Tag: malware
-
Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
Tags: cyber, government, healthcare, infrastructure, kaspersky, malware, microsoft, software, technology, windowsAn active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, highlighting the broad appeal of software-download lures. Microsoft has not attributed the activity to a nation-state actor, but the campaign’s infrastructure, payload…
-
Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
A sophisticated malware campaign has abused a trojanized installer for the legitimate Exodus cryptocurrency wallet to deploy a modular remote access trojan (RAT) capable of stealing browser credentials, session cookies, and extension data. The campaign prioritizes long-term interactive access over direct cryptocurrency theft, combining hidden VNC, SOCKS proxying, file management and browser-data theft in an…
-
Anthropic: Attackers Using Infostealers to Hijack Claude Sessions
Anthropic is warning Claude users that attackers are using infostealer malware to compromise their login sessions and stealing usage to run their nefarious activities. It’s the latest demonstration of the shift by bad actors from credentials to session tokens and authentication cookies. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/anthropic-attackers-using-infostealers-to-hijack-claude-sessions/
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
esearch by:hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early…
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
esearch by:hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early…
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
esearch by:hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early…
-
Infostealer malware compromises Claude accounts, bypassing 2FA
First seen on scworld.com Jump to article: www.scworld.com/brief/infostealer-malware-compromises-claude-accounts-bypassing-2fa
-
RevStealer malware spread through fake Claude Opus 5 download
Tags: malwareFirst seen on scworld.com Jump to article: www.scworld.com/news/revstealer-malware-spread-through-fake-claude-opus-5-download
-
Credential Security: What Endpoint Protection Really Means for Secrets
TL;DREndpoint protection means AV or EDR: The term “endpoint protection” almost always refers to antivirus or EDR. Antivirus started as signature-based malware detection; EDR added continuous behavioral monitoring and response. Both are designed to detect and stop malicious activity on… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/credential-security-what-endpoint-protection-really-means-for-secrets/
-
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/spring-ring-vishing-campaign-microsoft-teams/
-
EtherHiding Exposed: What Security Leaders Need to Know
EtherHiding Exposed: What Security Leaders Need to Know September 1, 2026 Jean-Pierre Mouton BLOG 5 min. TL;DR A malware campaign has compromised at least 31 organizations’ websites to deploy a persistent backdoor. It identifies its command and control (C2) infrastructure using… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/etherhiding-exposed-what-security-leaders-need-to-know/
-
Iranian cyber spies target aviation, fintech developers with new malware
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia. First seen on therecord.media Jump to article: therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware
-
Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme
Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines in Kansas. This case highlights a growing cyber-physical threat targeting financial institutions across the United States. The case arose from an FBI investigation into an alleged scheme to force automated teller machines (ATMs) to dispense…
-
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.Russian cybersecurity company Kaspersky is tracking the First seen…
-
Fake Claude Opus 5 app delivers malware and wipes its own tracks
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/
-
AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks
BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the…
-
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/
-
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilities, and in-memory payload execution. No threat actor, victim, delivery chain, or live campaign has yet been attributed to the malware. SLEEPWALKER is an unsigned 64-bit Windows DLL…
-
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that’s been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis.The idea, ESET said in a series of posts on X, is to deliberately trip a large language model’s…
-
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to…
-
Anthropic Warning: Infostealer Malware Is Hijacking Claude Sessions, Draining Accounts
Infostealer malware is stealing authenticated Claude browser sessions, letting attackers access paid AI accounts and consume victims’ usage allowances. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-claude-session-hijacking-infostealer-malware/
-
Anthropic Warning: Infostealer Malware Is Hijacking Claude Sessions, Draining Accounts
Infostealer malware is stealing authenticated Claude browser sessions, letting attackers access paid AI accounts and consume victims’ usage allowances. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-claude-session-hijacking-infostealer-malware/
-
AI Agents Can Infect Each Other: Mind Viruses and Turf Wars
Self-propagating instructions can spread through ordinary agent memory. Isolated agents with conflicting goals wrote malware to sabotage each other. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-agents-can-infect-each-other-mind-viruses-and-turf-wars/
-
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential…
-
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese…
-
Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. >>The malware identified … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/
-
Anthropic locks out Claude users after infostealers hijack login sessions
Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. >>The malware identified … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/claude-accounts-compromised-through-infostealer/
-
Chrome und Edge: Mehrere Browser-Add-ons per Update mit Malware verseucht
Forscher haben 19 mit Malware verseuchte Browsererweiterungen für Chrome und Edge entdeckt. Der Schadcode wurde erst nachträglich eingeschleust. First seen on golem.de Jump to article: www.golem.de/news/chrome-und-edge-mehrere-browser-add-ons-per-update-mit-malware-verseucht-2608-212452.html
-
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/russian-hackers-ai-safety-filters-manipulation/

