Advertisement
REVSTEALER Modules Disable Defenses, Deploy Miner, Steal Data
Elastic Security unveils four REVSTEALER-linked modules that disable Windows defenses, deploy crypto miners, and exfiltrate sensitive user data.
Solidity Pro VS Code Extensions Steal Crypto Wallets & Credentials
Malicious 'Solidity Pro' VS Code extensions steal crypto wallets, API keys, and credentials, using delayed activation to evade detection. Immediate removal is advised.
Bing Ads Promote Fake Claude App, Deliver SectopRAT Malware
A malvertising campaign on Bing Search is distributing a fake Claude AI desktop app, leading to SectopRAT malware infections. Verify software sources.
ClickLock macOS Malware: Password Theft via Forced Login Prompt
ClickLock macOS malware terminates processes, simulating a system crash to force users into revealing their login password.
CrashStealer: New macOS Info Stealer Bypasses Gatekeeper via Notarization
CrashStealer macOS malware leverages C++ and notarized droppers to evade security checks and exfiltrate validated credentials from compromised Apple devices.
Veil#Drop Attacks Deploy PureLog Info Stealer via Blogspot & PowerShell
Analysis of Veil#Drop attacks, a sophisticated framework abusing Blogspot and PowerShell to deploy PureLog information stealer with fileless techniques and evasion.
Advertisement
OXLOADER Analysis: Malicious Google Ads Deliver CastleStealer Malware
Researchers have identified OXLOADER, a new malware loader using malicious Google Ads to distribute the CastleStealer information stealer to Windows users.
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.
UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware
UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.
CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware
CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…
GlassWorm Malware Uses Solana Dead Drops for Stealthy C2 Delivery
GlassWorm evolves to use Solana blockchain metadata for C2 infrastructure, deploying a RAT and a malicious Google Docs Chrome extension to steal crypto data.