Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

MA
HIGH
Malware

DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation

DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives. Learn TTPs and defense…

Runtime Rebel Intel
4 min read · Apr 1, 2026
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
HIGH
Malware

WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems

Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…

Runtime Rebel Intel
5 min read · Apr 1, 2026
MA
INFO
Malware

Fileless Malware Registry Persistence Techniques Exposed

Analyzes how fileless malware leverages the Windows registry for persistence, minimizing filesystem footprint and complicating traditional detection. Provides defensive…

Runtime Rebel Intel
4 min read · Apr 1, 2026
DeepLoad Malware Leverages AI for Evasion and Credential Theft
HIGH
Malware

DeepLoad Malware Leverages AI for Evasion and Credential Theft

DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Mar 31, 2026
MA
HIGH
Malware

RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement

Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.

Runtime Rebel Intel
5 min read · Mar 31, 2026
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
HIGH
Malware

DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft

DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.

Runtime Rebel Intel
5 min read · Mar 30, 2026
MA
HIGH
Malware

Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads

Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.

Runtime Rebel Intel
3 min read · Mar 28, 2026
Bearlyfy Targets 70+ Russian Firms with Custom GenieLocker Ransomware
MEDIUM
Malware

Bearlyfy Targets 70+ Russian Firms with Custom GenieLocker Ransomware

Pro-Ukrainian group Bearlyfy deploys GenieLocker ransomware in a campaign targeting over 70 Russian organizations to cause maximum business disruption.

Runtime Rebel Intel
4 min read · Mar 27, 2026
MA
MEDIUM
Malware

ZIP Archive Evasion: Detecting Malicious Multi-File Payloads

Analyze how threat actors use ZIP archives containing over 100,000 files to bypass security inspection and overwhelm automated analysis tools.

Runtime Rebel Intel
4 min read · Mar 27, 2026
Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code
HIGH
Malware

Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code

Kaspersky researchers reveal that the Coruna iOS exploit kit reuses sophisticated kernel exploit code from the 2023 Operation Triangulation campaign.

Runtime Rebel Intel
4 min read · Mar 26, 2026
MA
HIGH
Malware

Torg Grabber Infostealer: Threat to 728 Crypto Wallets

Analysis of Torg Grabber infostealer, detailing its methods for exfiltrating sensitive data from 728 cryptocurrency wallets and 850 browser extensions.

Runtime Rebel Intel
4 min read · Mar 25, 2026
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
HIGH
Malware

GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery

GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.

Runtime Rebel Intel
3 min read · Mar 25, 2026
MA
HIGH
Malware

SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives

Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.

Runtime Rebel Intel
4 min read · Mar 25, 2026
MA
HIGH
Malware

VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol

VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.

Runtime Rebel Intel
3 min read · Mar 22, 2026
MA
HIGH
Malware

GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact

Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.

Runtime Rebel Intel
3 min read · Mar 20, 2026
Speagle Malware Hijacks Cobra DocGuard Infrastructure for Data Theft
HIGH
Malware

Speagle Malware Hijacks Cobra DocGuard Infrastructure for Data Theft

Speagle malware hijacks Cobra DocGuard infrastructure to exfiltrate sensitive data, masking malicious traffic as legitimate software communication.

Runtime Rebel Intel
4 min read · Mar 20, 2026
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
HIGH
Malware

54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers

Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.

Runtime Rebel Intel
3 min read · Mar 19, 2026
Perseus Android Banking Malware Targets Notes Apps for Data Theft
HIGH
Malware

Perseus Android Banking Malware Targets Notes Apps for Data Theft

Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.

Runtime Rebel Intel
3 min read · Mar 19, 2026
MA
HIGH
Malware

Perseus Android Malware: Technical Analysis of Note-Stealing Tactics

Perseus Android malware targets sensitive secrets in user notes by abusing Accessibility Services. Learn how to detect and mitigate this mobile threat.

Runtime Rebel Intel
4 min read · Mar 19, 2026
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
HIGH
Malware

SnappyClient C2 Implant Targets Crypto Wallets for Data Theft

A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.

Runtime Rebel Intel
5 min read · Mar 19, 2026
CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now
HIGH
Malware

CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now

Interlock ransomware actors are exploiting CVE-2026-20131, a critical 10.0 CVSS zero-day in Cisco FMC, to gain unauthenticated root access and deploy malware.

Runtime Rebel Intel
3 min read · Mar 18, 2026
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
MEDIUM
Malware

LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis

LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.

Runtime Rebel Intel
4 min read · Mar 17, 2026
GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions
MEDIUM
Malware

GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions

Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.

Runtime Rebel Intel
4 min read · Mar 17, 2026
MA
HIGH
Malware

Fake Chrome Update Campaigns Deploying NetSupport RAT

Technical analysis of phishing campaigns using JavaScript-injected websites to distribute NetSupport RAT via fake browser update overlays.

Runtime Rebel Intel
4 min read · Mar 16, 2026