Tag: malware
-
Weak Access Controls Leave Enterprise Networks at Risk
Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/weak-access-controls-leave-enterprise-networks-at-risk/
-
Chinese APT CL1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…
-
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, First seen…
-
Comparing Antivirus Software 2026: Avast vs. AVG
Compare Avast and AVG antivirus software in 2026. We assess features like malware detection, real-time protection, pricing, customer support, and more. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/avast-vs-avg-antivirus/
-
Norton vs McAfee: Compare Antivirus Software in 2026
Compare Norton and McAfee antivirus software in 2026. We assess features like malware detection, real-time protection, pricing, customer support, and more. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/products/norton-vs-mcafee-antivirus/
-
Turla group adds more malware to Russia’s espionage efforts against Ukraine
Threat intelligence researchers at Google described StockStay, the latest malware developed by the Russian cyber-espionage group known as Turla. First seen on therecord.media Jump to article: therecord.media/russia-turla-espionage-ukraine-stockstay-malware
-
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks
Japan’s defense infrastructure has faced scrutiny following an investigation that revealed members of the Japan Self-Defense Forces (JSDF) used counterfeit USB drives embedded with malware linked to China on systems handling classified information. According to findings reported by Nikkei, these compromised USB devices were acquired at significantly lower costs through unofficial channels. They were subsequently…
-
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem.”The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse,…
-
macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst
macOS.Gaslight: DPRK Rust implant for Mac with a prompt injection payload designed to fool AI-based malware analysts. SentinelLabs researchers spotted a Rust-based macOS implant, dubbed macOS.Gaslight, that surfaced in early June after an Apple XProtect update pointed to a VirusTotal sample uploaded on May 22. The binary was undetected by static engines at the time…
-
A privacy-first take on local malware analysis
Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/burnyard-local-malware-analysis/
-
A privacy-first take on local malware analysis
Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/burnyard-local-malware-analysis/
-
A privacy-first take on local malware analysis
Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/burnyard-local-malware-analysis/
-
A privacy-first take on local malware analysis
Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/burnyard-local-malware-analysis/
-
Mini Shai-Hulud Worm Poisons LeoPlatform npm Packages to Steal Developer and CI/CD Secrets
A fresh supply-chain wave tied to the Mini Shai-Hulud, Miasma, and Hades malware families is actively poisoning npm packages in the LeoPlatform and RStreams ecosystems and expanding into source-repository compromises. The intrusion blends registry poisoning, install-time execution via binding.gyp, Bun-staged JavaScript loaders, GitHub Actions abuse, and persistence hooks for IDEs and AI coding assistants an…
-
Mini Shai-Hulud Worm Poisons LeoPlatform npm Packages to Steal Developer and CI/CD Secrets
A fresh supply-chain wave tied to the Mini Shai-Hulud, Miasma, and Hades malware families is actively poisoning npm packages in the LeoPlatform and RStreams ecosystems and expanding into source-repository compromises. The intrusion blends registry poisoning, install-time execution via binding.gyp, Bun-staged JavaScript loaders, GitHub Actions abuse, and persistence hooks for IDEs and AI coding assistants an…
-
Hackers Use Malicious Minecraft Fabric Mods to Deploy LoaderClient and WeedHack Stealer
Hackers are weaponizing malicious Minecraft Fabric mods to deliver LoaderClient. This stage-one malware loader steals session data and hands it off to the WeedHack stealer through a fileless, blockchain-backed execution chain. The campaign stands out for its use of EtherHiding, where the command-and-control URL is pulled from an Ethereum smart contract instead of a conventional…
-
Operation Endgame Disrupts StealC Malware Infrastructure
Operation Endgame disrupted StealC infrastructure and seized millions of stolen credentials through a coordinated public-private effort. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/operation-endgame-disrupts-stealc-malware-infrastructure/
-
Russian APT ‘Gamaredon’ Upgrades Its Arsenal, Requiring New Defenses
