compilation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/
-
‘Grandoreiro’ Malware Resurfaces With Mexico Campaign
The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/grandoreiro-resurfaces-mexico-campaign
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In late July 2026, multiple ClickFix campaigns generated through the ErrTraffic malware-as-a-service platform and used to deliver Cruciferra, a loader advertised…
-
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with “significant enhancements,” including a set of 167 remote commands and expands its targeting footprint globally.Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications. First…
-
New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
Hackers Trick AI Agents Into Telling Users to Install the Malware Themselves
A supply-chain campaign targeting OpenClaw has shown how threat actors can turn autonomous AI agents into persuasive malware-delivery intermediaries. Rather than relying only on exploit code, attackers poisoned the ClawHub skill registry with seemingly legitimate extensions whose instructions prompted users to install fake prerequisite tools or paste obfuscated commands into a terminal. The campaign, tracked…
-
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that…
-
Detecting DCSync attacks using directory replication event logs
DCSync is one of the more important identity abuse techniques to understand if you run Active Directory. It does not rely on malware on the domain controller itself, and it can be carried out using legitimate directory replication interfaces if an attacker has the right permissions. That makes it especially relevant for defenders who want……
-
Microsoft Defender Update Crashes Virus Scans on Windows PCs
Microsoft Defender has been aborting Quick, Full, and Offline virus scans on Windows systems following a series of Security Intelligence updates released on August 18, 2026. This issue has affected both consumer devices and Microsoft Defender for Endpoint-managed environments, disrupting a critical malware-detection capability for administrators and home users alike. Microsoft Defender Update Crashes Virus…
-
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and Microsoft Copilot into convincing lures for infostealers, browser hijackers and remote-access backdoors. Sophos X-Ops reviewed 12 months of Managed Detection and Response (MDR) investigations, spanning July 2, 2025 to June 29, 2026. They…
-
Aeternum Operators Use Polygon Smart Contracts to Rotate Malware C2 Domains Dynamically
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control (C2) domains without depending on conventional attacker-owned servers. The approach turns a public blockchain into resilient C2 infrastructure that is substantially harder to disrupt through domain seizures, hosting takedowns, or sinkholing. Rather than contacting a fixed…
-
Geekom admits malware found in legacy mini PC driver download
Tags: malwareFirst seen on scworld.com Jump to article: www.scworld.com/brief/geekom-admits-malware-found-in-legacy-mini-pc-driver-download
-
Microsoft Links More Than 30 Domains to MacSync Stealer
Microsoft linked more than 30 rotating domains to MacSync Stealer by correlating endpoint and network behavior across the malware’s attack chain. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-microsoft-macsync-stealer-30-domains/
-
Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON
A threat actor impersonating a senior executive at a well-known cryptocurrency media outlet attempted to infect a Huntress researcher with malware in the days following this year’s Black Hat and DEF CON conferences, according to new research from the security vendor. The campaign began on X (formerly Twitter), where an account impersonating the executive sent…
-
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
Tags: malwareeSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/maas-clickfix-errtraffic-cruciferra/
-
Gefälschte CAPTCHAs und gehackte WordPress-Seiten treiben neue Malware-Kampagne
Check Point deckt StopAndProtect auf: Mehr als 5.000 infizierte Rechner, 2.000 gehackte WordPress-Seiten und ClickFix-Angriffe per Fake-CAPTCHA. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/gefaelschte-captchas-und-gehackte-wordpress-seiten-treiben-neue-malware-kampagne/a46206/
-
China-Nexus Hackers Target Myanmar Diplomats With QUICAgent Go Backdoor via Malicious VHD Files
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based backdoor, dubbed QUICAgent, through Virtual Hard Disk (VHD) files disguised as benign images. The campaign relies on highly targeted social engineering. One malicious file, named TrainingAnnouncement.jpg, is not an image but a VHD container.…
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.”The operation doesn’t rely on a single piece of malware, but on a whole toolkit of criminal software…

