Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

HIGH
Malware

Perseus Android Malware: Technical Analysis of Note-Stealing Tactics

Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.

Runtime Rebel Intel
4 min read · Mar 19, 2026
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
HIGH
Malware

SnappyClient C2 Implant Targets Crypto Wallets for Data Theft

A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.

Runtime Rebel Intel
5 min read · Mar 19, 2026
CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now
HIGH
Malware

CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now

Interlock ransomware actors are exploiting CVE-2026-20131, a critical 10.0 CVSS zero-day in Cisco FMC, to gain unauthenticated root access and deploy malware.

Runtime Rebel Intel
3 min read · Mar 18, 2026
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
MEDIUM
Malware

LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis

LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.

Runtime Rebel Intel
4 min read · Mar 17, 2026
GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions
MEDIUM
Malware

GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions

Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.

Runtime Rebel Intel
4 min read · Mar 17, 2026
HIGH
Malware

Fake Chrome Update Campaigns Deploying NetSupport RAT

Technical analysis of phishing campaigns using JavaScript-injected websites to distribute NetSupport RAT via fake browser update overlays.

Runtime Rebel Intel
4 min read · Mar 16, 2026

Advertisement

HIGH
Malware

SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT

Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT.

Runtime Rebel Intel
4 min read · Mar 14, 2026
HIGH
Malware

FBI Seeks Victims of Malicious Steam Games Stealing Credentials

The FBI is investigating eight malicious games on Steam that stole user credentials from tens of thousands of players.

Runtime Rebel Intel
5 min read · Mar 14, 2026
HIGH
Malware

AI-Generated Slopoly Malware Linked to Interlock Ransomware Attacks

Analysis of the AI-generated Slopoly malware and its role in Interlock ransomware operations, including technical details and detection strategies.

Runtime Rebel Intel
4 min read · Mar 12, 2026
Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access
HIGH
Malware

Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access

The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.

Runtime Rebel Intel
4 min read · Mar 12, 2026
VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks
HIGH
Malware

VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks

A new Rust-based malware called VENON is targeting 33 Brazilian banks with credential-stealing overlays, signaling a shift in Latin American cybercrime TTPs.

Runtime Rebel Intel
4 min read · Mar 12, 2026
HIGH
Malware

BeatBanker Android Malware: Starlink Impersonation & Device Hijack

New BeatBanker Android malware impersonates the Starlink app on fake app stores to hijack devices, targeting unsuspecting users. Learn detection & mitigation.

Runtime Rebel Intel
4 min read · Mar 11, 2026
BlackSanta Malware Targets HR Workflows to Disable EDR Systems
HIGH
Malware

BlackSanta Malware Targets HR Workflows to Disable EDR Systems

Russian-speaking threat actors deploy BlackSanta malware via hijacked HR workflows to terminate EDR agents and facilitate undetected data exfiltration.

Runtime Rebel Intel
3 min read · Mar 10, 2026
HIGH
Malware

KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network

The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.

Runtime Rebel Intel
4 min read · Mar 10, 2026
KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet
HIGH
Malware

KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet

KadNap malware has compromised over 14,000 edge devices, primarily Asus routers, to create a massive proxy botnet for anonymizing malicious traffic.

Runtime Rebel Intel
4 min read · Mar 10, 2026
HIGH
Malware

Quasar RAT Delivery via Malicious PDF and LNK Files

Technical analysis of a multi-stage infection chain using PDF lures and LNK files to deploy Quasar RAT, including detection and mitigation strategies.

Runtime Rebel Intel
3 min read · Mar 10, 2026
HIGH
Malware

InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers

The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.

Runtime Rebel Intel
4 min read · Mar 9, 2026
VOID#GEIST Malware: Multi-Stage Delivery of AsyncRAT and XWorm
MEDIUM
Malware

VOID#GEIST Malware: Multi-Stage Delivery of AsyncRAT and XWorm

Securonix identifies VOID#GEIST, a stealthy multi-stage malware campaign using obfuscated batch scripts to deliver XWorm, AsyncRAT, and Xeno RAT payloads.

Runtime Rebel Intel
3 min read · Mar 6, 2026
HIGH
Malware

Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers

Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.

Runtime Rebel Intel
4 min read · Mar 6, 2026
HIGH
Malware

Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto

The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.

Runtime Rebel Intel
5 min read · Mar 4, 2026
Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits
HIGH
Malware

Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits

Google's GTIG identified Coruna (CryptoWaters), a powerful iOS exploit kit leveraging 23 exploits across 5 chains to target iOS 13.0-17.2.1. Update immediately.

Runtime Rebel Intel
4 min read · Mar 4, 2026
MEDIUM
Malware

XWorm RAT Delivery: Analyzing Multi-Stage Infection Chains

New XWorm malware waves utilize multi-technology delivery involving LNK files and PowerShell. Learn how to detect and mitigate XWorm RAT infections.

Runtime Rebel Intel
3 min read · Mar 4, 2026
MEDIUM
Malware

Analyzing Embedded ZIP Payloads in RTF Documents for Malware Analysis

Learn how to detect ZIP files in RTF documents and extract hex-encoded binary payloads using specialized forensic tools to identify hidden malware threats.

Runtime Rebel Intel
4 min read · Mar 2, 2026
HIGH
Malware

QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware

Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.

Runtime Rebel Intel
3 min read · Feb 28, 2026