Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

Solidity Pro VS Code Extensions Steal Crypto Wallets & Credentials
HIGH
Malware

Solidity Pro VS Code Extensions Steal Crypto Wallets & Credentials

Malicious 'Solidity Pro' VS Code extensions steal crypto wallets, API keys, and credentials, using delayed activation to evade detection. Immediate removal is advised.

Runtime Rebel Intel
4 min read · Aug 10, 2026
ClickFix Attacks Deliver macOS Stealer Targeting Crypto
MEDIUM
Malware

ClickFix Attacks Deliver macOS Stealer Targeting Crypto

ClickFix social engineering campaigns target macOS users with Go-based infostealers designed to drain cryptocurrency wallets and credentials.

Runtime Rebel Intel
3 min read · Aug 10, 2026
Vidar Stealer & XMRig Campaign Leverages Malvertising, AMSI Bypass
HIGH
Malware

Vidar Stealer & XMRig Campaign Leverages Malvertising, AMSI Bypass

Financially motivated campaign delivers Vidar stealer and XMRig miner via malvertising for cracked software, targeting consumers and SMBs globally.

Runtime Rebel Intel
5 min read · Aug 9, 2026
TuxBot v3: LLM-Assisted IoT Botnet Framework Analysis
MEDIUM
Malware

TuxBot v3: LLM-Assisted IoT Botnet Framework Analysis

Analysis of TuxBot v3 Evolution, a modular IoT botnet framework developed with LLM assistance, leveraging Telnet brute-force and C2 for DDoS.

Runtime Rebel Intel
4 min read · Aug 8, 2026
XCSSET v40 Malware Targets macOS Developers via Xcode
MEDIUM
Malware

XCSSET v40 Malware Targets macOS Developers via Xcode

Discover how XCSSET v40 targets macOS developers using fileless persistence, memory execution, and Xcode project supply chain attacks.

Runtime Rebel Intel
3 min read · Aug 8, 2026
msaRAT: Chaos Ransomware's Covert Browser-Based C2
HIGH
Malware

msaRAT: Chaos Ransomware's Covert Browser-Based C2

Cisco Talos uncovers msaRAT, a new Rust-based RAT used by Chaos ransomware for covert C2 via Chrome DevTools Protocol, evading detection.

Runtime Rebel Intel
4 min read · Aug 8, 2026

Advertisement

HIGH
Malware

ClickFix Attack Deploys macOS Infostealer for Crypto Theft

The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.

Runtime Rebel Intel
5 min read · Aug 7, 2026
Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth
MEDIUM
Malware

Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth

Cheap Android TV boxes are pre-installed with Fuyao malware, impersonating phones for ad fraud and turning devices into residential proxy nodes.

Runtime Rebel Intel
4 min read · Jul 31, 2026
HIGH
Malware

SSH Botnet Reconnaissance Before Linux Cryptominer Deployment

An SSH botnet performs extensive hardware and system reconnaissance on Linux targets before deploying an optimized cryptocurrency miner. Weak credentials exploited.

Runtime Rebel Intel
4 min read · Jul 30, 2026
Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service
HIGH
Malware

Flying Eagle Mobile RAT Builder: China's Infostealer-as-a-Service

Analysis of the 'Flying Eagle' mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…

Runtime Rebel Intel
4 min read · Jul 30, 2026
Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence
MEDIUM
Malware

Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence

The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.

Runtime Rebel Intel
4 min read · Jul 28, 2026
HIGH
Malware

Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay

Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.

Runtime Rebel Intel
4 min read · Jul 27, 2026
Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience
HIGH
Malware

Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience

Dysphoria IoT botnet evolves with blockchain-based C2 and victim relays after JackSkid disruption, posing new challenges for defenders.

Runtime Rebel Intel
4 min read · Jul 27, 2026
SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly
HIGH
Malware

SourTrade Malvertising: Evasion via Browser-Side Bun Runtime Assembly

The SourTrade malvertising operation bypasses security controls by using the victim's browser to assemble malicious Bun runtime executables in real-time.

Runtime Rebel Intel
4 min read · Jul 25, 2026
MEDIUM
Malware

JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses

Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.

Runtime Rebel Intel
4 min read · Jul 25, 2026
HIGH
Malware

Dolphin X Malware: AI-Driven Target Prioritization & Defense

Analysis of Dolphin X, a new RAT utilizing AI to profile and rank victims, enabling threat actors to prioritize high-value targets for data exfiltration and further…

Runtime Rebel Intel
5 min read · Jul 24, 2026
HIGH
Malware

Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware

A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.

Runtime Rebel Intel
4 min read · Jul 23, 2026
HIGH
Malware

Notepad++ Plugin Abuse: LunchPoke Malware Establishes Persistence

CERT-UA uncovers attacks where threat actors bundle malicious LunchPoke utility as a Notepad++ plugin for stealthy malware installation and persistence.

Runtime Rebel Intel
5 min read · Jul 23, 2026
Brazilian Banking Trojan Expansion into Portugal Targets Businesses
MEDIUM
Malware

Brazilian Banking Trojan Expansion into Portugal Targets Businesses

Portuguese businesses face increased risk from Brazilian banking trojans leveraging shared language for phishing and credential theft.

Runtime Rebel Intel
4 min read · Jul 23, 2026
HIGH
Malware

msaRAT Malware Hijacks Browser Debugging for Stealthy C2 Traffic

Chaos ransomware operators deploy msaRAT, a new backdoor using Chromium-based browser debugging features to proxy C2 traffic and evade network security.

Runtime Rebel Intel
4 min read · Jul 23, 2026
Ransomware Attack Freezes Japanese Food Supply Chain Operations
MEDIUM
Malware

Ransomware Attack Freezes Japanese Food Supply Chain Operations

A ransomware attack on a Japanese food and logistics firm severely disrupted frozen food supply to thousands of clients, including KFC. Analyze the impact.

Runtime Rebel Intel
4 min read · Jul 23, 2026
Fake Bahrain Alert Apps Deploy Android Surveillance Malware
HIGH
Malware

Fake Bahrain Alert Apps Deploy Android Surveillance Malware

Analyzing fake Bahrain alert apps distributing four-stage Android surveillance malware via phony app stores, exploiting geopolitical tensions for extensive data…

Runtime Rebel Intel
4 min read · Jul 22, 2026
HIGH
Malware

FakeGit Campaign Leverages 7,600 GitHub Repos to Distribute SmartLoader, StealC

Analysis of the FakeGit campaign distributing SmartLoader and StealC malware via over 7,600 deceptive GitHub repositories, impacting millions of downloads.

Runtime Rebel Intel
4 min read · Jul 22, 2026
HIGH
Malware

Anubis Ransomware Targets Fairlife, Threatens Data Leak

The Anubis ransomware gang claims responsibility for a cyberattack on Coca-Cola's Fairlife, threatening a data leak. Learn about their TTPs and mitigation.

Runtime Rebel Intel
4 min read · Jul 21, 2026