Malware & Threats Medusa Ransomware Uses Malicious Driver to Disable Security Tools The Medusa ransomware relies on a malicious Windows driver to disable the security tools running on the infected systems. Ionut ArghireMarch 24, 2025
Malware & Threats Microsoft Warns of New StilachiRAT Malware Microsoft has shared details on StilachiRAT, an evasive and persistent piece of malware that facilitates sensitive data theft. Eduard KovacsMarch 19, 2025
Malware & Threats 11 State-Sponsored APTs Exploiting LNK Files for Espionage, Data Theft ZDI has uncovered 1,000 malicious .lnk files used by state-sponsored and cybercrime threat actors to execute malicious commands. Eduard KovacsMarch 18, 2025
Malware & Threats 100 Car Dealerships Hit by Supply Chain Attack The websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise. Ionut ArghireMarch 17, 2025
Phishing Microsoft Warns of Hospitality Sector Attacks Involving ClickFix A cybercrime group named Storm-1865 has targeted hospitality organizations via fake Booking.com emails and the use of social engineering. Eduard KovacsMarch 13, 2025
Artificial Intelligence DeepSeek’s Malware-Generation Capabilities Put to Test Researchers have analyzed the ability of the Chinese gen-AI DeepSeek to create malware such as ransomware and keyloggers. Eduard KovacsMarch 13, 2025
Malware & Threats New Ballista IoT Botnet Linked to Italian Threat Actor Cato Networks has analyzed a new IoT botnet named Ballista, which targets TP-Link Archer routers. Eduard KovacsMarch 11, 2025
Malware & Threats Microsoft Says One Million Devices Impacted by Infostealer Campaign Microsoft has uncovered a malvertising campaign that redirected users to information stealers hosted on GitHub. Ionut ArghireMarch 7, 2025
Malware & Threats New ‘Auto-Color’ Linux Malware Targets North America, Asia New Linux malware named Auto-Color, which allows full remote access to compromised devices, targets North America and Asia. Eduard KovacsFebruary 26, 2025
Malware & Threats New FrigidStealer macOS Malware Distributed as Fake Browser Update A recently identified macOS infostealer named FrigidStealer has been distributed through a compromised website, as a fake browser update. Ionut ArghireFebruary 19, 2025
Malware & Threats Golang Backdoor Abuses Telegram for C&C Communication A newly discovered Golang backdoor is abusing Telegram for communication with its command-and-control (C&C) server. Ionut ArghireFebruary 18, 2025
Malware & Threats Microsoft Warns of Improved XCSSET macOS Malware Microsoft has observed a new variant of the XCSSET malware being used in limited attacks against macOS users. Ionut ArghireFebruary 18, 2025
Malware & Threats New FinalDraft Malware Spotted in Espionage Campaign A newly identified malware family abuses the Outlook mail service for communication, via the Microsoft Graph API. Ionut ArghireFebruary 17, 2025
Data Breaches OpenAI Finds No Evidence of Breach After Hacker Offers to Sell 20 Million Credentials A hacker recently offered to sell 20 million OpenAI credentials, but the data likely comes from information stealers, not the AI firm’s systems. Eduard KovacsFebruary 11, 2025
Malware & Threats 22 New Mac Malware Families Seen in 2024 Nearly two dozen new macOS malware families were observed in 2024, including stealers, backdoors, downloaders and ransomware. Eduard KovacsFebruary 4, 2025
Malware & Threats Developers Targeted With Malware Disguised as DeepSeek Package Python developers looking to integrate DeepSeek into their projects were targeted with malicious packages delivered through PyPI. Eduard KovacsFebruary 4, 2025
Malware & Threats Cyber Insights 2025: Malware Directions The continuing advance of AI brings the likelihood of effective, specific vulnerability-targeted new malware automatically produced in hours rather than days or weeks ever... Kevin TownsendJanuary 23, 2025
Malware & Threats Homebrew macOS Users Targeted With Information Stealer Malware A malicious campaign has been redirecting macOS users to a fake Homebrew website, infecting them with information stealer malware. Ionut ArghireJanuary 23, 2025
Ransomware Compromised AWS Keys Abused in Codefinger Ransomware Attacks A ransomware group tracked as Codefinger is using compromised AWS keys to encrypt S3 bucket data using SSE-C. Ionut ArghireJanuary 14, 2025
Malware & Threats Infostealer Masquerades as PoC Code Targeting Recent LDAP Vulnerability A fake proof-of-concept (PoC) exploit for a recent LDAP vulnerability distributes information stealer malware. Ionut ArghireJanuary 13, 2025