Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth
MEDIUM
Malware

Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth

Cheap Android TV boxes are pre-installed with Fuyao malware, impersonating phones for ad fraud and turning devices into residential proxy nodes.

Runtime Rebel Intel
4 min read · Jul 31, 2026
MA
HIGH
Malware

Astaroth's Spambot Component: Expanding Phishing and Exfiltration

Analysis of Astaroth trojan's new spambot component, detailing its capabilities for email harvesting, spam distribution, and data exfiltration tactics.

Runtime Rebel Intel
5 min read · Jul 30, 2026
MA
HIGH
Malware

SSH Botnet Reconnaissance Before Linux Cryptominer Deployment

An SSH botnet performs extensive hardware and system reconnaissance on Linux targets before deploying an optimized cryptocurrency miner. Weak credentials exploited.

Runtime Rebel Intel
4 min read · Jul 30, 2026
Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service
HIGH
Malware

Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service

Analysis of the 'Flying Eagle' mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…

Runtime Rebel Intel
4 min read · Jul 30, 2026
Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence
MEDIUM
Malware

Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence

The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.

Runtime Rebel Intel
4 min read · Jul 28, 2026
MA
HIGH
Malware

Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay

Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.

Runtime Rebel Intel
4 min read · Jul 27, 2026
Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience
HIGH
Malware

Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience

Dysphoria IoT botnet evolves with blockchain-based C2 and victim relays after JackSkid disruption, posing new challenges for defenders.

Runtime Rebel Intel
4 min read · Jul 27, 2026
SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly
HIGH
Malware

SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly

The SourTrade malvertising operation bypasses security controls by using the victim's browser to assemble malicious Bun runtime executables in real-time.

Runtime Rebel Intel
4 min read · Jul 25, 2026
MA
MEDIUM
Malware

JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses

Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.

Runtime Rebel Intel
4 min read · Jul 25, 2026
MA
HIGH
Malware

Dolphin X Malware: AI-Driven Target Prioritization & Defense

Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…

Runtime Rebel Intel
5 min read · Jul 24, 2026
MA
HIGH
Malware

Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware

A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.

Runtime Rebel Intel
4 min read · Jul 23, 2026
MA
HIGH
Malware

Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence

CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.

Runtime Rebel Intel
5 min read · Jul 23, 2026
Brazilian Banking Trojan Expansion into Portugal Targets Businesses
MEDIUM
Malware

Brazilian Banking Trojan Expansion into Portugal Targets Businesses

Portuguese businesses face increased risk from Brazilian banking trojans leveraging shared language for phishing and credential theft.

Runtime Rebel Intel
4 min read · Jul 23, 2026
MA
HIGH
Malware

msaRAT Malware Hijacks Browser Debugging for Stealthy C2 Traffic

Chaos ransomware operators deploy msaRAT, a new backdoor using Chromium-based browser debugging features to proxy C2 traffic and evade network security.

Runtime Rebel Intel
4 min read · Jul 23, 2026
Ransomware Attack Freezes Japanese Food Supply Chain Operations
MEDIUM
Malware

Ransomware Attack Freezes Japanese Food Supply Chain Operations

A ransomware attack on a Japanese food and logistics firm severely disrupted frozen food supply to thousands of clients, including KFC. Analyze the impact.

Runtime Rebel Intel
4 min read · Jul 23, 2026
Fake Bahrain Alert Apps Deploy Android Surveillance Malware
HIGH
Malware

Fake Bahrain Alert Apps Deploy Android Surveillance Malware

Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…

Runtime Rebel Intel
4 min read · Jul 22, 2026
MA
HIGH
Malware

FakeGit Campaign Leverages 7,600 GitHub Repos to Distribute SmartLoader, StealC

Analysis of the FakeGit campaign distributing SmartLoader and StealC malware via over 7,600 deceptive GitHub repositories, impacting millions of downloads.

Runtime Rebel Intel
4 min read · Jul 22, 2026
MA
HIGH
Malware

Anubis Ransomware Targets Fairlife, Threatens Data Leak

The Anubis ransomware gang claims responsibility for a cyberattack on Coca-Cola's Fairlife, threatening a data leak. Learn about their TTPs and mitigation.

Runtime Rebel Intel
4 min read · Jul 21, 2026
ENCFORGE Ransomware Targets AI Systems via Langflow RCE
HIGH
Malware

ENCFORGE Ransomware Targets AI Systems via Langflow RCE

New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.

Runtime Rebel Intel
5 min read · Jul 21, 2026
FakeGit Campaign Exploits GitHub for SmartLoader Malware
HIGH
Malware

FakeGit Campaign Exploits GitHub for SmartLoader Malware

Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.

Runtime Rebel Intel
5 min read · Jul 20, 2026
MA
HIGH
Malware

HollowGraph Malware Uses Microsoft Graph for Stealthy C2

HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.

Runtime Rebel Intel
4 min read · Jul 20, 2026
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HIGH
Malware

HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2

HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.

Runtime Rebel Intel
5 min read · Jul 20, 2026
AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment
HIGH
Malware

AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment

An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.

Runtime Rebel Intel
5 min read · Jul 20, 2026
MA
HIGH
Malware

ACR Stealer Campaign Targets Microsoft Enterprise Credentials

Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.

Runtime Rebel Intel
3 min read · Jul 18, 2026