Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

ClearFake WebDAV Delivers Stealers & RATs to Ukrainian Gov
HIGH
Malware

ClearFake WebDAV Delivers Stealers & RATs to Ukrainian Gov

ClearFake WebDAV infection chain leverages Cloudflare Workers and BNB Smart Chain to deploy Amatera stealer, ZigCryptoStealer, and NetSupport Manager.

Runtime Rebel Intel
4 min read · Sep 8, 2026
PEEP Backdoor Turns Browsers into OS Command Execution Tools
MEDIUM
Malware

PEEP Backdoor Turns Browsers into OS Command Execution Tools

PEEP toolkit leverages Chrome and Edge as post-compromise backdoors, enabling host command execution, data exfiltration, and session hijacking.

Runtime Rebel Intel
4 min read · Sep 7, 2026
REVSTEALER Modules Disable Defenses, Deploy Miner, Steal Data
HIGH
Malware

REVSTEALER Modules Disable Defenses, Deploy Miner, Steal Data

Elastic Security unveils four REVSTEALER-linked modules that disable Windows defenses, deploy crypto miners, and exfiltrate sensitive user data.

Runtime Rebel Intel
5 min read · Sep 6, 2026
MEDIUM
Malware

ClickFix Payloads via Blockchain Affect 5,400+ Websites

Over 5,400 compromised WordPress and PrestaShop sites deliver ClickFix payloads and WebRTC stagers from BNB Smart Chain via EtherHiding.

Runtime Rebel Intel
4 min read · Sep 5, 2026
Silver Fox Malware Campaign Impersonates Software Vendors
MEDIUM
Malware

Silver Fox Malware Campaign Impersonates Software Vendors

An active Silver Fox malware campaign uses fake software download sites to disable Windows Update and weaken Microsoft Defender defenses.

Runtime Rebel Intel
3 min read · Sep 2, 2026
WordlistLoader Evades Detection, Delivers Amatera Infostealer
HIGH
Malware

WordlistLoader Evades Detection, Delivers Amatera Infostealer

WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.

Runtime Rebel Intel
4 min read · Aug 25, 2026

Advertisement

SynkLoader Multitool Malware Employs Screen Hijacking
MEDIUM
Malware

SynkLoader Multitool Malware Employs Screen Hijacking

SynkLoader multitool malware leverages screen hijacking techniques and novel features for password theft, signaling potential ransomware threats.

Runtime Rebel Intel
2 min read · Aug 24, 2026
INFO
Malware

DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files

Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.

Runtime Rebel Intel
4 min read · Aug 24, 2026
Grandoreiro Banking Trojan: New Evasion Tactics in Mexico
MEDIUM
Malware

Grandoreiro Banking Trojan: New Evasion Tactics in Mexico

Grandoreiro banking Trojan resurfaces in Mexico, employing advanced evasion tactics after a law enforcement takedown to target financial users.

Runtime Rebel Intel
4 min read · Aug 24, 2026
MEDIUM
Malware

FTP Banners Abused to Deliver E4del and PINHOLE RATs

Threat actors are using FTP server banners to hide commands, delivering new Windows remote access trojans E4del and PINHOLE via LNK-based infection chains.

Runtime Rebel Intel
4 min read · Aug 24, 2026
MEDIUM
Malware

ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN

ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.

Runtime Rebel Intel
3 min read · Aug 23, 2026
HIGH
Malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active

New and updated banking trojans Manic, Grandoreiro, and ToxicPanda 2.0 are actively targeting financial users globally, stealing credentials and data.

Runtime Rebel Intel
5 min read · Aug 22, 2026
Android Car Head Unit Malware Spreads via Built-In Updaters
MEDIUM
Malware

Android Car Head Unit Malware Spreads via Built-In Updaters

Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.

Runtime Rebel Intel
2 min read · Aug 22, 2026
HIGH
Malware

SynkLoader Malware Steals Credentials in Microsoft Teams Phishing

New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.

Runtime Rebel Intel
4 min read · Aug 22, 2026
Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft
HIGH
Malware

Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft

Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.

Runtime Rebel Intel
3 min read · Aug 17, 2026
HIGH
Malware

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control

AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.

Runtime Rebel Intel
4 min read · Aug 16, 2026
MEDIUM
Malware

Evooo1Bot Linux Botnet Turns Routers Into SOCKS5 Relays

A new Mirai-based modular Linux botnet called Evooo1Bot targets internet routers, turning them into SOCKS5 traffic relay nodes.

Runtime Rebel Intel
3 min read · Aug 15, 2026
New JWR Phishing Framework Bypasses MFA with Live Monitoring
HIGH
Malware

New JWR Phishing Framework Bypasses MFA with Live Monitoring

JWR, a new real-time phishing framework, uses WebSockets to bypass MFA and steal sensitive data via SMS lures, posing a critical threat.

Runtime Rebel Intel
3 min read · Aug 14, 2026
JWR Phishing Framework: Real-time Data Theft via PhaaS
HIGH
Malware

JWR Phishing Framework: Real-time Data Theft via PhaaS

The JWR phishing framework, a variant of The Outsider PhaaS, harvests payment data, PII, and 2FA codes in real-time via operator-controlled sessions.

Runtime Rebel Intel
4 min read · Aug 13, 2026
HIGH
Malware

Android Malware WindRelay & SpyNote: NFC Relay for Loan Fraud

A sophisticated Android malware combination, WindRelay and SpyNote, facilitates real-time NFC credit card fraud and unauthorized loans.

Runtime Rebel Intel
4 min read · Aug 13, 2026
Malicious Chrome VPN Extensions Route Traffic via SOCKS5 Proxies
HIGH
Malware

Malicious Chrome VPN Extensions Route Traffic via SOCKS5 Proxies

Over 730 free Chrome VPN extensions are redirecting user browser traffic through SOCKS5 proxies, enabling man-in-the-middle attacks and data interception.

Runtime Rebel Intel
4 min read · Aug 12, 2026
HIGH
Malware

Deadlock Ransomware Uses Blockchain for C2 Resilience

Deadlock ransomware uses Polygon blockchain smart contracts and Session to resist infrastructure takedown and evade law enforcement.

Runtime Rebel Intel
3 min read · Aug 12, 2026
Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience
HIGH
Malware

Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience

Kimwolf v7, an Android/IoT botnet, enhances DDoS capabilities with HTTP/2 fingerprinting and robust, multi-layered C2 infrastructure.

Runtime Rebel Intel
4 min read · Aug 11, 2026
Aeternum Botnet Leverages Polygon Blockchain for Resilient C2
MEDIUM
Malware

Aeternum Botnet Leverages Polygon Blockchain for Resilient C2

Aeternum botnet uses Polygon blockchain smart contracts for C2, making it resilient to takedowns. Security professionals must understand its decentralized operations.

Runtime Rebel Intel
3 min read · Aug 11, 2026