Tag: malware
-
Hackers Use Fake FIFA World Cup 2026 T-Shirt Offers to Spread Voidrift Malware
A fake FIFA World Cup 2026 T-shirt giveaway scam is spreading Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters. First seen on hackread.com Jump to article: hackread.com/hackers-fake-fifa-world-cup-2026-t-shirt-voidrift-malware/
-
Critical SimpleHelp Vulnerability Exploited For Malware Delivery
Attackers exploited a critical SimpleHelp RMM bug to deploy TaskWeaver and Djinn Stealer malware First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/simplehelp-rmm-vulnerability/
-
SimpleHelp Flaw Exploited to Deploy Malware Targeting Windows, macOS, and Linux
A SimpleHelp authentication flaw is being exploited to deploy Djinn Stealer, a cross-platform malware targeting cloud, developer, and AI credentials. The post SimpleHelp Flaw Exploited to Deploy Malware Targeting Windows, macOS, and Linux appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-simplehelp-flaw-djinn-stealer-developer-credentials/
-
DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains
Officials from the US Department of Justice seized nearly 400 domains linked to illegal World Cup streams and warned viewers about the risks of malware, phishing, and data theft. The post DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-doj-illegal-world-cup-streaming-domains/
-
USB drives carrying China-linked malware infected Japanese military networks for nearly a year
Read more in my article on the Hot for Security blog. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/usb-drives-carrying-china-linked-malware-infected-japanese-military-networks-for-nearly-a-year
-
SystemBC Malware Turns Windows Machines Into SOCKS5 Proxies for Ransomware Attacks
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed as a payload in exploit kits around 20182019, SystemBC has evolved into a widely traded commodity tool used by multiple…
-
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer.The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated First seen on thehackernews.com Jump…
-
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)
Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/simplehelp-vulnerability-exploited-cve-2026-48558/
-
Hackers Leverage Blockchain to Hit Japan’s Hotels Through Booking.com Phishing
A wave of phishing emails sent to Booking.com partner accommodations in Japan in May led to blockchain-hosted malware First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hackers-blockchain-japan-hotels/
-
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON
Two concurrent espionage campaigns by Mustang Panda targeting Indian government and energy-sector organisations, deploying a novel malware suite that includes SHARDLOADER, MINIRECON and ZOHOMURK. The intrusions, observed in June 2026, focused on hydropower entities and government offices engaged in MOUs with Taiwanese institutions, using geopolitically themed lures and weaponised archives that sideload malicious DLLs via…
-
Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll
A newly identified Windows backdoor, dubbed Mistic, that has been observed in intrusions since April 2026 and appears designed for stealthy, long-term access. The malware uses DLL sideloading, in-memory execution, and self-deletion to blend into enterprise environments and minimize forensic traces. Mistic is introduced via a DLL sideloading chain that abuses a legitimate executable named…
-
North Korea-Linked macOS Malware Uses Prompt Injection to Evade AI Analysis
SentinelOne says macOS.Gaslight uses prompt injection to mislead AI-based malware analysis, steal data, and use Telegram for C2. The post North Korea-Linked macOS Malware Uses Prompt Injection to Evade AI Analysis appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-macos-gaslight-malware-ai-prompt-injection/
-
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel.Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with First seen on thehackernews.com Jump…
-
DOJ Seizes 400 Illegal FIFA World Cup Streaming Domains
The DOJ seized nearly 400 illegal World Cup streaming domains, warning that piracy sites also pose malware and phishing risks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/doj-seizes-400-illegal-fifa-world-cup-streaming-domains/
-
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/
-
âš¡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open.The noise is not all noise, either. Forums are talking, researchers are finding easy cracks, and defenders have more cleanup waiting.Here’s the full Monday recap.âš¡ Threat of…
-
Gefälschtes Vertrauen wird zur neuen Währung der Cyberkriminalität
