Skip to main content
← All Articles

Category

Malware

249 articles

Advertisement

HIGH
Malware

Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak

Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…

Runtime Rebel Intel
4 min read · Apr 3, 2026
Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America
HIGH
Malware

Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America

Analyzing Casbaneiro, a sophisticated banking Trojan employing advanced evasion, process injection, and network worming to target financial institutions and users in…

Runtime Rebel Intel
4 min read · Apr 2, 2026
Ransomware Preparation: Healthcare Facilities' Defense Strategy
MEDIUM
Malware

Ransomware Preparation: Healthcare Facilities' Defense Strategy

Hospitals face inevitable ransomware attacks. Learn why proactive incident response planning, regular rehearsals, and robust technical controls are crucial for defense.

Runtime Rebel Intel
4 min read · Apr 2, 2026
HIGH
Malware

CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware

CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…

Runtime Rebel Intel
5 min read · Apr 2, 2026
HIGH
Malware

NoVoice Android Malware on Google Play: 2.3 Million Devices Infected

NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.

Runtime Rebel Intel
5 min read · Apr 1, 2026
Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks
HIGH
Malware

Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks

Analyze Venom Stealer MaaS, a new cybercrime platform enabling automated, persistent information-stealing through social engineering 'ClickFix' attacks.

Runtime Rebel Intel
4 min read · Apr 1, 2026

Advertisement

HIGH
Malware

DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation

DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.

Runtime Rebel Intel
4 min read · Apr 1, 2026
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
HIGH
Malware

WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems

Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…

Runtime Rebel Intel
5 min read · Apr 1, 2026
INFO
Malware

Fileless Malware Registry Persistence Techniques Exposed

Analyzes how fileless malware leverages the Windows registry for persistence, minimizing filesystem footprint and complicating traditional detection.

Runtime Rebel Intel
4 min read · Apr 1, 2026
DeepLoad Malware Leverages AI for Evasion and Credential Theft
HIGH
Malware

DeepLoad Malware Leverages AI for Evasion and Credential Theft

DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Mar 31, 2026
HIGH
Malware

RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement

Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.

Runtime Rebel Intel
5 min read · Mar 31, 2026
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
HIGH
Malware

DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft

DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.

Runtime Rebel Intel
5 min read · Mar 30, 2026
HIGH
Malware

Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads

Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.

Runtime Rebel Intel
3 min read · Mar 28, 2026
Bearlyfy Targets 70+ Russian Firms with Custom GenieLocker Ransomware
MEDIUM
Malware

Bearlyfy Targets 70+ Russian Firms with Custom GenieLocker Ransomware

Pro-Ukrainian group Bearlyfy deploys GenieLocker ransomware in a campaign targeting over 70 Russian organizations to cause maximum business disruption.

Runtime Rebel Intel
4 min read · Mar 27, 2026
MEDIUM
Malware

ZIP Archive Evasion: Detecting Malicious Multi-File Payloads

Analyze how threat actors use ZIP archives containing over 100,000 files to bypass security inspection and overwhelm automated analysis tools.

Runtime Rebel Intel
4 min read · Mar 27, 2026
Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code
HIGH
Malware

Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code

Kaspersky researchers reveal that the Coruna iOS exploit kit reuses sophisticated kernel exploit code from the 2023 Operation Triangulation campaign.

Runtime Rebel Intel
4 min read · Mar 26, 2026
HIGH
Malware

Torg Grabber Infostealer: Threat to 728 Crypto Wallets

Analysis of Torg Grabber infostealer, detailing its methods for exfiltrating sensitive data from 728 cryptocurrency wallets and 850 browser extensions.

Runtime Rebel Intel
4 min read · Mar 25, 2026
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
HIGH
Malware

GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery

GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.

Runtime Rebel Intel
3 min read · Mar 25, 2026
HIGH
Malware

SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives

Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.

Runtime Rebel Intel
4 min read · Mar 25, 2026
HIGH
Malware

VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol

VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.

Runtime Rebel Intel
3 min read · Mar 22, 2026
HIGH
Malware

GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact

Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.

Runtime Rebel Intel
3 min read · Mar 20, 2026
Speagle Malware Hijacks Cobra DocGuard Infrastructure for Data Theft
HIGH
Malware

Speagle Malware Hijacks Cobra DocGuard Infrastructure for Data Theft

Speagle malware hijacks Cobra DocGuard infrastructure to exfiltrate sensitive data, masking malicious traffic as legitimate software communication.

Runtime Rebel Intel
4 min read · Mar 20, 2026
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
HIGH
Malware

54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers

Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.

Runtime Rebel Intel
3 min read · Mar 19, 2026
Perseus Android Banking Malware Targets Notes Apps for Data Theft
HIGH
Malware

Perseus Android Banking Malware Targets Notes Apps for Data Theft

Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.

Runtime Rebel Intel
3 min read · Mar 19, 2026