Advertisement
Perseus Android Malware: Technical Analysis of Note-Stealing Tactics
Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.
CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now
Interlock ransomware actors are exploiting CVE-2026-20131, a critical 10.0 CVSS zero-day in Cisco FMC, to gain unauthenticated root access and deploy malware.
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.
GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions
Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.
Fake Chrome Update Campaigns Deploying NetSupport RAT
Technical analysis of phishing campaigns using JavaScript-injected websites to distribute NetSupport RAT via fake browser update overlays.
Advertisement
SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT
Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT.
FBI Seeks Victims of Malicious Steam Games Stealing Credentials
The FBI is investigating eight malicious games on Steam that stole user credentials from tens of thousands of players.
AI-Generated Slopoly Malware Linked to Interlock Ransomware Attacks
Analysis of the AI-generated Slopoly malware and its role in Interlock ransomware operations, including technical details and detection strategies.
Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access
The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.
VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks
A new Rust-based malware called VENON is targeting 33 Brazilian banks with credential-stealing overlays, signaling a shift in Latin American cybercrime TTPs.
BeatBanker Android Malware: Starlink Impersonation & Device Hijack
New BeatBanker Android malware impersonates the Starlink app on fake app stores to hijack devices, targeting unsuspecting users. Learn detection & mitigation.
BlackSanta Malware Targets HR Workflows to Disable EDR Systems
Russian-speaking threat actors deploy BlackSanta malware via hijacked HR workflows to terminate EDR agents and facilitate undetected data exfiltration.
KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network
The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.
KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet
KadNap malware has compromised over 14,000 edge devices, primarily Asus routers, to create a massive proxy botnet for anonymizing malicious traffic.
Quasar RAT Delivery via Malicious PDF and LNK Files
Technical analysis of a multi-stage infection chain using PDF lures and LNK files to deploy Quasar RAT, including detection and mitigation strategies.
InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers
The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.
VOID#GEIST Malware: Multi-Stage Delivery of AsyncRAT and XWorm
Securonix identifies VOID#GEIST, a stealthy multi-stage malware campaign using obfuscated batch scripts to deliver XWorm, AsyncRAT, and Xeno RAT payloads.
Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers
Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.
Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto
The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.
Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits
Google's GTIG identified Coruna (CryptoWaters), a powerful iOS exploit kit leveraging 23 exploits across 5 chains to target iOS 13.0-17.2.1. Update immediately.
XWorm RAT Delivery: Analyzing Multi-Stage Infection Chains
New XWorm malware waves utilize multi-technology delivery involving LNK files and PowerShell. Learn how to detect and mitigate XWorm RAT infections.
Analyzing Embedded ZIP Payloads in RTF Documents for Malware Analysis
Learn how to detect ZIP files in RTF documents and extract hex-encoded binary payloads using specialized forensic tools to identify hidden malware threats.
QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware
Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.