Tag: malware
-
Cavern Manticore Malware Uses Low-Detection .NET Modules for Reconnaissance and Lateral Movement
A newly identified Iran-linked threat group, tracked as Cavern Manticore, is deploying a sophisticated modular command-and-control (C2) framework built on a shared .NET foundation to conduct stealthy reconnaissance and lateral movement against Israeli government and IT organizations. The group’s custom C2 components exhibit extremely low detection rates on public sandboxes, enabling persistent access while evading…
-
Fake IT support calls on Microsoft Teams push EtherRAT malware
Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/
-
âš¡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary.Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems…
-
ClickFix Scams Abuse Google, Cloudflare Checks to Deliver 7 Malware Families
Malwarebytes links fake Google and Cloudflare verification pages to shared ClickFix infrastructure delivering StealC, NetSupport and other malware. First seen on hackread.com Jump to article: hackread.com/clickfix-scam-google-cloudflare-7-malware-families/
-
SilverFox Campaign Turns ValleyRAT Into Multi-Stage Malware With Rootkit Capabilities
The SilverFox advanced persistent threat (APT) group has escalated its offensive toolkit by transforming ValleyRAT from a conventional remote access trojan into an eight-stage malware chain culminating in a kernel-mode rootkit. This evolution marks a significant shift in post-exploitation persistence, blending user-mode orchestration with deep kernel control to evade detection and maintain long-term access. The…
-
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can decode.But TrojPix works only…
-
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that’s capable of targeting Windows, Linux, and macOS environments.According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150 for one month to $1,200 for lifetime access. Other subscription tiers include $300 for First seen on…
-
Backup und Recovery im Autopilot – Kontinuierliche Datenvalidierung schließt Malware-Infektionen in Wiederherstellungsprozessen aus
First seen on security-insider.de Jump to article: www.security-insider.de/kontinuierliche-datenvalidierung-schliesst-malware-infektionen-in-wiederherstellungsprozessen-aus-a-bda26039174ba1a4e07f1d90481e2217/
-
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Scanners meant to catch malicious add-on “skills” for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology.Their strongest trick slipped past every scanner tested more than 90% of the time, and the…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 104
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer Building a CI/CD pipeline for Sigma rules Inside StegoAd: How a Threat Actor Evolved to Fuel Silent Ad…
-
Neue Schadsoftware ChocoPoC nutzt GitHub aus
Die neue Malware ChocoPoC nimmt Sicherheitsforscher ins Visier. Angreifer verstecken den Schadcode in den Abhängigkeiten von GitHub-Exploits. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/github-schadsoftware-chocopoco
-
Avalon Malware Uses Legal Document Lure to Deliver CrownX Ransomware Capabilities
A previously undocumented malware framework, tracked as Avalon, that uses a spoofed legal-document lure and a multi-stage, fileless-oriented chain to deliver a ransomware component internally labeled CrownX. The campaign demonstrates a shift toward consolidation of multiple offensive capabilities into a single recovered payload and highlights how modern development practices including likely AI assistance are lowering…
-
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The…
-
TimbreStealer Malware Targets Mexico Companies With Advanced Evasion Techniques
A new campaign linked to the TimbreStealer information stealer that specifically targets Mexican companies, employing layered evasion and sophisticated runtime tricks to frustrate detection and analysis. Researchers Euler Neto and Cristóbal Tárraga detail behaviors that echo a 2024 Cisco Talos report while highlighting a notable variant: the use of DLL side”‘loading with unusually large malicious…
-
Verified X Sponsored Ad Spreads Mac Malware While ConsentFix Hijacks Microsoft 365 Accounts
A Mac-targeting ClickFix campaign amplified through a verified X sponsored ad, and a novel browser-based hijack technique called ConsentFix that exfiltrates Microsoft 365 session tokens without traditional malware. Researchers at Jamf and Malwarebytes tracked the X incident where a verified account ran a sponsored advertisement promoting a macOS utility dubbed “DynamicLake” a lookalike for legitimate…
