Tag: malware
-
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Tags: credentials, crypto, cyber, cybercrime, data, exploit, malware, password, ransomware, theft, threatThreat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one…
-
Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/
-
Podcast: BeaverTail and InvisibleFerret The Malware That Rewrites Itself for Every Target
Sep 9, 2026 Podcast: BeaverTail and InvisibleFerret The Malware That Rewrites Itself for Every Target Subscribe on Your Preferred Platform SpotifyListen Now Apple PodcastsListen Now YouTubeListen Now In This Episode In Part 2 of our DPRK deep dive, we… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/podcast-beavertail-and-invisibleferret-the-malware-that-rewrites-itself-for-every-target/
-
CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough
Adobe patched the actively exploited CVE-2026-75650 Magento zero-day, but compromised stores still need malware hunting and broad credential rotation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-adobe-commerce-cve-2026-75650-stylesmuggler/
-
Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware
Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake >>leaked<< copies of the hotly anticipated game. GTA6 is not due for release for another three months, but a wave of gameplay footage leaks and an…
-
WeedHack Malware Persists as Fake Minecraft Sites Survive C2 Disruption
Tags: malwareFake Minecraft sites continue distributing WeedHack malware through SEO poisoning and trusted hosting platforms despite disruption of its original C2 infrastructure. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-weedhack-fake-minecraft-malware/
-
North Korea-linked Hackers Hide a Backdoor Inside HAProxy
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s…
-
Hackers Create Domain Admin Account and Disable Security Tools Inside Windows Network
A newly documented ransomware intrusion attributed to The Gentlemen shows how attackers can convert a foothold in a Windows environment into domain-wide control by elevating accounts, turning off endpoint defenses, and abusing trusted Active Directory infrastructure to distribute ransomware. The operation illustrates a recurring enterprise risk: attackers do not need highly customized malware to compromise…
-
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two…
-
IT Help Desk Impersonation Lets Hackers Bypass MFA
Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PREY-0058 bypasses endpoint security entirely by targeting Microsoft 365 and SaaS environments through pure social…
-
Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through
A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can turn into a software supply-chain incident. Attackers pushed malicious versions across npm packages, including widely used visualization and frontend dependencies.…
-
Definition MaaS | Malware-as-a Was ist Malware-as-a-Service (MaaS)?
First seen on security-insider.de Jump to article: www.security-insider.de/was-ist-malware-as-a-service-maas-a-83116b8121180b9193079849d16eaf6d/
-
Attackers use rogue ScreenConnect clients to spread malware
A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. >>A CVE identifier … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/07/connectwise-screenconnect-file-transfer-flaw/
-
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
Tags: access, backdoor, cve, cyber, exploit, flaw, linux, malware, remote-code-execution, vulnerabilityA sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation of CVE-2025-53521, an unauthenticated remote code execution flaw affecting BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the vulnerability and links the related compromise activity…
-
Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks
A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash…
-
The 12 Best Network Sandboxing Solutions, Compared and Priced
Best value overall: ANY.RUN. It publishes its pricing, offers a free community tier that analysts genuinely use daily, and its interactive model lets you click through the malware yourself which defeats evasion techniques that beat automated sandboxes. Best evasion resistance: VMRay. Best if you already own the platform: Fortinet, Palo Alto, Check Point, or Cisco.…
-
JSCeal Hides Crypto Malware in V8 Bytecode
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a format that makes analysis much harder. Check Point presented its latest…
-
Attackers spread malware through ScreenConnect file transfers
A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. >>A CVE identifier … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/07/connectwise-screenconnect-file-transfer-flaw/
-
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.”The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
-
Fake Minecraft Mod Drops Myth Stealer RAT to Steal Passwords and Remotely Control PCs
A trojanized Minecraft optimization mod posing as a companion to the legitimate Lithium project has been used to deploy Myth Stealer 3.2-FIX, a password-stealing malware family with remote-access, surveillance, persistence, and victim-harassment capabilities. The malicious archive, tracked as MythStealer.jar_, masquerades as Lithium Extras 0.15.0+mc1.21.1 by “soder.” It abuses the reputation of CaffeineMC’s legitimate Lithium performance…
-
Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands
A newly identified Chromium-based post-exploitation toolkit named PEEP can turn Google Chrome and Microsoft Edge into persistent remote-access platforms, enabling attackers to steal browser data, hijack sessions, manage files and execute shell commands on compromised endpoints. Unlike a conventional initial-access malware strain, PEEP requires attackers to already possess administrative privileges or code-execution access on a…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted Infrastructure Gryxa: The AI-Built Toolkit That Watches How You Remove It ValleyRAT masquerading as adware…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging keystrokes, monitoring clipboard data, capturing screenshots, and harvesting extensive Facebook profile information. The newly observed variant, identified in August 2026, also expands browser and local data theft, using a split Telegram command-and-control (C2) design to…
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/

