Advertisement
Stealthy Quasar Linux (QLNX) Malware Targets Developers
New Quasar Linux (QLNX) malware is infecting developers' Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.
DarkSword: Analyzing the GTIG iOS Full-Chain Zero-Day Exploit
Google Threat Intelligence Group uncovers DarkSword, a sophisticated iOS exploit chain leveraging multiple zero-days for state-sponsored surveillance.
Malicious PDF Files: Analyzing AcroForm JavaScript for Initial Access
Security analysts have identified malicious PDF files utilizing AcroForm dictionaries to execute JavaScript and fetch remote payloads from external servers.
MacSync Stealer Distributed via Malicious Homebrew Ad Campaign
Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.
Hugging Face and ClawHub Abused for Malware Distribution
Threat actors are exploiting the trust of AI and code-hosting platforms like Hugging Face and ClawHub to distribute malware via social engineering lures.
New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials
DEEP#DOOR is a stealthy Python-based backdoor framework using tunneling services for persistent C2 and credential harvesting from cloud and browser data.
Advertisement
Redtail Malware Exploiting CVE-2024-3400: Technical Analysis
Analysis of the Libredtail variant exploiting Palo Alto Networks CVE-2024-3400 to deploy crypto-miners and establish rootkit persistence.
VECT 2.0 Ransomware Analysis: Encryption Flaws Act as Data Wiper
VECT 2.0 ransomware features a critical flaw in its encryption logic that permanently wipes large files, making data recovery impossible even with a key.
LofyGang Targets Minecraft Players with LofyStealer Malware
Brazilian cybercrime group LofyGang resurfaces after three years, deploying LofyStealer (GrabBot) disguised as a Minecraft 'Slinky' hack to steal player credentials.
VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi
VECT 2.0 ransomware permanently destroys files over 131KB on Windows, Linux, and ESXi systems due to flawed encryption, making data recovery impossible.
GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions
A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.
Firestarter Malware Persists on Cisco Firewalls Post-Update
U.S. and U.K. agencies warn about Firestarter malware exhibiting post-update persistence on Cisco Firepower and Secure Firewalls running ASA/FTD.
Firestarter Backdoor Infects Cisco Firewall at US Federal Agency
Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.
26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis
Researchers discover 26 malicious apps on the Apple App Store impersonating crypto wallets to steal seed phrases via trojanized software and browser redirects.
Trigona Ransomware: Custom Tool for Faster Data Exfiltration
Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.
FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall
CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.
Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption
Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.
CVE-2025-29635: Mirai Exploits EoL D-Link Routers
A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks.
Lotus Wiper Malware Targets Venezuelan Energy Sector
Kaspersky researchers uncover Lotus Wiper, a destructive malware targeting Venezuelan energy and utility systems via malicious batch scripts.
Malicious Crypto Apps on Apple App Store Target Private Keys
Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to…
Lotus Data Wiper Targets Venezuelan Energy Utilities
Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.
NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil
Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.
Python Infostealer Targeting Browser Credentials and Discord Tokens
Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.
Malware Delivery via Malicious .WAV Files — Technical Analysis
Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.