Advertisement
DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation
DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives. Learn TTPs and defense…
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…
Fileless Malware Registry Persistence Techniques Exposed
Analyzes how fileless malware leverages the Windows registry for persistence, minimizing filesystem footprint and complicating traditional detection. Provides defensive…
DeepLoad Malware Leverages AI for Evasion and Credential Theft
DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.
RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement
Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.
Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads
Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.
Bearlyfy Targets 70+ Russian Firms with Custom GenieLocker Ransomware
Pro-Ukrainian group Bearlyfy deploys GenieLocker ransomware in a campaign targeting over 70 Russian organizations to cause maximum business disruption.
ZIP Archive Evasion: Detecting Malicious Multi-File Payloads
Analyze how threat actors use ZIP archives containing over 100,000 files to bypass security inspection and overwhelm automated analysis tools.
Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code
Kaspersky researchers reveal that the Coruna iOS exploit kit reuses sophisticated kernel exploit code from the 2023 Operation Triangulation campaign.
Torg Grabber Infostealer: Threat to 728 Crypto Wallets
Analysis of Torg Grabber infostealer, detailing its methods for exfiltrating sensitive data from 728 cryptocurrency wallets and 850 browser extensions.
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.
SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives
Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.
VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol
VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.
GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact
Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.
Speagle Malware Hijacks Cobra DocGuard Infrastructure for Data Theft
Speagle malware hijacks Cobra DocGuard infrastructure to exfiltrate sensitive data, masking malicious traffic as legitimate software communication.
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.
Perseus Android Banking Malware Targets Notes Apps for Data Theft
Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.
Perseus Android Malware: Technical Analysis of Note-Stealing Tactics
Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.
CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now
Interlock ransomware actors are exploiting CVE-2026-20131, a critical 10.0 CVSS zero-day in Cisco FMC, to gain unauthenticated root access and deploy malware.
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.
GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions
Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.
Fake Chrome Update Campaigns Deploying NetSupport RAT
Technical analysis of phishing campaigns using JavaScript-injected websites to distribute NetSupport RAT via fake browser update overlays.