Advertisement
Bypass AI Malware Scanners via Policy-Triggering Prompt Injection
Malware authors are embedding 'forbidden' text into code to trigger safety refusals in AI-mediated security scanners, effectively bypassing automated analysis.
Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies
Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.
USB Worm Exploits LNK Files for Crypto-Stealing Malware
New USB worm propagates crypto-stealing malware through Windows shortcut files, leveraging removable drives and the Tor network for C2 to target cryptocurrency wallets.
Crypto Clipper Campaign Abuses AI Narrators and Fake Reviews
An unknown threat actor leverages paid posts, fake reviews, AI narrators, and phishing sites to distribute crypto clipper malware. Learn defense tactics.
Phantom Stealer: Fileless Credential Theft & Evasion
Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.
Rokarolla Android Malware Targets 217 Financial Apps
New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.
Advertisement
Malicious Chrome Wallpaper Extensions Distribute Adware
Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts.
MSI Malware Detection: Statistical Analysis for Base64 Payloads
Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.
Lumma Stealer Distributed via Fake EditPro AI Image Generator
Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.
The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties
Analysis of The Gentlemen ransomware reveals its worm-like propagation, double extortion tactics, and operational ties to LockBit, Qilin, and Medusa RaaS schemes…
OnyxC2 Stealer: Enterprise-Grade Info-Theft for $250/Month
OnyxC2 stealer targets over 200 applications and extensions, using encrypted payloads, DLL sideloading, and in-memory execution to evade detection.
Infostealers: Millions of Devices Compromised for Credential Theft
Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.
Miasma Worm Source Code Briefly Leaked on GitHub
Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks.
Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware
Researchers demonstrate an autonomous AI worm using local open-weight LLMs to navigate networks and replicate without human intervention or cloud services.
Python-Based Infostealer Masked as PDF Targets Browser Credentials
Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.
NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks
Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.
Excel VBA Macro Obfuscation: How to Detect Hidden Payloads
Learn how to analyze and detect obfuscated VBA macros in Excel files using oledump.py. Technical guide on character substitution and string reversal techniques.
C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation
C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.
Asin Android Spyware Targets Arabic Users via Fake War Maps
ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.
MSI-Branded Image Steganography: Analysis of WeTransfer Phishing
Analysis of a recurring phishing campaign using steganography in MSI-branded images to deliver malicious payloads via WeTransfer links and bypass security.
Weedhack MaaS Campaign Targets Minecraft Users via CountLoader
McAfee Labs reports the Weedhack campaign spreading CountLoader and cryptominers through fake Minecraft mods on YouTube. Learn detection and mitigation.
AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery
New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.
NetSupport RAT Infection: How to Detect Unidentified Loader Exploits
Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.
ChatGPT Share Link Abuse: Fake Outages Deliver Malware
Threat actors leverage ChatGPT share links to host deceptive outage pages, prompting users to download malware disguised as an official desktop app.