Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

MEDIUM
Malware

Phishing Campaign Leverages Donut Loader via Spoofed FedEx Alerts

Analysis of a phishing campaign using fake FedEx delivery notifications to deliver the Donut loader framework for in-memory shellcode execution.

Runtime Rebel Intel
4 min read · Feb 27, 2026
HIGH
Malware

CISA Warns of RESURGE Malware Persistence on Ivanti Devices

CISA details RESURGE, a sophisticated implant exploiting CVE-2025-0282 in Ivanti Connect Secure, capable of remaining dormant to bypass detection and recovery.

Runtime Rebel Intel
4 min read · Feb 27, 2026
HIGH
Malware

Aeternum Loader Employs Polygon Blockchain for Resilient C2

Analysis of the Aeternum botnet loader, which utilizes Polygon smart contracts to host decentralized command-and-control infrastructure for resilience.

Runtime Rebel Intel
4 min read · Feb 27, 2026
Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell
HIGH
Malware

Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell

Security researchers identify a malware campaign using trojanized gaming tools to deliver a Java-based RAT using PowerShell and portable Java runtimes.

Runtime Rebel Intel
4 min read · Feb 27, 2026
Aeternum C2 Leverages Polygon Blockchain for Command-and-Control
HIGH
Malware

Aeternum C2 Leverages Polygon Blockchain for Command-and-Control

Aeternum C2 loader uses the Polygon blockchain to store encrypted instructions, creating a decentralized infrastructure resilient to traditional takedowns.

Runtime Rebel Intel
3 min read · Feb 26, 2026
MEDIUM
Malware

Arkanix Stealer: Rapid Disappearance of C++ & Python Malware

Arkanix Stealer, a C++ and Python-based info-stealer, emerged briefly, exfiltrating system data, browser credentials, and files before vanishing. Analysis of its TTPs.

Runtime Rebel Intel
4 min read · Feb 25, 2026

Advertisement

BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement
MEDIUM
Malware

BYOVD-Driven XMRig Campaign Employs Time-Based Logic Bombs and Lateral Movement

An analysis of a sophisticated cryptojacking operation utilizing Bring Your Own Vulnerable Driver (BYOVD) techniques and wormable components to maximize Monero mining…

Runtime Rebel Intel
2 min read · Feb 23, 2026
HIGH
Malware

Predator Spyware: Hooking iOS SpringBoard to Suppress Privacy Indicators

An analysis of Intellexa's Predator spyware capabilities regarding the manipulation of iOS SpringBoard to suppress privacy indicators during unauthorized audio and…

Runtime Rebel Intel
2 min read · Feb 23, 2026
MEDIUM
Malware

Arkanix Stealer: Analysis of AI-Assisted Infostealer Development Patterns

A technical evaluation of the Arkanix Stealer operation, highlighting its AI-driven code characteristics and credential-harvesting capabilities.

Runtime Rebel Intel
2 min read · Feb 23, 2026