Tag: malware
-
Car Infotainment Malware Builds Criminal Proxy Botnet
DoFun Software Updates Exploited to Infect Android Head Units. Attackers are exploiting legitimate software updates to infect Android-based car infotainment systems, or head units, turning them into reverse proxies. Kaspersky linked the malware campaign to the MoYu Group, a threat actor linked to BADBOX and BADBOX 2.0. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/car-infotainment-malware-builds-criminal-proxy-botnet-a-32652
-
Android Car Systems Infected With Malware Through Software Updates
Kaspersky uncovered malware spreading via software updates on Android-based car head units, turning infected systems into proxy nodes in a botnet. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity-threats/news-android-car-malware-software-update-botnet/
-
ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps
ToxicPanda 2.0 now targets 349 financial apps across 16 countries while abusing VPN, Accessibility and Android debugging features for deeper control. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-toxicpanda-2-android-malware-349-financial-apps/
-
That fake Grand Theft Auto VI demo is actually just malware
Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/25/that-fake-grand-theft-auto-vi-demo-is-actually-just-malware/
-
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/fake-openai-codex-download-macos-users/
-
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.”While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to…
-
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the…
-
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how attackers are moving beyond a single delivery vector. A victim may be lured to a fake Cloudflare or Google verification page and instructed to paste a command, persuaded to install apparently legitimate software, or tricked into…
-
Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown
A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-minecraft-weedhack-malware/
-
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control…
-
Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manually executing malware through Terminal. The operation begins when users search for Codex-related terms, including “codex macos download.” Instead of selecting OpenAI’s legitimate listing, victims may encounter a sponsored result that…
-
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers found multiple active websites impersonating popular Minecraft projects, offering paid clients at no cost, and abusing well-known hosting platforms to make malicious downloads appear trustworthy.…
-
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers found multiple active websites impersonating popular Minecraft projects, offering paid clients at no cost, and abusing well-known hosting platforms to make malicious downloads appear trustworthy.…
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,…
-
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer. First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text
-
Fake GTA 6 Extended Look and demo sites deliver an infostealer
Bogus “Play Now” sites are exploiting the GTA 6 leak hype to spread malware that steals passwords stored in browsers. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer/
-
Cybercriminals Turn GTA VI Leaks Into Malware Bait
A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to >>take one for the…
-
Tricky ‘SynkLoader’ Multitool May Herald Ransomware
An advanced, multilingual malware family brings back a trick from yesteryear, screen hijacking, for effective password theft, along with a slew of novel features. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware
-
GTA VI Fake-ISO: 113 GB Download entpuppt sich als Malware-Falle
Tags: malwareGTA VI Fake-ISO mit 113 GB entpuppt sich als Malware-Falle: 99,99 Prozent sollen nur aus Datenmüll bestehen. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/gaming/gta-vi-fake-iso-malware-falle-332956.html
-
Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords
Fake Minecraft clients are delivering WeedHack malware that steals gaming sessions, browser passwords, crypto wallets and personal files from infected Windows systems. First seen on hackread.com Jump to article: hackread.com/fake-minecraft-clients-weedhack-malware-windows-passwords/
-
ToxicPanda Banking Trojan Matures into Enterprise Threat
The latest version of the Android malware has new features that expand its global reach and put more than users’ financial applications at risk. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat
-
Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-codex-download-google-sites/
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) First seen…
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) First seen…
-
Hackers infecting Android car systems to build proxy botnet
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet. First seen on therecord.media Jump to article: therecord.media/android-botnet-china-hackers
-
RAT-Familie Abyssos nutzt wandelnde Verschleierungstechniken
Ende Juni 2026 haben die Sicherheitsforscher des Zscaler-ThreatLabz eine neue Malware-Familie identifiziert, die den Namen Abyssos erhielt. Bei der in C++ geschriebenen Malware handelt es sich um ein modulares Remote-Administration-Tool (RAT). Die Malware besitzt umfangreiche Fähigkeiten für den Diebstahl von Anmeldeinformationen, die Exfiltration von Dateien sowie den direkten Fernzugriff via VNC. Zusätzlich legen die Entwickler…
-
Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign
Open VSX has removed three extension identifiers from its malicious-extension list after the legitimate projects they impersonated began reclaiming their names. The move restores publishing access for the affected maintainers but highlights a supply-chain tracking gap: a single extension ID can represent both a removed malicious artifact and a later legitimate release. Between August 16…
-
Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/android-malware-car-head-unit-badbox/
-
Botnetz aus Autos: Fahrzeug-Infotainmentsysteme mit Malware infiziert
Forscher haben eine Android-Malware entdeckt, die über eine Firmware-Updatefunktion in Infotainmentsysteme von Fahrzeugen eingeschleust wurde. First seen on golem.de Jump to article: www.golem.de/news/botnetz-aus-autos-fahrzeug-infotainmentsysteme-mit-malware-infiziert-2608-212212.html
-
New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks
SynkLoader, a newly identified modular malware framework that combines Python, C#, C++, PowerShell, and memory-resident payloads to evade endpoint detection. Delivered through Microsoft Teams phishing, the operation uses a convincing fake Windows lock screen to capture credentials before enabling network tunneling and interactive access to compromised enterprise environments. Compile timestamps and file metadata indicate the…

