Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

ENCFORGE Ransomware Targets AI Systems via Langflow RCE
HIGH
Malware

ENCFORGE Ransomware Targets AI Systems via Langflow RCE

New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.

Runtime Rebel Intel
5 min read · Jul 21, 2026
FakeGit Campaign Exploits GitHub for SmartLoader Malware
HIGH
Malware

FakeGit Campaign Exploits GitHub for SmartLoader Malware

Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.

Runtime Rebel Intel
5 min read · Jul 20, 2026
HIGH
Malware

HollowGraph Malware Uses Microsoft Graph for Stealthy C2

HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.

Runtime Rebel Intel
4 min read · Jul 20, 2026
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HIGH
Malware

HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2

HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.

Runtime Rebel Intel
5 min read · Jul 20, 2026
AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment
HIGH
Malware

AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment

An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.

Runtime Rebel Intel
5 min read · Jul 20, 2026
HIGH
Malware

ACR Stealer Campaign Targets Microsoft Enterprise Credentials

Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.

Runtime Rebel Intel
3 min read · Jul 18, 2026

Advertisement

HIGH
Malware

Fairlife Ransomware Attack Halts US Dairy Production

Coca-Cola's Fairlife dairy subsidiary suffered a ransomware attack, halting US production. Understand the operational impact and defense strategies.

Runtime Rebel Intel
4 min read · Jul 17, 2026
HIGH
Malware

ClickLock macOS Malware: Password Theft via Forced Login Prompt

ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password.

Runtime Rebel Intel
5 min read · Jul 17, 2026
HIGH
Malware

OkoBot Framework: Multi-Payload Data & Crypto Theft Attacks

The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.

Runtime Rebel Intel
4 min read · Jul 16, 2026
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
HIGH
Malware

ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops

ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.

Runtime Rebel Intel
3 min read · Jul 16, 2026
TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns
HIGH
Malware

TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns

TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.

Runtime Rebel Intel
4 min read · Jul 16, 2026
OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps
HIGH
Malware

OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps

The OkoBot malware framework targets Windows users to steal hardware wallet seed phrases by injecting malicious pages directly into legitimate desktop apps.

Runtime Rebel Intel
4 min read · Jul 15, 2026
HIGH
Malware

Malicious GitHub Repositories: Infostealer Distribution Threat

Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware.

Runtime Rebel Intel
4 min read · Jul 14, 2026
LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows
HIGH
Malware

LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows

Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.

Runtime Rebel Intel
4 min read · Jul 14, 2026
CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization
HIGH
Malware

CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization

CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.

Runtime Rebel Intel
4 min read · Jul 13, 2026
GigaWiper: Modular Implant Combines Backdoor & Wiper Functions
HIGH
Malware

GigaWiper: Modular Implant Combines Backdoor & Wiper Functions

Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.

Runtime Rebel Intel
5 min read · Jul 13, 2026
HIGH
Malware

Analyzing Remcos RAT Delivery via Malicious LNK Files

Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.

Runtime Rebel Intel
4 min read · Jul 13, 2026
HIGH
Malware

RedHook Android Malware: Abusing Wireless ADB for Local Shell Access

RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.

Runtime Rebel Intel
4 min read · Jul 12, 2026
MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2
HIGH
Malware

MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2

A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.

Runtime Rebel Intel
5 min read · Jul 10, 2026
GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware
HIGH
Malware

GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware

Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities.

Runtime Rebel Intel
5 min read · Jul 9, 2026
Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software
HIGH
Malware

Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software

A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…

Runtime Rebel Intel
5 min read · Jul 8, 2026
SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks
HIGH
Malware

SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks

Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.

Runtime Rebel Intel
4 min read · Jul 8, 2026
RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis
HIGH
Malware

RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis

RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs.

Runtime Rebel Intel
4 min read · Jul 7, 2026
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
HIGH
Malware

BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs

BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.

Runtime Rebel Intel
5 min read · Jul 7, 2026