Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

HIGH
Malware

Stealthy Quasar Linux (QLNX) Malware Targets Developers

New Quasar Linux (QLNX) malware is infecting developers' Linux systems, utilizing rootkit, backdoor, and credential-stealing techniques. Learn to detect and mitigate.

Runtime Rebel Intel
5 min read · May 6, 2026
HIGH
Malware

DarkSword: Analyzing the GTIG iOS Full-Chain Zero-Day Exploit

Google Threat Intelligence Group uncovers DarkSword, a sophisticated iOS exploit chain leveraging multiple zero-days for state-sponsored surveillance.

Runtime Rebel Intel
3 min read · May 5, 2026
MEDIUM
Malware

Malicious PDF Files: Analyzing AcroForm JavaScript for Initial Access

Security analysts have identified malicious PDF files utilizing AcroForm dictionaries to execute JavaScript and fetch remote payloads from external servers.

Runtime Rebel Intel
4 min read · May 4, 2026
HIGH
Malware

MacSync Stealer Distributed via Malicious Homebrew Ad Campaign

Malicious ads for Homebrew distribute MacSync Stealer, targeting macOS users. Threat actors leverage trusted software to deploy data-stealing malware.

Runtime Rebel Intel
4 min read · May 1, 2026
MEDIUM
Malware

Hugging Face and ClawHub Abused for Malware Distribution

Threat actors are exploiting the trust of AI and code-hosting platforms like Hugging Face and ClawHub to distribute malware via social engineering lures.

Runtime Rebel Intel
4 min read · May 1, 2026
New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials
HIGH
Malware

New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials

DEEP#DOOR is a stealthy Python-based backdoor framework using tunneling services for persistent C2 and credential harvesting from cloud and browser data.

Runtime Rebel Intel
4 min read · Apr 30, 2026

Advertisement

HIGH
Malware

Redtail Malware Exploiting CVE-2024-3400: Technical Analysis

Analysis of the Libredtail variant exploiting Palo Alto Networks CVE-2024-3400 to deploy crypto-miners and establish rootkit persistence.

Runtime Rebel Intel
3 min read · Apr 30, 2026
HIGH
Malware

VECT 2.0 Ransomware Analysis: Encryption Flaws Act as Data Wiper

VECT 2.0 ransomware features a critical flaw in its encryption logic that permanently wipes large files, making data recovery impossible even with a key.

Runtime Rebel Intel
3 min read · Apr 29, 2026
LofyGang Targets Minecraft Players with LofyStealer Malware
HIGH
Malware

LofyGang Targets Minecraft Players with LofyStealer Malware

Brazilian cybercrime group LofyGang resurfaces after three years, deploying LofyStealer (GrabBot) disguised as a Minecraft 'Slinky' hack to steal player credentials.

Runtime Rebel Intel
5 min read · Apr 28, 2026
VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi
MEDIUM
Malware

VECT 2.0 Ransomware Acts as Wiper on Windows, Linux, and ESXi

VECT 2.0 ransomware permanently destroys files over 131KB on Windows, Linux, and ESXi systems due to flawed encryption, making data recovery impossible.

Runtime Rebel Intel
4 min read · Apr 28, 2026
HIGH
Malware

GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions

A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.

Runtime Rebel Intel
4 min read · Apr 28, 2026
HIGH
Malware

Firestarter Malware Persists on Cisco Firewalls Post-Update

U.S. and U.K. agencies warn about Firestarter malware exhibiting post-update persistence on Cisco Firepower and Secure Firewalls running ASA/FTD.

Runtime Rebel Intel
4 min read · Apr 25, 2026
HIGH
Malware

Firestarter Backdoor Infects Cisco Firewall at US Federal Agency

Analysis of the Firestarter backdoor on Cisco firewalls, detailing its remote access capabilities, post-patch persistence, and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 24, 2026
26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis
HIGH
Malware

26 FakeWallet Apps Infiltrate Apple App Store - Research Analysis

Researchers discover 26 malicious apps on the Apple App Store impersonating crypto wallets to steal seed phrases via trojanized software and browser redirects.

Runtime Rebel Intel
4 min read · Apr 24, 2026
HIGH
Malware

Trigona Ransomware: Custom Tool for Faster Data Exfiltration

Trigona ransomware operators are employing a new custom command-line tool to accelerate data exfiltration, posing a significant threat to compromised networks.

Runtime Rebel Intel
5 min read · Apr 23, 2026
CRITICAL
Malware

FIRESTARTER Backdoor: Persistent Threat to Cisco Firepower & Secure Firewall

CISA and NCSC warn of FIRESTARTER, an APT-deployed backdoor maintaining persistence on Cisco Firepower and Secure Firewall devices post-patching.

Runtime Rebel Intel
6 min read · Apr 23, 2026
HIGH
Malware

Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption

Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.

Runtime Rebel Intel
4 min read · Apr 22, 2026
HIGH
Malware

CVE-2025-29635: Mirai Exploits EoL D-Link Routers

A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks.

Runtime Rebel Intel
4 min read · Apr 22, 2026
Lotus Wiper Malware Targets Venezuelan Energy Sector
MEDIUM
Malware

Lotus Wiper Malware Targets Venezuelan Energy Sector

Kaspersky researchers uncover Lotus Wiper, a destructive malware targeting Venezuelan energy and utility systems via malicious batch scripts.

Runtime Rebel Intel
4 min read · Apr 22, 2026
HIGH
Malware

Malicious Crypto Apps on Apple App Store Target Private Keys

Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to…

Runtime Rebel Intel
5 min read · Apr 21, 2026
HIGH
Malware

Lotus Data Wiper Targets Venezuelan Energy Utilities

Analysis of the Lotus data wiper targeting Venezuelan energy and utility firms in 2023. Understand its destructive capabilities and TTPs for defense.

Runtime Rebel Intel
5 min read · Apr 21, 2026
NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil
HIGH
Malware

NGate Android Malware: Trojanized HandyPay Targets NFC Data in Brazil

Attackers are deploying NGate malware in Brazil by trojanizing the HandyPay app to capture NFC data and PINs using AI-generated malicious code.

Runtime Rebel Intel
4 min read · Apr 21, 2026
HIGH
Malware

Python Infostealer Targeting Browser Credentials and Discord Tokens

Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.

Runtime Rebel Intel
4 min read · Apr 21, 2026
MEDIUM
Malware

Malware Delivery via Malicious .WAV Files — Technical Analysis

Security analysts identify .WAV audio files being used to hide malicious payloads. Learn how steganography allows attackers to bypass perimeter security.

Runtime Rebel Intel
4 min read · Apr 21, 2026