Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

MEDIUM
Malware

Bypass AI Malware Scanners via Policy-Triggering Prompt Injection

Malware authors are embedding 'forbidden' text into code to trigger safety refusals in AI-mediated security scanners, effectively bypassing automated analysis.

Runtime Rebel Intel
4 min read · Jun 19, 2026
MEDIUM
Malware

Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies

Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.

Runtime Rebel Intel
4 min read · Jun 19, 2026
HIGH
Malware

USB Worm Exploits LNK Files for Crypto-Stealing Malware

New USB worm propagates crypto-stealing malware through Windows shortcut files, leveraging removable drives and the Tor network for C2 to target cryptocurrency wallets.

Runtime Rebel Intel
5 min read · Jun 18, 2026
Crypto Clipper Campaign Abuses AI Narrators and Fake Reviews
HIGH
Malware

Crypto Clipper Campaign Abuses AI Narrators and Fake Reviews

An unknown threat actor leverages paid posts, fake reviews, AI narrators, and phishing sites to distribute crypto clipper malware. Learn defense tactics.

Runtime Rebel Intel
4 min read · Jun 17, 2026
Phantom Stealer: Fileless Credential Theft & Evasion
HIGH
Malware

Phantom Stealer: Fileless Credential Theft & Evasion

Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.

Runtime Rebel Intel
5 min read · Jun 17, 2026
HIGH
Malware

Rokarolla Android Malware Targets 217 Financial Apps

New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.

Runtime Rebel Intel
4 min read · Jun 16, 2026

Advertisement

Malicious Chrome Wallpaper Extensions Distribute Adware
HIGH
Malware

Malicious Chrome Wallpaper Extensions Distribute Adware

Analysis of 152 malicious Chrome wallpaper extensions distributing adware and generating fake traffic. Over 105K installs across 38 publisher accounts.

Runtime Rebel Intel
4 min read · Jun 15, 2026
MEDIUM
Malware

MSI Malware Detection: Statistical Analysis for Base64 Payloads

Learn how to use statistical analysis to identify obfuscated Base64 payloads within malicious MSI files and improve your incident response capabilities.

Runtime Rebel Intel
4 min read · Jun 15, 2026
HIGH
Malware

Lumma Stealer Distributed via Fake EditPro AI Image Generator

Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.

Runtime Rebel Intel
3 min read · Jun 13, 2026
The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties
HIGH
Malware

The Gentlemen Ransomware: Worm-like Spread, 478 Victims, RaaS Ties

Analysis of The Gentlemen ransomware reveals its worm-like propagation, double extortion tactics, and operational ties to LockBit, Qilin, and Medusa RaaS schemes…

Runtime Rebel Intel
4 min read · Jun 11, 2026
HIGH
Malware

OnyxC2 Stealer: Enterprise-Grade Info-Theft for $250/Month

OnyxC2 stealer targets over 200 applications and extensions, using encrypted payloads, DLL sideloading, and in-memory execution to evade detection.

Runtime Rebel Intel
5 min read · Jun 11, 2026
HIGH
Malware

Infostealers: Millions of Devices Compromised for Credential Theft

Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.

Runtime Rebel Intel
4 min read · Jun 11, 2026
HIGH
Malware

Miasma Worm Source Code Briefly Leaked on GitHub

Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks.

Runtime Rebel Intel
4 min read · Jun 10, 2026
Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware
MEDIUM
Malware

Autonomous AI Worm: How Local LLMs Enable Self-Replicating Malware

Researchers demonstrate an autonomous AI worm using local open-weight LLMs to navigate networks and replicate without human intervention or cloud services.

Runtime Rebel Intel
3 min read · Jun 9, 2026
HIGH
Malware

Python-Based Infostealer Masked as PDF Targets Browser Credentials

Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.

Runtime Rebel Intel
4 min read · Jun 9, 2026
HIGH
Malware

NFCShare Malware: GitHub Spoofing Leads to NFC Relay Attacks

Attackers leverage GitHub to distribute NFCShare (NGate) malware, utilizing NFC relay attacks to clone payment cards and perform unauthorized ATM withdrawals.

Runtime Rebel Intel
3 min read · Jun 9, 2026
MEDIUM
Malware

Excel VBA Macro Obfuscation: How to Detect Hidden Payloads

Learn how to analyze and detect obfuscated VBA macros in Excel files using oledump.py. Technical guide on character substitution and string reversal techniques.

Runtime Rebel Intel
3 min read · Jun 8, 2026
HIGH
Malware

C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation

C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.

Runtime Rebel Intel
3 min read · Jun 7, 2026
Asin Android Spyware Targets Arabic Users via Fake War Maps
HIGH
Malware

Asin Android Spyware Targets Arabic Users via Fake War Maps

ESET identifies Asin, a new Android spyware targeting Arabic speakers through malicious websites masquerading as news platforms and utility applications.

Runtime Rebel Intel
4 min read · Jun 5, 2026
MEDIUM
Malware

MSI-Branded Image Steganography: Analysis of WeTransfer Phishing

Analysis of a recurring phishing campaign using steganography in MSI-branded images to deliver malicious payloads via WeTransfer links and bypass security.

Runtime Rebel Intel
4 min read · Jun 5, 2026
Weedhack MaaS Campaign Targets Minecraft Users via CountLoader
MEDIUM
Malware

Weedhack MaaS Campaign Targets Minecraft Users via CountLoader

McAfee Labs reports the Weedhack campaign spreading CountLoader and cryptominers through fake Minecraft mods on YouTube. Learn detection and mitigation.

Runtime Rebel Intel
4 min read · Jun 3, 2026
MEDIUM
Malware

AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery

New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.

Runtime Rebel Intel
5 min read · Jun 2, 2026
HIGH
Malware

NetSupport RAT Infection: How to Detect Unidentified Loader Exploits

Analyze the multi-stage infection chain of an unidentified loader delivering NetSupport RAT, featuring technical breakdowns of JavaScript and PowerShell TTPs.

Runtime Rebel Intel
4 min read · Jun 1, 2026
HIGH
Malware

ChatGPT Share Link Abuse: Fake Outages Deliver Malware

Threat actors leverage ChatGPT share links to host deceptive outage pages, prompting users to download malware disguised as an official desktop app.

Runtime Rebel Intel
4 min read · May 29, 2026