Tag: malware
-
‘MessiahGPT’ AI Service Promises Ransomware, Phishing Kits, and Malware
Trellix says MessiahGPT is marketed to cybercriminals as an uncensored AI service for ransomware, phishing kits, malware, and breach exploitation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-messiahgpt-malware-phishing-ai/
-
Apple Mac Malware Lets Attackers Control Browser Sessions After Infection
AmnesiaStealer malware targets macOS with data theft and remote browser-session control, potentially exposing accounts already open on compromised Macs. The post Apple Mac Malware Lets Attackers Control Browser Sessions After Infection appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-amnesiastealer-mac-malware/
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed as a MaaS framework by a forum user known as “LenAI.” Its core feature is a traffic distribution system that routes victims to…
-
Malware – Shai-Hulud-Wurm kompromittiert mehr als 400 npm-Pakete
Tags: malwareFirst seen on security-insider.de Jump to article: www.security-insider.de/shai-hulud-wurm-npm-keyv-cacheable-a-5ab064c6a0b5bd36ed9809e3b1d1fa37/
-
The Art of Detonating Malware: Lessons from a Research Lab
Modern ransomware operators are no longer content to simply encrypt data and hope for a payout. They are actively working to evade every layer of enterprise defense, from sandboxes and EDR to backup infrastructure itself, using techniques observed in Cohesity’s in-house REDLab malware research environment. For security leaders, backup and recovery systems can no longer..…
-
Fake The Odyssey Downloads Are Hiding Password-Stealing Malware
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information. The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-the-odyssey-fake-downloads-lumma-stealer/
-
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.South Korean security firm…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Tags: attack, authentication, cloud, cryptography, data-breach, malware, mfa, passkey, password, phishing, windowsThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a First…
-
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a new GitHub Advisory Database importer for OpenSSF’s malicious-packages repository, which enhances supply chain detection across these eight ecosystems. GitHub Expands…
-
Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware
Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad credential and cryptocurrency-wallet stealers. Yeeth Security identified two publishers, helper-beeps and web3devtoolsx, distributing related solidity-pro packages that use Solidity-themed branding, obfuscation, and version churn to target web3 developers. The campaign reflects…
-
Open Source: Android-Trojaner soll in Software von MG-Autos stecken
In einer Software-Dokumentation des chinesischen Herstellers MG taucht die Malware Teardroid auf. Das könnte jedoch ein Scan-Fehler sein. First seen on golem.de Jump to article: www.golem.de/news/open-source-android-trojaner-soll-in-software-von-mg-autos-stecken-2608-211759.html
-
Go-Based macOS Malware Steals Crypto and Secrets
A macOS malware variant has been detected stealing crypto, passwords and more First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/gobased-macos-malware-crypto-and/
-
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/github-dependabot-malware-alerts/
-
Cybersecurity Newsletter Weekly Top 50 Biggest Cybersecurity Stories $70M Bitcoin Heist,Google Passkey Theft, Copilot CEO Fraud,Chrome 151 Claude Exploits More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 37, 2026. It was a brutal week for trust in the tools we rely on: a Coldcard firmware flaw drained $70 million in Bitcoin, malware learned to steal Google’s synced passkeys, and […]…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba…
-
Odysseus-Film: Homer dichtet Malware
Hacker nutzen Fake-Angebote für Christopher Nolans Odysseus-Film, um Malware mit LummaStealer auszuspielen. Laut der renommierten Althistorikerin Mary Beard hat Christopher Nolan in seiner aktuellen Odysseus-Verfilmung von 2026 Erotik und Witz zugunsten von Gewalt weggekürzt. Hacker transportieren ihrerseits aktuell illegal die LummaStealer-Malware zum Informationsdiebstahl als Angebot vermeintlicher Downloads des Films. Die Experten der Bitdefender Labs… First…
-
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/09/week-in-review-cisco-fixes-imc-bug-patch-tuesday-forecast-black-hat-usa-2026/
-
Roblox-Cheater werden selbst zu Betrogenen
Cyberkriminelle nutzen die Suche vieler Gamer nach Cheats und Hilfsprogrammen gezielt aus. Nach Erkenntnissen der Bitdefender Labs verbreiten Angreifer manipulierte Roblox-Tools, die Schadsoftware installieren und den vollständigen Zugriff auf infizierte Computer ermöglichen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malware-roblox-cheater-betrug
-
Detecting Cobalt Strike beacons with JA3 and JARM fingerprinting
Cobalt Strike remains a common post-compromise tool in intrusion sets because it gives an operator a flexible command-and-control channel, tasking framework, and a way to blend into normal network traffic. For defenders, the challenge is not just spotting malware on an endpoint. It is identifying the beaconing pattern that sits behind the traffic, especially when……
-
Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on both macOS and Windows machines. Documented by Jamf, unlike most macOS malware, which typically relies on Go or Rust for cross-platform reach, this campaign’s first-stage downloader, a macOS ARM64 Mach-O binary named ZoomMeetings,…

