Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

HIGH
Malware

Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell

Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.

Runtime Rebel Intel
5 min read · Jul 6, 2026
HIGH
Malware

JadePuffer Ransomware: AI Agents Automate the Full Attack Lifecycle

Researchers have identified JadePuffer, a ransomware operation using LLM-driven AI agents to automate scanning, exploitation, and lateral movement.

Runtime Rebel Intel
3 min read · Jul 4, 2026
PamStealer: New macOS Malware Targets PAM for Password Exfiltration
HIGH
Malware

PamStealer: New macOS Malware Targets PAM for Password Exfiltration

Jamf Threat Labs identifies PamStealer, a macOS malware using fake sites and AppleScript to steal login passwords through PAM exploitation.

Runtime Rebel Intel
4 min read · Jul 3, 2026
ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
HIGH
Malware

ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse

Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.

Runtime Rebel Intel
5 min read · Jul 2, 2026
Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users
HIGH
Malware

Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users

Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.

Runtime Rebel Intel
4 min read · Jul 1, 2026
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
MEDIUM
Malware

Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets

Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.

Runtime Rebel Intel
5 min read · Jun 30, 2026

Advertisement

Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558
HIGH
Malware

Djinn Stealer Targets Cloud & AI Credentials via SimpleHelp CVE-2026-48558

Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.

Runtime Rebel Intel
4 min read · Jun 30, 2026
Microsoft Pulls 119 Malicious StegoAd Edge Extensions
MEDIUM
Malware

Microsoft Pulls 119 Malicious StegoAd Edge Extensions

Microsoft removes 119 Edge extensions linked to the StegoAd campaign, which used steganography in images and fonts to steal credentials and commit ad fraud.

Runtime Rebel Intel
3 min read · Jun 29, 2026
SharkLoader Malware Delivers Cobalt Strike in StrikeShark Attacks
HIGH
Malware

SharkLoader Malware Delivers Cobalt Strike in StrikeShark Attacks

Analysis of SharkLoader malware, a new loader delivering Cobalt Strike Beacon to diplomatic and government entities in StrikeShark cyberattacks.

Runtime Rebel Intel
5 min read · Jun 26, 2026
"Adblock for YouTube" Extension: Dormant Script Injection Threat
HIGH
Malware

"Adblock for YouTube" Extension: Dormant Script Injection Threat

A popular Chrome ad blocker, "Adblock for YouTube," with over 10 million installs, contains a dormant capability for arbitrary JavaScript injection.

Runtime Rebel Intel
4 min read · Jun 25, 2026
Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection
HIGH
Malware

Gaslight macOS Malware Uses Prompt Injection to Bypass AI Detection

Gaslight is a newly discovered Rust-based macOS implant that uses prompt injection to deceive AI-driven analysis tools and bypass automated detection.

Runtime Rebel Intel
3 min read · Jun 25, 2026
MEDIUM
Malware

Malware Evades AI Analysis with 'Forbidden Text' Tactics

Threat actors embed 'forbidden' text in malware to confuse AI analysis tools, targeting bioinformatics and MCP developers.

Runtime Rebel Intel
5 min read · Jun 25, 2026
Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen
HIGH
Malware

Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen

Law enforcement and private sector dismantled infrastructure for Amadey and StealC malware, leading to 27M stolen credentials recovery. Learn impact & defense.

Runtime Rebel Intel
5 min read · Jun 24, 2026
HIGH
Malware

Amadey & StealC Malware C2 Infrastructure Disrupted

Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.

Runtime Rebel Intel
4 min read · Jun 24, 2026
HIGH
Malware

Amadey & StealC Malware Operations Disrupted by Operation Endgame

Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.

Runtime Rebel Intel
5 min read · Jun 24, 2026
FortiBleed: FortiGate Firewalls Used as Credential Stealers
HIGH
Malware

FortiBleed: FortiGate Firewalls Used as Credential Stealers

Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.

Runtime Rebel Intel
4 min read · Jun 23, 2026
HIGH
Malware

Analysis of Obfuscated PowerShell Loaders Delivering Remcos RAT

Technical breakdown of a multi-stage PowerShell malware loader using scheduled tasks for persistence and Remcos RAT as the final payload.

Runtime Rebel Intel
3 min read · Jun 23, 2026
Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto
MEDIUM
Malware

Cross-Platform Clipboard Hijacker: Fake Reputation Campaign Targets Crypto

Analysis of a cross-platform clipboard hijacker spread via elaborate fake reputation campaigns on GitHub, YouTube, and VirusTotal to steal cryptocurrency.

Runtime Rebel Intel
5 min read · Jun 22, 2026
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
HIGH
Malware

OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware

Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.

Runtime Rebel Intel
3 min read · Jun 22, 2026
AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network
MEDIUM
Malware

AryStinger Malware Hijacks 4,300 Legacy Routers for Proxy Network

Security researchers have identified AryStinger, a new malware family using 4,300 legacy routers as a reconnaissance proxy network to bypass security.

Runtime Rebel Intel
4 min read · Jun 22, 2026
HIGH
Malware

AryStinger Botnet: Thousands of D-Link Routers Compromised as Proxies

The AryStinger botnet has compromised over 4,000 D-Link routers, converting them into malicious proxies using automated exploits for end-of-life hardware.

Runtime Rebel Intel
3 min read · Jun 21, 2026
MEDIUM
Malware

Prinz Eugen Ransomware Prioritizes Recent Files to Maximize Impact

Prinz Eugen ransomware targets files modified within 30 days to disrupt active operations, using a Go-based encrypter and unconventional ransom demands.

Runtime Rebel Intel
4 min read · Jun 20, 2026
HIGH
Malware

CryptoBandits Malware: Tor-Abusing Backdoor & Data Theft

CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.

Runtime Rebel Intel
5 min read · Jun 19, 2026
Operation Endgame Disrupts SocGholish: WordPress Site Remediation
HIGH
Malware

Operation Endgame Disrupts SocGholish: WordPress Site Remediation

Operation Endgame targets SocGholish infrastructure, cleaning 14,971 WordPress sites. Understand the impact and crucial remediation steps for web administrators.

Runtime Rebel Intel
5 min read · Jun 19, 2026