Advertisement
ENCFORGE Ransomware Targets AI Systems via Langflow RCE
New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.
FakeGit Campaign Exploits GitHub for SmartLoader Malware
Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.
HollowGraph Malware Uses Microsoft Graph for Stealthy C2
HollowGraph malware leverages Microsoft Graph API calendar features for covert command-and-control and data exfiltration from Microsoft 365 environments.
HollowGraph Malware Leverages Microsoft 365 Calendar for Stealthy C2
HollowGraph, a new espionage malware, hides C2 commands and exfiltrates data via legitimate Microsoft 365 calendar events, mimicking normal Graph API traffic.
AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment
An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.
ACR Stealer Campaign Targets Microsoft Enterprise Credentials
Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.
Advertisement
Fairlife Ransomware Attack Halts US Dairy Production
Coca-Cola's Fairlife dairy subsidiary suffered a ransomware attack, halting US production. Understand the operational impact and defense strategies.
ClickLock macOS Malware: Password Theft via Forced Login Prompt
ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password.
OkoBot Framework: Multi-Payload Data & Crypto Theft Attacks
The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.
ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops
ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.
TELEPUZ Malware: Analyzing Modular Payloads in ClickFix Campaigns
TELEPUZ is a new modular malware spreading via ClickFix lures to steal sensitive data and execute remote commands on compromised Windows systems.
OkoBot Framework Injects Phishing Modules into Ledger and Trezor Apps
The OkoBot malware framework targets Windows users to steal hardware wallet seed phrases by injecting malicious pages directly into legitimate desktop apps.
Malicious GitHub Repositories: Infostealer Distribution Threat
Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware.
LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows
Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.
CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization
CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.
GigaWiper: Modular Implant Combines Backdoor & Wiper Functions
Analysis of GigaWiper, a modular implant allowing threat actors to combine backdoor and wiper functionality for customizable destructive attacks and maximum impact.
Analyzing Remcos RAT Delivery via Malicious LNK Files
Technical analysis of how threat actors use deceptive LNK files and obfuscated PowerShell to deliver Remcos RAT, including detection and mitigation strategies.
RedHook Android Malware: Abusing Wireless ADB for Local Shell Access
RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.
MODBEACON RAT: Silver Fox Uses gRPC for Stealthy C2
A new Rust-based MODBEACON RAT, linked to the Silver Fox cybercrime group, employs gRPC streaming for encrypted C2, propagated via SEO poisoning.
GigaWiper Windows Backdoor Analysis: Disk Wiping & Fake Ransomware
Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities.
Vidar Infostealer Malvertising Campaign: SMBs Targeted by Fake Software
A financially motivated malvertising campaign is actively targeting Small to Medium Businesses, delivering Vidar Infostealer and a cryptominer through fake software…
SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks
Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.
RedWing MaaS: Android Bank Fraud via Telegram Rental Service Analysis
RedWing MaaS is an Android bank fraud malware-as-a-service rented on Telegram, enabling low-skill attackers to steal banking logins and OTPs.
BusySnake Infostealer Targets Critical Infrastructure: Armored Likho's TTPs
BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.