Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

MA
HIGH
Malware

Analysis of Cross-Platform NPM Stealer Using Discord Webhooks

Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.

Runtime Rebel Intel
4 min read · May 22, 2026
MA
MEDIUM
Malware

Malicious PDF Structure Analysis and Obfuscation Detection

Learn how to detect malicious PDF obfuscation and analyze internal structures like /OpenAction and /JS streams to identify hidden malware payloads.

Runtime Rebel Intel
4 min read · May 21, 2026
SHub Reaper Stealer Backdoors macOS via Spoofed Apps
HIGH
Malware

SHub Reaper Stealer Backdoors macOS via Spoofed Apps

SHub Reaper stealer targets macOS, using fake Google, Microsoft, Apple, WeChat, and Miro installers for Apple script-based execution and backdooring.

Runtime Rebel Intel
5 min read · May 19, 2026
Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests
MEDIUM
Malware

Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests

Researchers reveal the Trapdoor ad fraud scheme, involving 455 Android apps and 183 C2 domains generating over 600 million daily fraudulent bid requests.

Runtime Rebel Intel
4 min read · May 19, 2026
MA
MEDIUM
Malware

Abuse of MSHTA in Stealthy Malware Delivery Chains

Attackers are abusing the legacy Windows MSHTA utility to deliver malware silently via phishing and fake downloads, bypassing EDR through LOLBIN techniques.

Runtime Rebel Intel
4 min read · May 19, 2026
MA
HIGH
Malware

SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor

A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.

Runtime Rebel Intel
4 min read · May 19, 2026
Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments
HIGH
Malware

Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments

The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.

Runtime Rebel Intel
4 min read · May 18, 2026
MA
MEDIUM
Malware

Malware Evolution: How New Libraries and Languages Bypass EDR

Attackers are adopting Go, Rust, and custom libraries to evade static signatures. Learn how to adapt your detection engineering for modern malware binaries.

Runtime Rebel Intel
4 min read · May 15, 2026
MA
HIGH
Malware

Malicious Windows 11 ISOs Deliver Vidar Infostealer — Analysis

Security researchers warn of fake Windows 11 ISO installers delivering Vidar and RedLine infostealers through sophisticated DLL side-loading techniques.

Runtime Rebel Intel
4 min read · May 12, 2026
MA
HIGH
Malware

TrickMo Android Trojan Uses TON Blockchain for Covert C2

TrickMo Android banking malware adopts The Open Network (TON) blockchain for decentralized C2, targeting European users via accessibility service abuse.

Runtime Rebel Intel
3 min read · May 11, 2026
TCLBANKER Malware: Brazilian Trojan Spreads via WhatsApp and Outlook
HIGH
Malware

TCLBANKER Malware: Brazilian Trojan Spreads via WhatsApp and Outlook

TCLBANKER (REF3076) targets 59 financial platforms using the SORVEPOTEL worm. Learn how to detect and mitigate this evolving Brazilian banking trojan.

Runtime Rebel Intel
4 min read · May 8, 2026
Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks
HIGH
Malware

Quasar Linux RAT (QLNX) Targets Developers for Supply Chain Attacks

A new Linux implant, Quasar Linux RAT (QLNX), targets developer systems for credential theft and network tunneling to compromise software supply chains.

Runtime Rebel Intel
4 min read · May 8, 2026
MA
HIGH
Malware

Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215

Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.

Runtime Rebel Intel
3 min read · May 8, 2026
MA
HIGH
Malware

PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments

PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.

Runtime Rebel Intel
4 min read · May 8, 2026
MA
HIGH
Malware

TCLBanker Malware Targets Fintech via WhatsApp and Outlook

TCLBanker malware uses trojanized Logitech AI installers to target 59 banking apps and spreads automatically via WhatsApp and Outlook messages.

Runtime Rebel Intel
4 min read · May 8, 2026
MA
HIGH
Malware

PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access

New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.

Runtime Rebel Intel
4 min read · May 7, 2026
PCPJack Credential Stealer: Cloud System Exploitation & Spread
HIGH
Malware

PCPJack Credential Stealer: Cloud System Exploitation & Spread

PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…

Runtime Rebel Intel
5 min read · May 7, 2026
Mirai-Based xlabs_v1 Botnet Hijacks IoT Devices via ADB
HIGH
Malware

Mirai-Based xlabs_v1 Botnet Hijacks IoT Devices via ADB

Learn how the xlabs_v1 botnet exploits Android Debug Bridge (ADB) on port 5555 to enroll IoT devices into a DDoS network and how to secure your hardware.

Runtime Rebel Intel
4 min read · May 7, 2026
MA
HIGH
Malware

Stealthy Quasar Linux (QLNX) Malware Targets Developers

New Quasar Linux (QLNX) malware is infecting developers' Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.

Runtime Rebel Intel
5 min read · May 6, 2026
MA
HIGH
Malware

DarkSword: Analyzing the GTIG iOS Full-Chain Zero-Day Exploit

Google Threat Intelligence Group uncovers DarkSword, a sophisticated iOS exploit chain leveraging multiple zero-days for state-sponsored surveillance.

Runtime Rebel Intel
3 min read · May 5, 2026
MA
MEDIUM
Malware

Malicious PDF Files: Analyzing AcroForm JavaScript for Initial Access

Security analysts have identified malicious PDF files utilizing AcroForm dictionaries to execute JavaScript and fetch remote payloads from external servers.

Runtime Rebel Intel
4 min read · May 4, 2026
MA
HIGH
Malware

MacSync Stealer Distributed via Malicious Homebrew Ad Campaign

Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.

Runtime Rebel Intel
4 min read · May 1, 2026
MA
MEDIUM
Malware

Hugging Face and ClawHub Abused for Malware Distribution

Threat actors are exploiting the trust of AI and code-hosting platforms like Hugging Face and ClawHub to distribute malware via social engineering lures.

Runtime Rebel Intel
4 min read · May 1, 2026
New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials
HIGH
Malware

New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials

DEEP#DOOR is a stealthy Python-based backdoor framework using tunneling services for persistent C2 and credential harvesting from cloud and browser data.

Runtime Rebel Intel
4 min read · Apr 30, 2026