Die Kampagne rund um manipulierte Krypto-Tools macht deutlich, wie sehr sich Cyberangriffe inzwischen verändert haben. Malware muss sich heute nicht mehr nur verstecken, sie kann sich auch gezielt als vertrauenswürdiges Produkt inszenieren. In diesem Fall wurde eine gesamte Fake-Reputation-Ökonomie aufgebaut, um einen Crypto-Clipboard-Hijacker als beliebtes, geprüftes und sicheres Tool erscheinen zu lassen. Gefälschte Github-Sterne, künstlich…
-
Webinar: Why business email compromise attacks keep succeeding
Business email compromise attacks increasingly rely on convincing impersonation rather than malware, making them harder for employees and traditional email defenses to detect. This webinar explores how behavioral AI can help identify sophisticated email threats and automate response workflows. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/webinar-why-business-email-compromise-attacks-keep-succeeding/
-
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025.Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half of the…
-
Microsoft Edge: Malware in millionenfach installierten Browser-Add-ons entdeckt
Forscher haben in 119 Browsererweiterungen mit zusammen 2,6 Millionen Installationen Malware gefunden – obwohl sie ziemlich gut versteckt war. First seen on golem.de Jump to article: www.golem.de/news/microsoft-edge-malware-in-millionenfach-installierten-browser-add-ons-entdeckt-2606-210295.html
-
STOCKSTAY Malware Uses WebSocket C2, RSA Encryption, and Environmental Keying for Stealth
Analysis of a .NET backdoor tracked as STOCKSTAY exposes a mature, modular espionage implant actively developed and deployed by the Russia-linked Turla cluster since at least December 2022. STOCKSTAY demonstrates several operational techniques designed to maximize stealth and survivability: secure WebSocket-based C2, asymmetric encryption using a 4096-bit RSA keypair, inter-component IPC, and environment-based keying of…
-
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud.The company calls it StegoAd, a mash-up of steganography and adware, and ties 119 extensions to a single threat…
-
Wenn Vertrauen zur Falle wird: Cyberkriminelle tarnen Malware als beliebtes Krypto-Tool
Selbst wenn Nutzer versuchen, die Schadsoftware manuell zu entfernen, kann sie sich erneut festsetzen oder wiederherstellen. Für Betroffene wird die Bereinigung dadurch deutlich schwieriger. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/wenn-vertrauen-zur-falle-wird-cyberkriminelle-tarnen-malware-als-beliebtes-krypto-tool/a45627/
-
DOJ Seizes Nearly 400 Domains Used for Illegal World Cup Streaming and Malware Threats
The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 internet domains used to stream FIFA World Cup 2026 matches illegally. This operation represents one of the largest coordinated anti-piracy enforcement actions related to a global sporting event. Conducted under the title “Operation Offsides,” it targeted websites that were distributing real-time broadcasts…
-
DOJ Seizes Nearly 400 Domains Used for Illegal World Cup Streaming and Malware Threats
The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 internet domains used to stream FIFA World Cup 2026 matches illegally. This operation represents one of the largest coordinated anti-piracy enforcement actions related to a global sporting event. Conducted under the title “Operation Offsides,” it targeted websites that were distributing real-time broadcasts…
-
Millenium RAT Uses Base64 and XOR Configuration to Hide Telegram C2 Settings
Millenium RAT version 4.* exposes a compact but potent evolution: the malware has migrated from .NET to native C++, while retaining a stealthy Telegram-based command-and-control (C2) model that requires no bespoke server infrastructure. The sample set and telemetry analyzed by Group-IB show the RAT embeds its entire configuration inside an RCDATA resource, masks that configuration…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 103
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers A VBScript campaign distributed through WhatsApp deploying RMM software Lost in relocation: analysis of a new loader distributing CASTLESTEALER…
-
Clean GitHub repo tricks AI coding agents into running malware
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/
-
Malware-Laced USBs Breach Japanese Military Networks
Reused USB Drives Linked to China Spread Malware to Private Sector. Counterfeit flash drives embedded with a Chinese-linked computer virus and used by the Japanese army are now dispensing malware throughout other secure networks in the country. The virus went overlooked until February 2025, when military personnel reported slower device speeds. First seen on govinfosecurity.com…
-
Weak Access Controls Leave Enterprise Networks at Risk
Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/weak-access-controls-leave-enterprise-networks-at-risk/

