Tag: malware
-
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and coding repositories, using trojanized macOS applications distributed as disk images and installer packages. Jamf Threat Labs identified 14 malicious DMG and PKG samples impersonating legitimate Mac software, all of which ultimately deliver an OtterCookie-aligned JavaScript implant designed for…
-
Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns
Cybersecurity firm Huntress has uncovered a wave of malicious installations of ScreenConnect, a widely used remote-support tool, that spread between machines without any further action from a victim or an attacker, a self-propagating attack chain researchers likened to a computer worm. In a blog post published this week, Huntress said its Security Operations Center (SOC)…
-
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.”Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial First seen on thehackernews.com Jump to article:…
-
Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is…
-
Russian man indicted for spreading malware to 80,000 freelancers
A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/03/russian-national-indicted-freelance-platform-malware/
-
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.”The technique’s appeal is…
-
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.”The technique’s appeal is…
-
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international…
-
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international…
-
2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international…
-
Gambling Goblin missbraucht Regierungswebsites als SEO-Waffe
Gambling Goblin kapert brasilianische Regierungswebsites, manipuliert Suchergebnisse und schafft eine Infrastruktur, die auch Malware verbreiten könnte. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/gambling-goblin-missbraucht-regierungswebsites-als-seo-waffe/a46322/
-
Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning
A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct large-scale SEO poisoning and online-gambling fraud. The operation has been active since mid-2025 and represents a notable shift in Brazil’s threat landscape. Rather than deploying the country’s more familiar banking malware, the attackers are…
-
Your threat feed is someone else’s database: What ingesting malware intel at scale takes
The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/03/github-threat-intelligence-feed-ingestion/
-
Global Public-Private Action Disrupts Russia-Linked Sality Botnet
US, European Law Enforcement, Cyber Firms Target Two-Decade-Old P2P Malware Network. U.S. and European authorities, CrowdStrike and Shadowserver disrupted the Russia-linked Sality botnet by exploiting its trusted-peer protocol to isolate roughly 15,000 infected machines and sever a malware network that had operated since 2003. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/global-public-private-action-disrupts-russia-linked-sality-botnet-a-32732
-
Five Men Tried to Make Kansas ATMs Spit Out Cash
Five men pleaded guilty after targeting Kansas ATMs with jackpotting malware as the FBI warns of a nationwide rise in attacks and financial losses. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-kansas-atm-jackpotting-malware-guilty-pleas/
-
Russian national facing 20 years for malware campaign that infected 80,000 freelancers
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week. First seen on therecord.media Jump to article: therecord.media/russian-national-facing-20-years-malware-campaign
-
Fake Software Update Installs a Real Crypto Wallet Rigged So It Can Never Open
Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool. The firm said it identified four separate organisations…
-
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.”The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/fake-software-installers-disable.html
-
Threat Intelligence: Definition, Benefits, and Use Cases
Security teams rarely struggle because they lack data. More often, the challenge is deciding which signals actually deserve attention. Modern security environments generate information about suspicious IP addresses, malicious domains, malware samples, phishing infrastructure, ransomware activity, attacker behavior, and thousands of other indicators. Without context, that volume can quickly become another source of noise. Threat…
-
Threat Gang ‘Springs’ Vishing Attacks on Microsoft Teams Users
The Spring Ring operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users
-
Russian Man Extradited Over Malware Campaign Targeting Freelancers
Russian man extradited to US over malware campaign that targeted 80,000 freelance users First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-man-extradited-malware/
-
Russian Man Extradited Over Malware Campaign Targeting Freelancers
Russian man extradited to US over malware campaign that targeted 80,000 freelance users First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-man-extradited-malware/
-
Sality, one of the longest-running botnets, finally gets disrupted
U.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators. First seen on therecord.media Jump to article: therecord.media/sality-botnet-cyber-doj
-
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were…
-
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney’s…
-
US charges Russian for infecting 80,000 freelancers with malware
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-charges-russian-for-infecting-80-000-freelancers-with-malware/
-
Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/
-
Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation.The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation.…
-
Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
Tags: cyber, government, healthcare, infrastructure, kaspersky, malware, microsoft, software, technology, windowsAn active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, highlighting the broad appeal of software-download lures. Microsoft has not attributed the activity to a nation-state actor, but the campaign’s infrastructure, payload…

