Malware & Threats
Between June and August, over 300 entities were targeted with the Atomic macOS Stealer via malvertising.
Hi, what are you looking for?
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
Between June and August, over 300 entities were targeted with the Atomic macOS Stealer via malvertising.
PipeMagic, which poses as a ChatGPT application, is a modular malware framework that provides persistent access and flexibility.
Noteworthy stories that might have slipped under the radar: federal court filing system hack, Chanel data breach, emergency CISA directive.
Microsoft has unveiled Project Ire, a prototype autonomous AI agent that can analyze any software file to determine if it’s malicious.
The Koske Linux malware shows how cybercriminals can use AI for payload development, persistence, and adaptivity.
More information has emerged on the ToolShell SharePoint zero-day attacks, including impact, victims, and threat actors.
Akamai’s analysis of the Coyote malware revealed that it abuses Microsoft’s UIA accessibility framework to obtain data.
The Lumma Stealer is back after Microsoft and law enforcement took action to significantly disrupt the malware’s infrastructure.
Microsoft says the Chinese threat actors Linen Typhoon, Violet Typhoon, and Storm-2603 have been exploiting the ToolShell zero-days.
More details emerged on the ToolShell zero-day attacks targeting SharePoint servers, but confusion remains over the vulnerabilities.
Iranian APT MuddyWater has been using new versions of the DCHSpy Android surveillance tool since the beginning of the conflict with Israel.
Google has filed a lawsuit against the Badbox 2.0 botnet operators, after identifying over 10 million infected Android devices.
Obfuscated JavaScript code is embedded within SVG files for browser-native redirection to malicious pages.
The Interlock ransomware group has partnered with the KongTuke TDS to distribute a new RAT variant via FileFix attacks.
Noteworthy stories that might have slipped under the radar: Microsoft shows attack against AMD processors, SentinelOne details latest ZuRu macOS malware version, Indian APT...
A stolen copy of Shellter Elite shows how easily legitimate security tools can be repurposed by threat actors when vetting and oversight fail.
SentinelOne says the fake Zoom update scam delivers ‘NimDoor’, a rare Nim-compiled backdoor.
China-linked Silver Fox hacking group is targeting Chinese users with fake installers carrying a RAT and a rootkit.
G Data has observed a surge in malware infections originating from ConnectWise applications with modified certificate tables.
SonicWall says a modified version of the legitimate NetExtender application contains information-stealing code.