Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
HIGH
Malware

Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558

Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.

Runtime Rebel Intel
4 min read · Jun 30, 2026
Microsoft Pulls 119 Malicious StegoAd Edge Extensions
MEDIUM
Malware

Microsoft Pulls 119 Malicious StegoAd Edge Extensions

Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.

Runtime Rebel Intel
3 min read · Jun 29, 2026
SharkLoader Malware Delivers Cobalt Strike in StrikeShark Attacks
HIGH
Malware

SharkLoader Malware Delivers Cobalt Strike in StrikeShark Attacks

Analysis of SharkLoader malware, a new loader delivering Cobalt Strike Beacon to diplomatic and government entities in StrikeShark cyberattacks.

Runtime Rebel Intel
5 min read · Jun 26, 2026
"Adblock for YouTube" Extension: Dormant Script Injection Threat
HIGH
Malware

"Adblock for YouTube" Extension: Dormant Script Injection Threat

A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.

Runtime Rebel Intel
4 min read · Jun 25, 2026
Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection
HIGH
Malware

Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection

Gaslight is a newly discovered Rust-based macOS implant that uses prompt injection to deceive AI-driven analysis tools and bypass automated detection.

Runtime Rebel Intel
3 min read · Jun 25, 2026
MA
MEDIUM
Malware

Malware Evades AI Analysis with 'Forbidden Text' Tactics

Threat actors embed 'forbidden' text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers. Learn how to defend against this novel evasion…

Runtime Rebel Intel
5 min read · Jun 25, 2026
Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen
HIGH
Malware

Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen

Law enforcement and private sector dismantled infrastructure for Amadey and StealC malware, leading to 27M stolen credentials recovery. Learn impact & defense.

Runtime Rebel Intel
5 min read · Jun 24, 2026
MA
HIGH
Malware

Amadey & StealC Malware C2 Infrastructure Disrupted

Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.

Runtime Rebel Intel
4 min read · Jun 24, 2026
MA
HIGH
Malware

Amadey & StealC Malware Operations Disrupted by Operation Endgame

Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.

Runtime Rebel Intel
5 min read · Jun 24, 2026
FortiBleed: FortiGate Firewalls Used as Credential Stealers
HIGH
Malware

FortiBleed: FortiGate Firewalls Used as Credential Stealers

Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.

Runtime Rebel Intel
4 min read · Jun 23, 2026
MA
HIGH
Malware

Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT

Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.

Runtime Rebel Intel
3 min read · Jun 23, 2026
Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto
MEDIUM
Malware

Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto

Analysis of a cross-platform clipboard hijacker spread via elaborate fake reputation campaigns on GitHub, YouTube, and VirusTotal to steal cryptocurrency.

Runtime Rebel Intel
5 min read · Jun 22, 2026
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
HIGH
Malware

OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware

Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.

Runtime Rebel Intel
3 min read · Jun 22, 2026
AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network
MEDIUM
Malware

AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network

Security researchers have identified AryStinger, a new malware family using 4,300 legacy routers as a reconnaissance proxy network to bypass security.

Runtime Rebel Intel
4 min read · Jun 22, 2026
MA
HIGH
Malware

AryStinger Botnet: Thousands of D-Link Routers Compromised as Proxies

The AryStinger botnet has compromised over 4,000 D-Link routers, converting them into malicious proxies using automated exploits for end-of-life hardware.

Runtime Rebel Intel
3 min read · Jun 21, 2026
MA
MEDIUM
Malware

Prinz Eugen Ransomware Prioritizes Recent Files to Maximize Impact

Prinz Eugen ransomware targets files modified within 30 days to disrupt active operations, using a Go-based encrypter and unconventional ransom demands.

Runtime Rebel Intel
4 min read · Jun 20, 2026
MA
HIGH
Malware

CryptoBandits Malware: Tor-Abusing Backdoor & Data Theft

CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.

Runtime Rebel Intel
5 min read · Jun 19, 2026
Operation Endgame Disrupts SocGholish: WordPress Site Remediation
HIGH
Malware

Operation Endgame Disrupts SocGholish: WordPress Site Remediation

Operation Endgame targets SocGholish infrastructure, cleaning 14,971 WordPress sites. Understand the impact and crucial remediation steps for web administrators.

Runtime Rebel Intel
5 min read · Jun 19, 2026
MA
MEDIUM
Malware

Bypass AI Malware Scanners via Policy-Triggering Prompt Injection

Malware authors are embedding 'forbidden' text into code to trigger safety refusals in AI-mediated security scanners, effectively bypassing automated analysis.

Runtime Rebel Intel
4 min read · Jun 19, 2026
MA
MEDIUM
Malware

Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies

Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.

Runtime Rebel Intel
4 min read · Jun 19, 2026
MA
HIGH
Malware

USB Worm Exploits LNK Files for Crypto-Stealing Malware

New USB worm propagates crypto-stealing malware through Windows shortcut files, leveraging removable drives and the Tor network for C2 to target cryptocurrency wallets.

Runtime Rebel Intel
5 min read · Jun 18, 2026
Crypto Clipper Campaign Abuses AI Narrators and Fake Reviews
HIGH
Malware

Crypto Clipper Campaign Abuses AI Narrators and Fake Reviews

An unknown threat actor leverages paid posts, fake reviews, AI narrators, and phishing sites to distribute crypto clipper malware. Learn defense tactics.

Runtime Rebel Intel
4 min read · Jun 17, 2026
Phantom Stealer: Fileless Credential Theft & Evasion
HIGH
Malware

Phantom Stealer: Fileless Credential Theft & Evasion

Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.

Runtime Rebel Intel
5 min read · Jun 17, 2026
MA
HIGH
Malware

Rokarolla Android Malware Targets 217 Financial Apps

New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.

Runtime Rebel Intel
4 min read · Jun 16, 2026