Skip to main content
← All Articles

Category

Malware

219 articles

Advertisement

MA
HIGH
Malware

SmartApeSG Leverages ClickFix Pages to Deploy Remcos RAT

Analysis of the SmartApeSG campaign, detailing its use of deceptive 'ClickFix' pages to distribute Remcos RAT. Learn about RAT capabilities and general mitigation…

Runtime Rebel Intel
4 min read · Mar 14, 2026
MA
HIGH
Malware

FBI Seeks Victims of Malicious Steam Games Stealing Credentials

The FBI is investigating eight malicious games on Steam that stole user credentials from tens of thousands of players. Learn how to identify and report compromised…

Runtime Rebel Intel
5 min read · Mar 14, 2026
MA
HIGH
Malware

AI-Generated Slopoly Malware Linked to Interlock Ransomware Attacks

Analysis of the AI-generated Slopoly malware and its role in Interlock ransomware operations, including technical details and detection strategies.

Runtime Rebel Intel
4 min read · Mar 12, 2026
Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access
HIGH
Malware

Hive0163 Deploys AI-Assisted Slopoly Malware for Persistent Access

The Hive0163 threat actor is leveraging Slopoly, an AI-generated malware framework, to maintain persistence in ransomware campaigns and financial theft operations.

Runtime Rebel Intel
4 min read · Mar 12, 2026
VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks
HIGH
Malware

VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks

A new Rust-based malware called VENON is targeting 33 Brazilian banks with credential-stealing overlays, signaling a shift in Latin American cybercrime TTPs.

Runtime Rebel Intel
4 min read · Mar 12, 2026
MA
HIGH
Malware

BeatBanker Android Malware: Starlink Impersonation & Device Hijack

New BeatBanker Android malware impersonates the Starlink app on fake app stores to hijack devices, targeting unsuspecting users. Learn detection & mitigation.

Runtime Rebel Intel
4 min read · Mar 11, 2026
BlackSanta Malware Targets HR Workflows to Disable EDR Systems
HIGH
Malware

BlackSanta Malware Targets HR Workflows to Disable EDR Systems

Russian-speaking threat actors deploy BlackSanta malware via hijacked HR workflows to terminate EDR agents and facilitate undetected data exfiltration.

Runtime Rebel Intel
3 min read · Mar 10, 2026
MA
HIGH
Malware

KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network

The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.

Runtime Rebel Intel
4 min read · Mar 10, 2026
KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet
HIGH
Malware

KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet

KadNap malware has compromised over 14,000 edge devices, primarily Asus routers, to create a massive proxy botnet for anonymizing malicious traffic.

Runtime Rebel Intel
4 min read · Mar 10, 2026
MA
HIGH
Malware

Quasar RAT Delivery via Malicious PDF and LNK Files

Technical analysis of a multi-stage infection chain using PDF lures and LNK files to deploy Quasar RAT, including detection and mitigation strategies.

Runtime Rebel Intel
3 min read · Mar 10, 2026
MA
HIGH
Malware

InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers

The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.

Runtime Rebel Intel
4 min read · Mar 9, 2026
VOID#GEIST Malware: Multi-Stage Delivery of AsyncRAT and XWorm
MEDIUM
Malware

VOID#GEIST Malware: Multi-Stage Delivery of AsyncRAT and XWorm

Securonix identifies VOID#GEIST, a stealthy multi-stage malware campaign using obfuscated batch scripts to deliver XWorm, AsyncRAT, and Xeno RAT payloads.

Runtime Rebel Intel
3 min read · Mar 6, 2026
MA
HIGH
Malware

Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers

Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.

Runtime Rebel Intel
4 min read · Mar 6, 2026
MA
HIGH
Malware

Coruna iOS Exploit Kit: Spyware-Grade Threat Targets Crypto

The sophisticated Coruna iOS exploit kit, leveraging 23 undocumented vulnerabilities, is now deployed in targeted espionage and crypto theft attacks.

Runtime Rebel Intel
5 min read · Mar 4, 2026
Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits
HIGH
Malware

Coruna iOS Exploit Kit Targets iOS 13-17.2.1 with 23 Exploits

Google's GTIG identified Coruna (CryptoWaters), a powerful iOS exploit kit leveraging 23 exploits across 5 chains to target iOS 13.0-17.2.1. Update immediately.

Runtime Rebel Intel
4 min read · Mar 4, 2026
MA
MEDIUM
Malware

XWorm RAT Delivery: Analyzing Multi-Stage Infection Chains

New XWorm malware waves utilize multi-technology delivery involving LNK files and PowerShell. Learn how to detect and mitigate XWorm RAT infections.

Runtime Rebel Intel
3 min read · Mar 4, 2026
MA
MEDIUM
Malware

Analyzing Embedded ZIP Payloads in RTF Documents for Malware Analysis

Learn how to detect ZIP files in RTF documents and extract hex-encoded binary payloads using specialized forensic tools to identify hidden malware threats.

Runtime Rebel Intel
4 min read · Mar 2, 2026
MA
HIGH
Malware

QuickLens Chrome Extension Hijacked to Deploy ClickFix Malware

Malicious QuickLens Chrome extension removed from Web Store after stealing cryptocurrency and deploying ClickFix malware to 30,000 users.

Runtime Rebel Intel
3 min read · Feb 28, 2026
MA
MEDIUM
Malware

Phishing Campaign Leverages Donut Loader via Spoofed FedEx Alerts

Analysis of a phishing campaign using fake FedEx delivery notifications to deliver the Donut loader framework for in-memory shellcode execution.

Runtime Rebel Intel
4 min read · Feb 27, 2026
MA
HIGH
Malware

CISA Warns of RESURGE Malware Persistence on Ivanti Devices

CISA details RESURGE, a sophisticated implant exploiting CVE-2025-0282 in Ivanti Connect Secure, capable of remaining dormant to bypass detection and recovery.

Runtime Rebel Intel
4 min read · Feb 27, 2026
MA
HIGH
Malware

Aeternum Loader Employs Polygon Blockchain for Resilient C2

Analysis of the Aeternum botnet loader, which utilizes Polygon smart contracts to host decentralized command-and-control infrastructure for resilience.

Runtime Rebel Intel
4 min read · Feb 27, 2026
Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell
HIGH
Malware

Trojanized Gaming Tools Deliver Java-Based RAT via PowerShell

Security researchers identify a malware campaign using trojanized gaming tools to deliver a Java-based RAT using PowerShell and portable Java runtimes.

Runtime Rebel Intel
4 min read · Feb 27, 2026
Aeternum C2 Leverages Polygon Blockchain for Command-and-Control
HIGH
Malware

Aeternum C2 Leverages Polygon Blockchain for Command-and-Control

Aeternum C2 loader uses the Polygon blockchain to store encrypted instructions, creating a decentralized infrastructure resilient to traditional takedowns.

Runtime Rebel Intel
3 min read · Feb 26, 2026
MA
MEDIUM
Malware

Arkanix Stealer: Rapid Disappearance of C++ & Python Malware

Arkanix Stealer, a C++ and Python-based info-stealer, emerged briefly, exfiltrating system data, browser credentials, and files before vanishing. Analysis of its TTPs.

Runtime Rebel Intel
4 min read · Feb 25, 2026