Tag: malware
-
Hackers Use Infostealer Malware to Steal Claude Session Cookies and Hijack Accounts
Anthropic’s Claude AI platform is currently dealing with two separate cybercrime campaigns that aim to steal account credentials, misuse paid subscriptions, and reinstall malware even after a victim believes their device has been cleaned. In response to this threat, Anthropic has started invalidating compromised sessions, removing saved payment methods, and refunding verified fraudulent charges. While…
-
Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
A compromised attacker-side workstation has given researchers an unusual view into the operational ecosystem behind a suspected Blind Eagle malware campaign, exposing RAT builders, phishing templates, bulk-mail tooling, crypter activity and infrastructure tracking records. Rather than directly exposing a modified executable, the account hosted a legitimate AutoIt interpreter alongside separately retrievable malicious script logic an…
-
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
A recent router-level DNS change is gaining attention as a method to reduce exposure to phishing pages and malware across all devices connected to a home network. Cybersecurity expert Luis Catacora has recommended replacing a router’s default DNS resolvers with Cloudflare’s malware-filtering addresses: 1.1.1.2 as the primary resolver and 1.0.0.2 as the secondary. Simple Router…
-
When Malware Does Math: The Arms Race Between Sandboxes and Self-Aware Threats
Modern malware can detect sandboxes and stay dormant, making inactivity a potential sign of evasion. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/when-malware-does-math-the-arms-race-between-sandboxes-and-self-aware-threats/
-
BlueDelta Targets Defense and Diplomatic Organizations With HOOKEDGE Malware
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activity, tracked from late September 2025 through early April 2026, relied on macro-enabled Microsoft Word documents and legitimate webhook infrastructure to establish access, execute…
-
Hundreds of WordPress Sites Hijacked to Show Fake reCAPTCHA and Steal Windows Passwords.
Hundreds of compromised WordPress websites are being used in a sophisticated malware-delivery campaign that combines browser persistence, blockchain-hosted payloads, fake reCAPTCHA prompts and fileless execution to deploy the Amatera information stealer on Windows systems. The campaign stands out for placing its malicious logic across nine layers designed to minimize durable evidence: no conventional payload server,…
-
Go Loader Uses Anti-Sandbox Checks and SNOWLIGHT to Execute Fileless VShell RAT in Memory
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access trojan (RAT) to targets likely associated with Chinese academic and technical research environments. The attack uses a custom 32-bit Go loader that performs sandbox checks, opens a legitimate-looking Word document as a decoy, and…
-
Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected
Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework called GoCaracal. Arctic Wolf Labs uncovered the framework while investigating a targeted intrusion in June 2026 against a communications organization in Venezuela. The company assesses, with medium confidence, that the activity is tied to Dark…
-
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon”‘linked espionage group, and says it deployed a…
-
Fake GTA 6 Demo Spreads Malware: How to Spot the Scam
There is no legitimate GTA 6 demo. Fake Rockstar sites are distributing Vidar malware that targets passwords, cookies, and logged-in browser sessions. The post Fake GTA 6 Demo Spreads Malware: How to Spot the Scam appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-fake-gta-6-demo-malware-scam/
-
Australian Police Charge Two Over TeamPCP Credential Theft
Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source software and used it to steal data from thousands of organisations. >>Two West…
-
Arctic Wolf Labs entdeckt neues Malware-Framework <>
Ein neues Malware-Framework in zwei unterschiedlich umfangreichen Ausführungen und ein Ausweichmechanismus über die Ethereum-Blockchain: Arctic Wolf Labs hat bei der Untersuchung eines gezielten Angriffs auf eine Organisation aus dem Kommunikationssektor in Venezuela die bislang nicht dokumentierte Malware <> entdeckt. Arctic Wolf ordnet den Angriff mit mittlerer Sicherheit der Cyberspionage-Gruppe Dark Caracal zu. Die wichtigsten Erkenntnisse…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/fbi-disrupts-china-linked-hacking-network/
-
SLEEPWALKER Backdoor Uses Magic Packet, DLL Side-Loading and In-Memory Shellcode Execution
A newly documented Windows backdoor named SLEEPWALKER combines passive network monitoring, DLL side-loading, and encrypted bytecode to remain dormant until attackers deliver a precisely crafted trigger packet. The malware does not beacon to a conventional command-and-control server, making it particularly difficult to identify through outbound-traffic monitoring alone. The 59,904-byte unsigned file masquerades as Microsoft’s dpapi.dll…
-
Nimbus Manticore expands infrastructure and malware arsenal
First seen on scworld.com Jump to article: www.scworld.com/brief/nimbus-manticore-expands-infrastructure-and-malware-arsenal
-
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
GoCaracal is a new modular malware framework that broadens Dark Caracal’s capabilities to steal data and maintain access to victims. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/dark-caracal-adds-new-malware-cyber-espionage-arsenal
-
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka First seen on thehackernews.com…
-
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to give operators covert, durable access to compromised internal networks. The research began with public reporting from Kaspersky on Mirage Kitten’s newer malware ecosystem, which included the NightLedger backdoor and WebSocket tunneling tools ArcBridge and BridgeHead.…
-
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be…
-
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/tortoiseshell-new-backdoor-ssh/
-
Phishing ohne Link und Malware: Wenn ein Telefonanruf zum eigentlichen Angriff wird
Eine Debt-Relief-Phishing-Kampagne trifft mehr als 9.000 Organisationen. Angreifer nutzen Telefonnummern statt Links und verlagern den Angriff ins Gespräch. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/phishing-ohne-link-und-malware-wenn-ein-telefonanruf-zum-eigentlichen-angriff-wird/a46266/
-
Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2
A fake Claude Desktop installer campaign is using Bing malvertising to impersonate trusted Claude. ai-hosted content, DLL sideloading, and blockchain-based command-and-control to deploy the SectopRAT remote-access trojan. CyberProof researchers said an agent-led hunt scoped the full intrusion chain across endpoint telemetry in about ten minutes, turning a single suspicious scheduled task into a confirmed multi-stage…
-
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted developer tooling can be turned into an effective execution layer for malware while reducing the value of file-signature and hash-based detection. The…
-
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be…
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
Hackers Hide Malware Inside Plain English Words to Infect Windows Users With Amatera Stealer
Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The loader disguises executable shellcode as sequences of ordinary English words, helping malware evade static inspection before reconstructing and launching the final payload in memory. Microsoft previously observed ACR Stealer operators using fake verification prompts,…
-
Core Werewolf Hackers Deploy New CoreRAT Malware Against Russian Government and Defense Organizations
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector bodies and defense-industry organizations. The shift is notable because Core Werewolf, previously associated with the abuse of legitimate UltraVNC remote-access software and smaller custom backdoors, now operates a full-featured C++ RAT of its own.…

