Tag: spyware
-
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/
-
Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs
Iranian state-linked attackers are using fake MRI scans and software lures to deploy CHOSEN BRICK spyware on Windows PCs. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-chosen-brick-spyware-windows/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
UK, US and Netherlands warn of Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted…
-
Iranian Hackers Dodging Corporate Defenses to Reach Critics
Joint Advisory Details Chosen Brick Spyware Used Against Iran’s Critics Abroad. Iranian state hackers are steering dissidents, activists and journalists away from corporate devices and onto personal computers to plant spyware that can capture screens, record audio and steal messages, according to a joint advisory from British, U.S. and Dutch intelligence agencies. First seen on…
-
UK, US and Netherlands warn over Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
Mantax Otax Targets Android Phones With Spyware and Ransomware
Mantax Otax Android malware steals messages, PINs, and files, monitors screens, and uses ransomware and harassment to pressure victims into paying. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-mantax-otax-android-malware-apac-indonesia/
-
Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking…
-
Anthropic details bad actors’ efforts to misuse its AI for bioweapons
Report comes two days after former employee quit claiming company’s models could cause human extinction by 2030Criminals, state-sponsored groups, spyware vendors, scientists and propagandists have attempted to use Anthropic’s powerful artificial intelligence models to design missiles and bombs, create deadly pathogens and surveil dissidents, according to a<a href=”https://www.anthropic.com/threat-intelligence-report-september-2026#biological-misuse-sep-26″> threat intelligence report the company published on…
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/mantaxotax-android-malware/
-
European parliament members call for slowdown of Serbia’s EU entry over spyware use
Tags: spywareThe letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. First seen on cyberscoop.com Jump to article: cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/
-
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging keystrokes, monitoring clipboard data, capturing screenshots, and harvesting extensive Facebook profile information. The newly observed variant, identified in August 2026, also expands browser and local data theft, using a split Telegram command-and-control (C2) design to…
-
Pegasus and NoviSpy Used Against Serbian Protesters
Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group’s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation,…
-
Large group of Serbian opposition, activist figures targeted with spyware
At least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers. First seen on therecord.media Jump to article: therecord.media/serbia-spyware-pegasus-europe
-
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone
The iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.”Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” the Citizen Lab said. “We…
-
Malicious Composer themes deliver spyware to unpatched iOS devices
First seen on scworld.com Jump to article: www.scworld.com/brief/malicious-composer-themes-deliver-spyware-to-unpatched-ios-devices
-
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet. First seen on cyberscoop.com Jump to article: cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/
-
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.”The injected code runs two operations against a site’s visitors: a mobile ad-fraud and…
-
Gefälschte Indeed-Apps verbreiten Spyware unter Android-Jobsuchenden
Sicherheitsforscher von Malwarebytes warnen vor gefälschten Stellenanzeigen auf der großen Jobplattform Indeed. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/gefaelschte-indeed-apps
-
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
13 malicious Composer theme packages on Packagist that turn Vietnamese movie and comic streaming websites into delivery points for iPhone spyware, gambling redirects, ad fraud, and cryptocurrency-wallet theft. Once an operator installs one of the trojanized themes through Composer, the bundled front-end JavaScript is served to every visitor. Mobile users are selectively targeted, while iPhone…
-
Indeed Job Scam: Fake Recruiters Are Spreading Android Spyware
Scammers are using fake Indeed interview apps to infect Android phones with spyware. Learn how the attack works and how job seekers can avoid it. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-indeed-fake-interview-app-android-malware/
-
How AI could make it harder for governments to use hacking tools
AI is proving effective at finding and exploiting vulnerabilities. Some say this will make it harder for governments to use hacking tools and spyware and could reignite calls to backdoor devices. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/31/how-ai-could-make-it-harder-for-governments-to-use-hacking-tools/
-
Beware of fake Indeed interview apps used to install spyware
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/beware-of-fake-indeed-interview-apps-used-to-install-spyware/

