Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

Malicious Chrome Wallpaper Extensions Distribute Adware
HIGH
Malware

Malicious Chrome Wallpaper Extensions Distribute Adware

Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts. Learn to identify…

Runtime Rebel Intel
4 min read · Jun 15, 2026
MA
MEDIUM
Malware

MSI Malware Detection: Statistical Analysis for Base64 Payloads

Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.

Runtime Rebel Intel
4 min read · Jun 15, 2026
MA
HIGH
Malware

Lumma Stealer Distributed via Fake EditPro AI Image Generator

Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.

Runtime Rebel Intel
3 min read · Jun 13, 2026
The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties
HIGH
Malware

The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties

Analysis of The Gentlemen ransomware reveals its worm-like propagation, double extortion tactics, and operational ties to LockBit, Qilin, and Medusa RaaS schemes…

Runtime Rebel Intel
4 min read · Jun 11, 2026
MA
HIGH
Malware

OnyxC2 Stealer: Enterprise-Grade Info-Theft for $250/Month

OnyxC2 stealer targets over 200 applications and extensions, using encrypted payloads, DLL sideloading, and in-memory execution to evade detection.

Runtime Rebel Intel
5 min read · Jun 11, 2026
MA
HIGH
Malware

Infostealers: Millions of Devices Compromised for Credential Theft

Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.

Runtime Rebel Intel
4 min read · Jun 11, 2026
MA
HIGH
Malware

Miasma Worm Source Code Briefly Leaked on GitHub

Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks. Understand…

Runtime Rebel Intel
4 min read · Jun 10, 2026
Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware
MEDIUM
Malware

Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware

Researchers demonstrate an autonomous AI worm using local open-weight LLMs to navigate networks and replicate without human intervention or cloud services.

Runtime Rebel Intel
3 min read · Jun 9, 2026
MA
HIGH
Malware

Python-Based Infostealer Masked as PDF Targets Browser Credentials

Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.

Runtime Rebel Intel
4 min read · Jun 9, 2026
MA
HIGH
Malware

NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks

Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.

Runtime Rebel Intel
3 min read · Jun 9, 2026
MA
MEDIUM
Malware

Excel VBA Macro Obfuscation: How to Detect Hidden Payloads

Learn how to analyze and detect obfuscated VBA macros in Excel files using oledump.py. Technical guide on character substitution and string reversal techniques.

Runtime Rebel Intel
3 min read · Jun 8, 2026
MA
HIGH
Malware

C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation

C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.

Runtime Rebel Intel
3 min read · Jun 7, 2026
Asin Android Spyware Targets Arabic Users via Fake War Maps
HIGH
Malware

Asin Android Spyware Targets Arabic Users via Fake War Maps

ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.

Runtime Rebel Intel
4 min read · Jun 5, 2026
MA
MEDIUM
Malware

MSI-Branded Image Steganography: Analysis of WeTransfer Phishing

Analysis of a recurring phishing campaign using steganography in MSI-branded images to deliver malicious payloads via WeTransfer links and bypass security.

Runtime Rebel Intel
4 min read · Jun 5, 2026
Weedhack MaaS Campaign Targets Minecraft Users via CountLoader
MEDIUM
Malware

Weedhack MaaS Campaign Targets Minecraft Users via CountLoader

McAfee Labs reports the Weedhack campaign spreading CountLoader and cryptominers through fake Minecraft mods on YouTube. Learn detection and mitigation.

Runtime Rebel Intel
4 min read · Jun 3, 2026
MA
MEDIUM
Malware

AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery

New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.

Runtime Rebel Intel
5 min read · Jun 2, 2026
MA
HIGH
Malware

NetSupport RAT Infection: How to Detect Unidentified Loader Exploits

Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.

Runtime Rebel Intel
4 min read · Jun 1, 2026
MA
HIGH
Malware

ChatGPT Share Link Abuse: Fake Outages Deliver Malware

Threat actors leverage ChatGPT share links to host deceptive outage pages, prompting users to download malware disguised as an official desktop app.

Runtime Rebel Intel
4 min read · May 29, 2026
MA
HIGH
Malware

BTMOB Android Malware: Analyzing Phishing-Driven Full Device Takeover

BTMOB malware targets Android users via phishing, utilizing VNC and accessibility services to facilitate financial theft and total remote device control.

Runtime Rebel Intel
3 min read · May 28, 2026
MA
HIGH
Malware

Akira Ransomware Kill Chain: Log Analysis for Early Detection

Analyze Akira Ransomware kill chain stages using perimeter and endpoint logs to detect initial access, privilege escalation, and pre-encryption activity.

Runtime Rebel Intel
5 min read · May 28, 2026
MA
MEDIUM
Malware

SEO Poisoning and AI Chatbots Spread GPU Mining Malware

Threat actors are using SEO poisoning and manipulated AI chatbot recommendations to distribute persistent GPU mining malware to high-performance systems.

Runtime Rebel Intel
4 min read · May 28, 2026
MA
HIGH
Malware

ACR Stealer Distributed via Fake Claude AI Desktop Site

Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.

Runtime Rebel Intel
4 min read · May 26, 2026
MA
MEDIUM
Malware

Analyzing Microsoft Access VBA Macros for Malware Detection

Learn how threat actors use Microsoft Access .accdb files to execute malicious VBA code and how to analyze these OLE streams for incident response.

Runtime Rebel Intel
3 min read · May 25, 2026
MA
INFO
Malware

Obfuscating Strings in C++ Implants: Detection and Analysis

Analyze how stack strings help malware authors evade static analysis. Explore the assembly-level mechanics and detection strategies for Windows implants.

Runtime Rebel Intel
4 min read · May 23, 2026