Advertisement
Fairlife Ransomware Attack Halts US Dairy Production
Coca-Cola's Fairlife dairy subsidiary suffered a ransomware attack, halting US production. Understand the operational impact and defense strategies.
ClickLock macOS Malware: Password Theft via Forced Login Prompt
ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password. Learn how to identify and mitigate this…
OkoBot Framework: Multi-Payload Data & Crypto Theft Attacks
The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data. Understand its impact and…
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.
TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns
TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.
OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps
The OkoBot malware framework targets Windows users to steal hardware wallet seed phrases by injecting malicious pages directly into legitimate desktop apps.
Malicious GitHub Repositories: Infostealer Distribution Threat
Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware. Learn to detect and mitigate this…
LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows
Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.
CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization
CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.
GigaWiper: Modular Implant Combines Backdoor & Wiper Functions
Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.
Analyzing Remcos RAT Delivery via Malicious LNK Files
Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.
RedHook Android Malware: Abusing Wireless ADB for Local Shell Access
RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.
MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2
A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.
GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware
Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities. Understand its…
Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software
A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…
SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks
Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.
RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis
RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs. Learn to detect and…
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.
Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell
Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.
JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle
Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.
PamStealer: New macOS Malware Targets PAM for Password Exfiltration
Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.
ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.
Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users
Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.