Malware & Threats Cyberspy Group Hacked Governments and Critical Infrastructure in 37 Countries Palo Alto Networks has not attributed the APT activity to any specific country, but evidence points to China. Eduard KovacsFebruary 5, 2026
Malware & Threats Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit The threat actor uses a signed driver file containing two user-mode shellcodes to execute its ToneShell backdoor. Ionut ArghireDecember 30, 2025
Malware & Threats Cisco Routers Hacked for Rootkit Deployment Threat actors are exploiting CVE-2025-20352, a recent Cisco zero-day, to deploy a rootkit on older networking devices. Ionut ArghireOctober 16, 2025
Malware & Threats SonicWall Updates SMA 100 Appliances to Remove Overstep Malware The software update includes additional file checks and helps users remove the known rootkit deployed in a recent campaign. Ionut ArghireSeptember 24, 2025
Malware & Threats Hundreds Download Malicious NPM Package Capable of Delivering Rootkit Threat actor uses typosquatting to trick hundreds of users into downloading a malicious NPM package that delivers the r77 rootkit. Ionut ArghireOctober 5, 2023