Advertisement
Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak
Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…
Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America
Analyzing Casbaneiro, a sophisticated banking Trojan employing advanced evasion, process injection, and network worming to target financial institutions and users in…
Ransomware Preparation: Healthcare Facilities' Defense Strategy
Hospitals face inevitable ransomware attacks. Learn why proactive incident response planning, regular rehearsals, and robust technical controls are crucial for defense.
CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware
CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…
NoVoice Android Malware on Google Play: 2.3 Million Devices Infected
NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.
Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks
Analyze Venom Stealer MaaS, a new cybercrime platform enabling automated, persistent information-stealing through social engineering 'ClickFix' attacks.
Advertisement
DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation
DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives.
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…
Fileless Malware Registry Persistence Techniques Exposed
Analyzes how fileless malware leverages the Windows registry for persistence, minimizing filesystem footprint and complicating traditional detection.
DeepLoad Malware Leverages AI for Evasion and Credential Theft
DeepLoad, an AI-powered malware, uses massive junk code to evade detection while stealing credentials. Learn its TTPs and mitigation strategies.
RoadK1ll WebSocket Implant: New Threat for Stealthy Lateral Movement
Analysis of the new RoadK1ll WebSocket implant, detailing its capabilities for lateral movement on compromised networks and offering detection and mitigation strategies.
DeepLoad Malware Leverages ClickFix, WMI for Browser Credential Theft
DeepLoad malware leverages ClickFix social engineering and WMI for persistence to steal browser credentials, employing AI-assisted obfuscation for evasion.
Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads
Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.
Bearlyfy Targets 70+ Russian Firms with Custom GenieLocker Ransomware
Pro-Ukrainian group Bearlyfy deploys GenieLocker ransomware in a campaign targeting over 70 Russian organizations to cause maximum business disruption.
ZIP Archive Evasion: Detecting Malicious Multi-File Payloads
Analyze how threat actors use ZIP archives containing over 100,000 files to bypass security inspection and overwhelm automated analysis tools.
Coruna iOS Kit Reuses Operation Triangulation Kernel Exploit Code
Kaspersky researchers reveal that the Coruna iOS exploit kit reuses sophisticated kernel exploit code from the 2023 Operation Triangulation campaign.
Torg Grabber Infostealer: Threat to 728 Crypto Wallets
Analysis of Torg Grabber infostealer, detailing its methods for exfiltrating sensitive data from 728 cryptocurrency wallets and 850 browser extensions.
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.
SmartApeSG Campaign: Multi-RAT Distribution via Malicious Archives
Analysis of the SmartApeSG campaign leveraging phishing, LNK files, and scripts to distribute Remcos RAT, NetSupport RAT, StealC, and Sectop RAT. Learn mitigation.
VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol
VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.
GSocket Backdoor Analysis: Malicious Bash Script Delivery and Impact
Analysis of a malicious Bash script deploying the GSocket backdoor for persistent access, bypassing firewalls through advanced NAT traversal techniques.
Speagle Malware Hijacks Cobra DocGuard Infrastructure for Data Theft
Speagle malware hijacks Cobra DocGuard infrastructure to exfiltrate sensitive data, masking malicious traffic as legitimate software communication.
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.
Perseus Android Banking Malware Targets Notes Apps for Data Theft
Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.