-
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls.Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one First seen on thehackernews.com Jump to article: thehackernews.com/2026/07/new-avalon-malware-framework-packs.html
-
GTA 6 Early Access: Fake-Webseiten locken Fans in Krypto-Falle
GTA 6 Early Access gibt es offiziell nicht. Fake-Webseiten locken mit VIP-Zugängen, Malware und Krypto-Betrug. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/gaming/gta-6-early-access-krypto-falle-331077.html
-
Lawmaker Probing Pegasus Spyware Infected Using Same Malware
Members of European Parliament Seek Fresh Spyware Probe Following Revelations. Multiple European lawmakers are calling for a fresh investigation into spyware following new revelations that a European Parliament committee member probing Pegasus mobile device hacking software himself fell victim to attackers who wielded the surveillance tool against him. First seen on govinfosecurity.com Jump to article:…
-
New PamStealer Malware Targets macOS Users via Fake Maccy Clipboard App
The newly spotted PamStealer is spreading through a fake Maccy clipboard app and steal Mac passwords, browser data and clipboard content. First seen on hackread.com Jump to article: hackread.com/pamstealer-malware-macos-fake-maccy-clipboard-app/
-
Netzwerk zerschlagen: Millionen Streaminggeräte per Malware als Proxy missbraucht
Tags: malwareEin riesiges Proxy-Netzwerk namens Netnut hat Cyberkriminelle ihren Traffic über private Internetanschlüsse leiten lassen. Doch damit ist jetzt Schluss. First seen on golem.de Jump to article: www.golem.de/news/netzwerk-zerschlagen-millionen-streaminggeraete-per-malware-als-proxy-missbraucht-2607-210471.html
-
Netzwerk zerschlagen: Millionen Streaminggeräte per Malware als Proxy missbraucht
Tags: malwareEin riesiges Proxy-Netzwerk namens Netnut hat Cyberkriminelle ihren Traffic über private Internetanschlüsse leiten lassen. Doch damit ist jetzt Schluss. First seen on golem.de Jump to article: www.golem.de/news/netzwerk-zerschlagen-millionen-streaminggeraete-per-malware-als-proxy-missbraucht-2607-210471.html
-
Netzwerk zerschlagen: Millionen Streaminggeräte per Malware als Proxy missbraucht
Tags: malwareEin riesiges Proxy-Netzwerk namens Netnut hat Cyberkriminelle ihren Traffic über private Internetanschlüsse leiten lassen. Doch damit ist jetzt Schluss. First seen on golem.de Jump to article: www.golem.de/news/netzwerk-zerschlagen-millionen-streaminggeraete-per-malware-als-proxy-missbraucht-2607-210471.html
-
SharkLoader Malware Uses Perfect DLL Hijacking to Execute Cobalt Strike in Memory
SharkLoader, used by an intrusion cluster tracked as StrikeShark to deliver Cobalt Strike Beacon entirely in memory across a wide international footprint. The campaign combines opportunistic exploitation of exposed internet-facing infrastructure with custom droppers disguised as trusted installers to establish initial access, then relies on layered, memory-only execution techniques and “Perfect DLL Hijacking” to minimize…
-
SharkLoader Malware Uses Perfect DLL Hijacking to Execute Cobalt Strike in Memory
SharkLoader, used by an intrusion cluster tracked as StrikeShark to deliver Cobalt Strike Beacon entirely in memory across a wide international footprint. The campaign combines opportunistic exploitation of exposed internet-facing infrastructure with custom droppers disguised as trusted installers to establish initial access, then relies on layered, memory-only execution techniques and “Perfect DLL Hijacking” to minimize…
-
Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks
Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026. This action is part of an ongoing campaign to…
-
Newly discovered PamStealer isn’t your typical macOS malware
The discovery underscores the increased effort being poured into Mac infostealers. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthy/
-
This Threat Hunter Helped Cops Bust Up An African Cybercrime Syndicate
Dark Reading Confidential Episode 15: Interpol relied on Will Thomas and his team at Team Cymru to help break up a sprawling cybercrime ring, leading to the arrest of 574 suspects, the recovery of more than $3 million, and the decryption of six malware variants. Here’s his story. First seen on darkreading.com Jump to article:…

