Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

HIGH
Malware

Malicious Crypto Wallets Infiltrate China's Apple App Store

26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.

Runtime Rebel Intel
4 min read · Apr 21, 2026
MEDIUM
Malware

Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions

Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.

Runtime Rebel Intel
3 min read · Apr 17, 2026
HIGH
Malware

Lumma Stealer and Sectop RAT Dual Infection Chain Analysis

Technical breakdown of the Lumma Stealer and Sectop RAT (ArechClient2) infection chain, detailing C2 communication and persistence mechanisms.

Runtime Rebel Intel
3 min read · Apr 17, 2026
MEDIUM
Malware

PDF JavaScript Exploitation: Analysis of PowerShell Delivery

Technical analysis of malicious PDF documents using embedded JavaScript and /OpenAction triggers to execute PowerShell for initial access and C2 establishment.

Runtime Rebel Intel
4 min read · Apr 17, 2026
Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion
HIGH
Malware

Dragon Boss Adware Evolves: Scheduled Tasks & Windows Defender Evasion

Dragon Boss adware transforms into a persistent AV killer, using scheduled tasks to establish presence and disable Windows Defender protections on infected systems.

Runtime Rebel Intel
5 min read · Apr 17, 2026
HIGH
Malware

Analyzing ZionSiphon: Malware Targeting Water Treatment OT Systems

Investigate ZionSiphon malware, an OT-specific threat designed to sabotage water treatment and desalination facilities.

Runtime Rebel Intel
5 min read · Apr 17, 2026

Advertisement

HIGH
Malware

Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware

Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.

Runtime Rebel Intel
3 min read · Apr 16, 2026
MEDIUM
Malware

SVG File Phishing: How Attackers Hide Malicious JavaScript in Images

Discover how attackers use Scalable Vector Graphics (SVG) to embed malicious JavaScript for phishing and credential theft while bypassing security filters.

Runtime Rebel Intel
3 min read · Apr 16, 2026
HIGH
Malware

AgingFly Malware: Credential Theft Operations Against Ukraine

Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…

Runtime Rebel Intel
5 min read · Apr 16, 2026
HIGH
Malware

Signed Software Abuse: How Malicious Scripts Disable EDR and AV

Analysis of signed adware being used to deploy antivirus-killing scripts with SYSTEM privileges across government and healthcare sectors.

Runtime Rebel Intel
4 min read · Apr 15, 2026
HIGH
Malware

Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse

Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.

Runtime Rebel Intel
4 min read · Apr 15, 2026
Mirax Android RAT: Bypassing Security via Malicious Meta Ads
HIGH
Malware

Mirax Android RAT: Bypassing Security via Malicious Meta Ads

Mirax Android RAT targets 220,000 users via Meta Ads, turning devices into SOCKS5 proxies. Learn to detect and mitigate this emerging mobile threat.

Runtime Rebel Intel
3 min read · Apr 14, 2026
JanelaRAT Malware Analysis: 14,000+ Attacks Target Latin American Banks
HIGH
Malware

JanelaRAT Malware Analysis: 14,000+ Attacks Target Latin American Banks

Analyze the JanelaRAT campaign targeting Brazil and Mexico. Learn how this BX RAT variant steals financial data and how to detect JanelaRAT attacks.

Runtime Rebel Intel
3 min read · Apr 13, 2026
HIGH
Malware

Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide

Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.

Runtime Rebel Intel
4 min read · Apr 13, 2026
HIGH
Malware

Storm Infostealer: Bypassing Local Decryption for Session Hijacking

Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.

Runtime Rebel Intel
3 min read · Apr 13, 2026
MEDIUM
Malware

Detect Obfuscated JavaScript Phishing Delivered via RAR Archives

Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Malware

LucidRook Malware Targets Taiwan NGOs via DLL Side-Loading

Analysis of the Lua-based LucidRook malware targeting Taiwanese NGOs and universities through spear-phishing and sophisticated DLL side-loading techniques.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Malware

Magecart Skimmer Hides in Pixel-Sized SVG on Magento Stores

A sophisticated Magecart campaign targets nearly 100 Magento stores, concealing credit card-stealing JavaScript within tiny, pixel-sized SVG images.

Runtime Rebel Intel
5 min read · Apr 9, 2026
Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns
HIGH
Malware

Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns

The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.

Runtime Rebel Intel
4 min read · Apr 8, 2026
Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy
HIGH
Malware

Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy

A new variant of Chaos malware targets misconfigured cloud deployments, leveraging SOCKS proxy capabilities to expand botnet infrastructure beyond edge devices.

Runtime Rebel Intel
4 min read · Apr 8, 2026
HIGH
Malware

Masjesu Botnet: Stealthy DDoS Malware Targets Linux IoT Devices

Masjesu is a highly evasive DDoS botnet targeting Linux IoT devices. It prioritizes persistence and avoids critical infrastructure to remain undetected.

Runtime Rebel Intel
4 min read · Apr 8, 2026
HIGH
Malware

Medusa Ransomware: Rapid Vulnerability Weaponization and Analysis

An analysis of Medusa ransomware's rapid exploitation of vulnerabilities and Zero-Day bugs to exfiltrate and encrypt data within days of initial access.

Runtime Rebel Intel
4 min read · Apr 7, 2026
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
HIGH
Malware

Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD

Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.

Runtime Rebel Intel
3 min read · Apr 6, 2026
SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases
HIGH
Malware

SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases

A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.

Runtime Rebel Intel
6 min read · Apr 3, 2026