The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/russia-apt-gamaredon-arsenal-defense
-
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact.The malware has been codenamed Gaslight owing to this deceptive behavior. It’s been assessed with high…
-
12 Jahre alter Bug: Manipulierbare Download-Links auf Python.org
Tags: malwareAngreifer hätten über das offizielle Python-Downloadportal jahrelang Malware verbreiten können. Ursache war eine Codeänderung von 2014. First seen on golem.de Jump to article: www.golem.de/news/12-jahre-alter-bug-manipulierbare-download-links-auf-python-org-2606-210174.html
-
Behörden greifen ein: Millionen von Passwörtern mit Malware erbeutet
Tags: malwareStrafverfolger mehrerer Länder haben 326 mit verschiedenen Malware-Varianten verbundene Server vom Netz genommen, darunter 40 aus Deutschland. First seen on golem.de Jump to article: www.golem.de/news/operation-endgame-behoerden-zerschlagen-mehrere-grosse-malware-netzwerke-2606-210156.html
-
Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement
Microsoft touted its latest action against malware infrastructure as a new approach aimed at the full cybercrime “supply chain.” Europol said more than 300 servers were targeted. First seen on therecord.media Jump to article: therecord.media/stealc-amadey-socgholish-malware-takedown-europol-microsoft
-
Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks
Operation Endgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns. First seen on hackread.com Jump to article: hackread.com/operation-endgame-stealc-amadey-socgholish-malware/
-
Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame
Operation Endgame disrupted malware services like StealC and Amadey that enable ransomware, fraud, and attacks on critical infrastructure. Between June 15 and 19, 2026, Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK, and the US, alongside private firms like Microsoft, Bitdefender, IBM X-Force, Proofpoint, Infoblox, Shadowserver,…
-
Russia’s Gamaredon Adapts Tactics to Target Ukraine
Tags: cloud, data, espionage, infrastructure, malware, phishing, russia, spear-phishing, tactics, ukraineEset Documents New Malware Families and Infrastructure Tactics. Eset found Russia’s FSB-linked Gamaredon expanded its malware toolkit, launched dozens of spear-phishing campaigns, and increasingly relied on legitimate cloud, tunneling and social platforms to conceal C2 infrastructure, exfiltrate data and sustain espionage operations targeting Ukraine. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/russias-gamaredon-adapts-tactics-to-target-ukraine-a-32068
-
Europol, Microsoft Hit Malware Network Behind 27M Stolen Logins, 140,000 Infected Computers
Europol and Microsoft disrupted malware infrastructure linked to 27 million stolen login credentials and 140,000 infected computers in a global cybercrime network. The post Europol, Microsoft Hit Malware Network Behind 27M Stolen Logins, 140,000 Infected Computers appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-europol-microsoft-malware-takedown-emea-eu/
-
Malicious Edge extension abuses Native Messaging as bridge to malware
A malicious Microsoft Edge extension dubbed ‘Edgecution’ has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/
-
LokiBot Malware Uses API Hashing and 3DES-Encrypted C2 to Hide Infostealer Activity
LokiBot, a long-lived infostealer first advertised in May 2015, continues to evolve. Recent samples demonstrate deliberate attempts to evade static detection and frustrate analysis by combining API hashing with 3DES-encrypted command-and-control (C2) configuration stored inside the binary. The result is a compact, stealthy loader that reconstructs and executes a traditional LokiBot payload while limiting observable…
-
Shai-Hulud Hades Payload Hits 20 Leo/RStreams npm Packages in Fresh Supply Chain Attack
A fresh supply-chain wave by the Shai-Hulud/Hades family that infected 20 npm packages in the Leo/RStreams ecosystem, an AWS-native event streaming SDK widely used for Kinesis, Firehose, Lambda and S3-based pipelines. The malicious releases were detected shortly after publication and, while not a dramatic redesign of prior Hades/Miasma variants, demonstrate the malware family’s continued operational…
-
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered
Tags: attack, breach, credentials, cybercrime, finance, fraud, infrastructure, law, malware, microsoft, network, ransomwareA coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC.”The main common goal was to disrupt the ‘assembly lines’ cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure,” Europol said in First seen…

