Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

MA
HIGH
Malware

Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware

Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.

Runtime Rebel Intel
3 min read · Apr 16, 2026
MA
MEDIUM
Malware

SVG File Phishing: How Attackers Hide Malicious JavaScript in Images

Discover how attackers use Scalable Vector Graphics (SVG) to embed malicious JavaScript for phishing and credential theft while bypassing security filters.

Runtime Rebel Intel
3 min read · Apr 16, 2026
MA
HIGH
Malware

AgingFly Malware: Credential Theft Operations Against Ukraine

Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…

Runtime Rebel Intel
5 min read · Apr 16, 2026
MA
HIGH
Malware

Signed Software Abuse: How Malicious Scripts Disable EDR and AV

Analysis of signed adware being used to deploy antivirus-killing scripts with SYSTEM privileges across government and healthcare sectors.

Runtime Rebel Intel
4 min read · Apr 15, 2026
MA
HIGH
Malware

Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse

Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.

Runtime Rebel Intel
4 min read · Apr 15, 2026
Mirax Android RAT: Bypassing Security via Malicious Meta Ads
HIGH
Malware

Mirax Android RAT: Bypassing Security via Malicious Meta Ads

Mirax Android RAT targets 220,000 users via Meta Ads, turning devices into SOCKS5 proxies. Learn to detect and mitigate this emerging mobile threat.

Runtime Rebel Intel
3 min read · Apr 14, 2026
JanelaRAT Malware Analysis: 14,000+ Attacks Target Latin American Banks
HIGH
Malware

JanelaRAT Malware Analysis: 14,000+ Attacks Target Latin American Banks

Analyze the JanelaRAT campaign targeting Brazil and Mexico. Learn how this BX RAT variant steals financial data and how to detect JanelaRAT attacks.

Runtime Rebel Intel
3 min read · Apr 13, 2026
MA
HIGH
Malware

Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide

Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.

Runtime Rebel Intel
4 min read · Apr 13, 2026
MA
HIGH
Malware

Storm Infostealer: Bypassing Local Decryption for Session Hijacking

Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.

Runtime Rebel Intel
3 min read · Apr 13, 2026
MA
MEDIUM
Malware

Detect Obfuscated JavaScript Phishing Delivered via RAR Archives

Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.

Runtime Rebel Intel
4 min read · Apr 10, 2026
MA
HIGH
Malware

LucidRook Malware Targets Taiwan NGOs via DLL Side-Loading

Analysis of the Lua-based LucidRook malware targeting Taiwanese NGOs and universities through spear-phishing and sophisticated DLL side-loading techniques.

Runtime Rebel Intel
4 min read · Apr 10, 2026
MA
HIGH
Malware

Magecart Skimmer Hides in Pixel-Sized SVG on Magento Stores

A sophisticated Magecart campaign targets nearly 100 Magento stores, concealing credit card-stealing JavaScript within tiny, pixel-sized SVG images.

Runtime Rebel Intel
5 min read · Apr 9, 2026
Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns
HIGH
Malware

Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns

The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.

Runtime Rebel Intel
4 min read · Apr 8, 2026
Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy
HIGH
Malware

Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy

A new variant of Chaos malware targets misconfigured cloud deployments, leveraging SOCKS proxy capabilities to expand botnet infrastructure beyond edge devices.

Runtime Rebel Intel
4 min read · Apr 8, 2026
MA
HIGH
Malware

Masjesu Botnet: Stealthy DDoS Malware Targets Linux IoT Devices

Masjesu is a highly evasive DDoS botnet targeting Linux IoT devices. It prioritizes persistence and avoids critical infrastructure to remain undetected.

Runtime Rebel Intel
4 min read · Apr 8, 2026
MA
HIGH
Malware

Medusa Ransomware: Rapid Vulnerability Weaponization and Analysis

An analysis of Medusa ransomware's rapid exploitation of vulnerabilities and Zero-Day bugs to exfiltrate and encrypt data within days of initial access.

Runtime Rebel Intel
4 min read · Apr 7, 2026
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
HIGH
Malware

Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD

Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.

Runtime Rebel Intel
3 min read · Apr 6, 2026
SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases
HIGH
Malware

SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases

A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.

Runtime Rebel Intel
6 min read · Apr 3, 2026
MA
HIGH
Malware

Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak

Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…

Runtime Rebel Intel
4 min read · Apr 3, 2026
Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America
HIGH
Malware

Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America

Analyzing Casbaneiro, a sophisticated banking Trojan employing advanced evasion, process injection, and network worming to target financial institutions and users in…

Runtime Rebel Intel
4 min read · Apr 2, 2026
Ransomware Preparation: Healthcare Facilities' Defense Strategy
MEDIUM
Malware

Ransomware Preparation: Healthcare Facilities' Defense Strategy

Hospitals face inevitable ransomware attacks. Learn why proactive incident response planning, regular rehearsals, and robust technical controls are crucial for defense.

Runtime Rebel Intel
4 min read · Apr 2, 2026
MA
HIGH
Malware

CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware

CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…

Runtime Rebel Intel
5 min read · Apr 2, 2026
MA
HIGH
Malware

NoVoice Android Malware on Google Play: 2.3 Million Devices Infected

NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.

Runtime Rebel Intel
5 min read · Apr 1, 2026
Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks
HIGH
Malware

Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks

Analyze Venom Stealer MaaS, a new cybercrime platform enabling automated, persistent information-stealing through social engineering 'ClickFix' attacks. Learn detection…

Runtime Rebel Intel
4 min read · Apr 1, 2026