Tag: malware
-
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration.The tech giant said it required multiple endpoint and network behaviors to align before First seen on…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
AndroidKombination beantragt Kredite und leitet Daten weiter
Group-IB hat die Android-Malware WindRelay dokumentiert, die zusammen mit SpyNote Smartphones in gefälschte Kartenlesegeräte verwandelt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/android-malware-kredite
-
China-Linked APT Uses AI to Optimize Hand-Built Malware
SilkParasite Deployed Against Central Asian Governments. Bitdefender said the China-linked SilkParasite espionage campaign deployed seven modular RATs against Central Asian governments, with coding artifacts indicating AI assisted expert developers rather than generating the stealth-focused malware itself. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/china-linked-apt-uses-ai-to-optimize-hand-built-malware-a-32597
-
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver their advertised features, but their shared codebase also enables runtime JavaScript execution and access to desktop-capture functionality creating a serious surveillance and post-compromise risk. Search-optimized…
-
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over…
-
Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud
-
Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver
GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs, raising fresh supply-chain security concerns around vendor-hosted driver downloads. The company said the affected file was confined to a legacy resource, not its current support portal or factory-installed Windows images. The incident came…
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
Shadow hVNC Malware Kit Gives Hackers Hidden Windows Desktop for Covert Remote Control
A newly advertised malware-as-a-service toolkit named Shadow hVNC combines browser credential theft, hidden virtual desktop control, reverse proxying, and extensive persistence into a single Windows-focused payload. Marketed by a user known as “RemoteX” in March 2026, the kit gives operators a parallel Win32 desktop where they can browse, run tools, and interact with hijacked sessions…
-
‘Turf War’ Between Claude Agents Leads to Self-Replicating Malware
Three testing models with the same goal but different directives engaged in increasingly aggressive territorial attacks on one another, according to Anthropic. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/turf-war-claude-agents-self-replicating-malware
-
‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware
Trellix says MessiahGPT is marketed to cybercriminals as an uncensored AI service for ransomware, phishing kits, malware, and breach exploitation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-messiahgpt-malware-phishing-ai/

