Advertisement
Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell
Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.
JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle
Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.
PamStealer: New macOS Malware Targets PAM for Password Exfiltration
Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.
ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.
Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users
Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.
Advertisement
Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.
Microsoft Pulls 119 Malicious StegoAd Edge Extensions
Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.
SharkLoader Malware Delivers Cobalt Strike in StrikeShark Attacks
Analysis of SharkLoader malware, a new loader delivering Cobalt Strike Beacon to diplomatic and government entities in StrikeShark cyberattacks.
"Adblock for YouTube" Extension: Dormant Script Injection Threat
A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.
Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection
Gaslight is a newly discovered Rust-based macOS implant that uses prompt injection to deceive AI-driven analysis tools and bypass automated detection.
Malware Evades AI Analysis with 'Forbidden Text' Tactics
Threat actors embed 'forbidden' text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers.
Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen
Law enforcement and private sector dismantled infrastructure for Amadey and StealC malware, leading to 27M stolen credentials recovery. Learn impact & defense.
Amadey & StealC Malware C2 Infrastructure Disrupted
Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.
Amadey & StealC Malware Operations Disrupted by Operation Endgame
Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.
FortiBleed: FortiGate Firewalls Used as Credential Stealers
Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.
Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT
Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.
Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto
Analysis of a cross-platform clipboard hijacker spread via elaborate fake reputation campaigns on GitHub, YouTube, and VirusTotal to steal cryptocurrency.
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.
AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network
Security researchers have identified AryStinger, a new malware family using 4,300 legacy routers as a reconnaissance proxy network to bypass security.
AryStinger Botnet: Thousands of D-Link Routers Compromised as Proxies
The AryStinger botnet has compromised over 4,000 D-Link routers, converting them into malicious proxies using automated exploits for end-of-life hardware.
Prinz Eugen Ransomware Prioritizes Recent Files to Maximize Impact
Prinz Eugen ransomware targets files modified within 30 days to disrupt active operations, using a Go-based encrypter and unconventional ransom demands.
CryptoBandits Malware: Tor-Abusing Backdoor & Data Theft
CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.
Operation Endgame Disrupts SocGholish: WordPress Site Remediation
Operation Endgame targets SocGholish infrastructure, cleaning 14,971 WordPress sites. Understand the impact and crucial remediation steps for web administrators.