Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

MA
HIGH
Malware

Redtail Malware Exploiting CVE-2024-3400: Technical Analysis

Analysis of the Libredtail variant exploiting Palo Alto Networks CVE-2024-3400 to deploy crypto-miners and establish rootkit persistence.

Runtime Rebel Intel
3 min read · Apr 30, 2026
MA
HIGH
Malware

VECT 2.0 Ransomware Analysis: Encryption Flaws Act as Data Wiper

VECT 2.0 ransomware features a critical flaw in its encryption logic that permanently wipes large files, making data recovery impossible even with a key.

Runtime Rebel Intel
3 min read · Apr 29, 2026
LofyGang Targets Minecraft Players with LofyStealer Malware
HIGH
Malware

LofyGang Targets Minecraft Players with LofyStealer Malware

Brazilian cybercrime group LofyGang resurfaces after three years, deploying LofyStealer (GrabBot) disguised as a Minecraft 'Slinky' hack to steal player credentials.

Runtime Rebel Intel
5 min read · Apr 28, 2026
VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi
MEDIUM
Malware

VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi

VECT 2.0 ransomware permanently destroys files over 131KB on Windows, Linux, and ESXi systems due to flawed encryption, making data recovery impossible.

Runtime Rebel Intel
4 min read · Apr 28, 2026
MA
HIGH
Malware

GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions

A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.

Runtime Rebel Intel
4 min read · Apr 28, 2026
MA
HIGH
Malware

Firestarter Malware Persists on Cisco Firewalls Post-Update

U.S. and U.K. agencies warn about Firestarter malware exhibiting post-update persistence on Cisco Firepower and Secure Firewalls running ASA/FTD.

Runtime Rebel Intel
4 min read · Apr 25, 2026
MA
HIGH
Malware

Firestarter Backdoor Infects Cisco Firewall at US Federal Agency

Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 24, 2026
26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis
HIGH
Malware

26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis

Researchers discover 26 malicious apps on the Apple App Store impersonating crypto wallets to steal seed phrases via trojanized software and browser redirects.

Runtime Rebel Intel
4 min read · Apr 24, 2026
MA
HIGH
Malware

Trigona Ransomware: Custom Tool for Faster Data Exfiltration

Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.

Runtime Rebel Intel
5 min read · Apr 23, 2026
MA
CRITICAL
Malware

FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall

CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.

Runtime Rebel Intel
6 min read · Apr 23, 2026
MA
HIGH
Malware

Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption

Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.

Runtime Rebel Intel
4 min read · Apr 22, 2026
MA
HIGH
Malware

CVE-2025-29635: Mirai Exploits EoL D-Link Routers

A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks. Urgent…

Runtime Rebel Intel
4 min read · Apr 22, 2026
Lotus Wiper Malware Targets Venezuelan Energy Sector
MEDIUM
Malware

Lotus Wiper Malware Targets Venezuelan Energy Sector

Kaspersky researchers uncover Lotus Wiper, a destructive malware targeting Venezuelan energy and utility systems via malicious batch scripts.

Runtime Rebel Intel
4 min read · Apr 22, 2026
MA
HIGH
Malware

Malicious Crypto Apps on Apple App Store Target Private Keys

Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to…

Runtime Rebel Intel
5 min read · Apr 21, 2026
MA
HIGH
Malware

Lotus Data Wiper Targets Venezuelan Energy Utilities

Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.

Runtime Rebel Intel
5 min read · Apr 21, 2026
NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil
HIGH
Malware

NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil

Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.

Runtime Rebel Intel
4 min read · Apr 21, 2026
MA
HIGH
Malware

Python Infostealer Targeting Browser Credentials and Discord Tokens

Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.

Runtime Rebel Intel
4 min read · Apr 21, 2026
MA
MEDIUM
Malware

Malware Delivery via Malicious .WAV Files — Technical Analysis

Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.

Runtime Rebel Intel
4 min read · Apr 21, 2026
MA
HIGH
Malware

Malicious Crypto Wallets Infiltrate China's Apple App Store

26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.

Runtime Rebel Intel
4 min read · Apr 21, 2026
MA
MEDIUM
Malware

Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions

Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.

Runtime Rebel Intel
3 min read · Apr 17, 2026
MA
HIGH
Malware

Lumma Stealer and Sectop RAT Dual Infection Chain Analysis

Technical breakdown of the Lumma Stealer and Sectop RAT (ArechClient2) infection chain, detailing C2 communication and persistence mechanisms.

Runtime Rebel Intel
3 min read · Apr 17, 2026
MA
MEDIUM
Malware

PDF JavaScript Exploitation: Analysis of PowerShell Delivery

Technical analysis of malicious PDF documents using embedded JavaScript and /OpenAction triggers to execute PowerShell for initial access and C2 establishment.

Runtime Rebel Intel
4 min read · Apr 17, 2026
Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
HIGH
Malware

Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion

Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.

Runtime Rebel Intel
5 min read · Apr 17, 2026
MA
HIGH
Malware

Analyzing ZionSiphon: Malware Targeting Water Treatment OT Systems

Investigate ZionSiphon malware, an OT-specific threat designed to sabotage water treatment and desalination facilities. Understand its impact and critical defense…

Runtime Rebel Intel
5 min read · Apr 17, 2026