Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

MA
HIGH
Malware

Fairlife Ransomware Attack Halts US Dairy Production

Coca-Cola's Fairlife dairy subsidiary suffered a ransomware attack, halting US production. Understand the operational impact and defense strategies.

Runtime Rebel Intel
4 min read · Jul 17, 2026
MA
HIGH
Malware

ClickLock macOS Malware: Password Theft via Forced Login Prompt

ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password. Learn how to identify and mitigate this…

Runtime Rebel Intel
5 min read · Jul 17, 2026
MA
HIGH
Malware

OkoBot Framework: Multi-Payload Data & Crypto Theft Attacks

The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data. Understand its impact and…

Runtime Rebel Intel
4 min read · Jul 16, 2026
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
HIGH
Malware

ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops

ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.

Runtime Rebel Intel
3 min read · Jul 16, 2026
TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns
HIGH
Malware

TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns

TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.

Runtime Rebel Intel
4 min read · Jul 16, 2026
OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps
HIGH
Malware

OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps

The OkoBot malware framework targets Windows users to steal hardware wallet seed phrases by injecting malicious pages directly into legitimate desktop apps.

Runtime Rebel Intel
4 min read · Jul 15, 2026
MA
HIGH
Malware

Malicious GitHub Repositories: Infostealer Distribution Threat

Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware. Learn to detect and mitigate this…

Runtime Rebel Intel
4 min read · Jul 14, 2026
LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows
HIGH
Malware

LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows

Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.

Runtime Rebel Intel
4 min read · Jul 14, 2026
CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization
HIGH
Malware

CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization

CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.

Runtime Rebel Intel
4 min read · Jul 13, 2026
GigaWiper: Modular Implant Combines Backdoor & Wiper Functions
HIGH
Malware

GigaWiper: Modular Implant Combines Backdoor & Wiper Functions

Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.

Runtime Rebel Intel
5 min read · Jul 13, 2026
MA
HIGH
Malware

Analyzing Remcos RAT Delivery via Malicious LNK Files

Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.

Runtime Rebel Intel
4 min read · Jul 13, 2026
MA
HIGH
Malware

RedHook Android Malware: Abusing Wireless ADB for Local Shell Access

RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.

Runtime Rebel Intel
4 min read · Jul 12, 2026
MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2
HIGH
Malware

MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2

A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.

Runtime Rebel Intel
5 min read · Jul 10, 2026
GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware
HIGH
Malware

GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware

Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities. Understand its…

Runtime Rebel Intel
5 min read · Jul 9, 2026
Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software
HIGH
Malware

Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software

A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…

Runtime Rebel Intel
5 min read · Jul 8, 2026
SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks
HIGH
Malware

SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks

Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.

Runtime Rebel Intel
4 min read · Jul 8, 2026
RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis
HIGH
Malware

RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis

RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs. Learn to detect and…

Runtime Rebel Intel
4 min read · Jul 7, 2026
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
HIGH
Malware

BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs

BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.

Runtime Rebel Intel
5 min read · Jul 7, 2026
MA
HIGH
Malware

Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell

Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.

Runtime Rebel Intel
5 min read · Jul 6, 2026
MA
HIGH
Malware

JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle

Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.

Runtime Rebel Intel
3 min read · Jul 4, 2026
PamStealer: New macOS Malware Targets PAM for Password Exfiltration
HIGH
Malware

PamStealer: New macOS Malware Targets PAM for Password Exfiltration

Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.

Runtime Rebel Intel
4 min read · Jul 3, 2026
ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
HIGH
Malware

ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse

Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.

Runtime Rebel Intel
5 min read · Jul 2, 2026
Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users
HIGH
Malware

Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users

Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.

Runtime Rebel Intel
4 min read · Jul 1, 2026
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
MEDIUM
Malware

Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets

Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.

Runtime Rebel Intel
5 min read · Jun 30, 2026