Tag: malware
-
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/
-
Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said. First seen on therecord.media Jump to article: therecord.media/ukraine-malware-russia-ransomware
-
Mantax Otax Targets Android Phones With Spyware and Ransomware
Mantax Otax Android malware steals messages, PINs, and files, monitors screens, and uses ransomware and harassment to pressure victims into paying. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-mantax-otax-android-malware-apac-indonesia/
-
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive…
-
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
-
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy…
-
Detecting commandcontrol traffic at the network layer
Command-and-control traffic, often shortened to C2, is the communication path an attacker uses to control a compromised system after initial access. Once malware or a hands-on operator has a foothold, C2 is how they issue commands, move data, stage tools,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-command-and-control-traffic-at-the-network-layer/
-
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to…
-
Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison
Lytvynenko Admitted Developing Malware and Stealing Data for Conti. A U.S. court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison after he admitted developing malware and stealing data for Conti, the ransomware operation blamed for more than 1,000 victims and $150 million in payments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ukrainian-conti-ransomware-developer-gets-4-years-in-us-prison-a-32805
-
Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/
-
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking…
-
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a…
-
Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat actor UAC-0099, which used the method during an attack against an organization in Ukraine. The group inserted a safety-sensitive, weapon-related request…
-
New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed…
-
Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking…
-
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
A new Windows remote-access trojan dubbed SloppyRAT, which appears to be positioned as an intrusion-enablement tool for ransomware operations. First observed in June 2026, the malware is delivered through a multi-stage ClickFix chain and combines host reconnaissance, stealthy command execution, reverse proxying, and resilient command-and-control mechanisms to support post-compromise activity and lateral movement. Rather than…
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
Cisco Firewall Bugs Let in Sandworm, Qilin
Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws. Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cisco-firewall-bugs-let-in-sandworm-qilin-a-32793
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
SloppyRAT: A New Tool For Ransomware Attacks
IntroductionIn June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/sloppyrat-a-new-tool-for-ransomware-attacks/
-
AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-papercut-ai-agent-attack-education/
-
AI-Orchestrated PaperCut Attack Compromises 440 Servers Across 48 Countries
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-papercut-ai-agent-attack-education/
-
Hackers Are Hijacking Claude Accounts and Burning Through Paid Usage
Infostealer malware is hijacking authenticated Claude sessions, allowing attackers to consume paid AI usage without stealing users’ passwords. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-claude-session-theft-infostealer-malware-2026/
-
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.A work profile is a separate space that Android typically reserves for employer apps, and what’s inside it…
-
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/mantaxotax-android-malware/
-
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain controller. This technique, known as DCSync, allows attackers with privileged domain credentials to impersonate a legitimate domain controller and request sensitive directory replication data. Unlike noisy attacks that use malware on servers or attempt to extract credentials…
-
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Tags: credentials, crypto, cyber, cybercrime, data, exploit, malware, password, ransomware, theft, threatThreat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one…

