Tag: malware
-
What the Minnesota Water Attacks Reveal About Securing Remote Access to Critical Infrastructure
Tags: access, ai, attack, authentication, cisa, control, corporate, credentials, cyberattack, data-breach, exploit, Hardware, identity, infrastructure, Internet, law, least-privilege, malware, mfa, monitoring, network, password, risk, router, supply-chain, technology, vpn, zero-day, zero-trustWhen headlines break about cyberattacks targeting critical infrastructure, the conversation often turns immediately to zero-day exploits, advanced malware, and other sophisticated techniques. The recent attacks on municipal water systems across at least seven US states, including more than 30 Minnesota water and wastewater utilities, illustrate why this assumption can be misleading. As a “recovering CISO” who…
-
Adform-Skript kompromittiert: Malware über unzählige Webseiten verbreitet
Ein Angreifer hat Malware in ein Skript von Adform eingeschleust. Der Schadcode wurde dadurch an Besucher zahlreicher Webseiten ausgespielt. First seen on golem.de Jump to article: www.golem.de/news/adform-skript-kompromittiert-malware-ueber-unzaehlige-webseiten-verbreitet-2608-211525.html
-
Mapping the malware blast radius a single alert won’t show you
In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/mike-wiacek-stairwell-backstory-malware-blast-radius/
-
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. After several months of apparent inactivity, the actors behind the XCSSET malware resurfaced with version 40 (v40), a major re-architecture of the…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Malware Delivered Through Malvertising MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions Unpacking “Cruciferra”: An Analysis of a…
-
New HollowFrame loader and Matryoshka malware family discovered
Tags: malwareFirst seen on scworld.com Jump to article: www.scworld.com/brief/new-hollowframe-loader-and-matryoshka-malware-family-discovered
-
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…
-
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight…
-
MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan. Documented by Huntress, the kit targets browser credentials, keychain secrets, and cryptocurrency wallets. The attack begins when victims search Google for >>how to install Claude on a Mac<< and click a sponsored…
-
Malvertising-Kampagne täuscht macOS-Nutzern Systemabsturz vor
Eine macOS-Kampagne verleitet Nutzer über eine vermeintlich abstürzende Systemaktualisierung zur Ausführung eines Schadbefehls. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/malvertising-kampagne-macos
-
North Korea’s APT Capabilities Are No Longer State-Exclusive
Tags: access, apt, cyber, finance, group, hacker, infrastructure, korea, lazarus, malware, military, north-korea, ransomware, skillsAhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns. Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military hackers allegedly used state-trained skills to steal bank funds, exposing cyber capability diffusion and blowback inside the regime. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-koreas-apt-capabilities-are-no-longer-state-exclusive-a-32392
-
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…
-
ESET tracks rise in malicious AI skills and adaptable malware
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/eset-tracks-rise-in-malicious-ai-skills-and-adaptable-malware/
-
Anthropic AI Models Hacked 3 Real Companies
Setup Error Let Models Steal Data and Release Malware Online. Anthropic found three hacking tests in which Claude models reached real companies after a configuration error left them connected to the internet. One accessed customer data, another released malware that ran on 15 computers and a third scanned 9,000 systems. First seen on govinfosecurity.com Jump…
-
Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/31/infoblox-domain-abuse-campaigns-report/
-
The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats
Tags: ai, cyber, cyberattack, data, exploit, finance, fraud, government, infrastructure, intelligence, leak, malicious, malware, software, threatThis weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses. First seen…
-
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command”‘and”‘control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain, and exchange infrastructure. Instead of traditional web C2, the implant resolves its live command”‘and”‘control endpoints from Ethereum smart contracts, a takedown”‘resistant pattern known as…
-
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively grading host hardware for cryptomining suitability, then exiting without dropping a single binary. Cowrie, which exposes a realistic fake Linux shell and records full command transcripts, logged a connection from 91.92.40.13 that…
-
Astaroth Banking Trojan Adds WhatsApp Web Spambot to Spread Malware Across Brazil
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts into automated malware relays, marking a significant evolution of the LATAM e-crime ecosystem. Traditionally propagated via email and archive-based phishing, recent campaigns such as STAC3150 and the “Boto Cor-de-Rosa” operation shifted distribution to WhatsApp…
-
Anthropic’s Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/
-
Why brand impersonation is becoming an initial access vector
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing…
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software…
-
Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum and Solana blockchain domain names to hide its command infrastructure. The botnet evolved from jackskid and fbot malware…
-
PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access. First seen on hackread.com Jump to article: hackread.com/phantomenigma-infects-malware-hijack-gov-sites/
-
Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai…
-
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang.…
-
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal…
-
Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. Unlike legacy Mirai variants, Tengu employs a hybrid C2 model that blends plaintext and encrypted communications. Initial registration and heartbeat messages are transmitted in cleartext, while…
-
Fake ShinyHunters Emails Give Victims 48 Hours to Pay $2,000 Bitcoin Ransom
Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom is paid within 48 hours. Despite the technical-sounding claims, there is no evidence of actual device compromise, malware deployment, or recorded content behind these messages. The emails impersonate…

