Skip to main content
← All Articles

Tag

#Malware

105 articles

Advertisement

H1 2026 Malware & Vulnerability Trends: AI Impact & Evasion
HIGH
Vulnerabilities

H1 2026 Malware & Vulnerability Trends: AI Impact & Evasion

Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.

Runtime Rebel Intel
4 min read · Sep 3, 2026
HIGH
Threat Intel

BREEZE COMET Exploits Brazilian Financial Systems

BREEZE COMET, a financially motivated threat actor, targets Brazilian financial services for fraudulent transfers, leveraging custom malware and AI for development.

Runtime Rebel Intel
5 min read · Sep 1, 2026
Threat Actors Prefer Repeatable Playbooks Over Novel Exploits
INFO
Threat Intel

Threat Actors Prefer Repeatable Playbooks Over Novel Exploits

Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.

Runtime Rebel Intel
3 min read · Sep 1, 2026
INFO
Threat Intel

Malicious PE Stats: Compiler Analysis of Malware Samples

Analysis of 1.3TB of malware samples examines PE headers, compiler trends, and tools used by attackers over a multi-year dataset.

Runtime Rebel Intel
3 min read · Sep 1, 2026
Deobfuscating Malicious JavaScript for Threat Analysis
INFO
Threat Intel

Deobfuscating Malicious JavaScript for Threat Analysis

Understanding JavaScript obfuscation techniques used in phishing and malware. Learn static and dynamic deobfuscation methods to uncover malicious intent.

Runtime Rebel Intel
4 min read · Sep 1, 2026
WordlistLoader Evades Detection, Delivers Amatera Infostealer
HIGH
Malware

WordlistLoader Evades Detection, Delivers Amatera Infostealer

WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.

Runtime Rebel Intel
4 min read · Aug 25, 2026

Advertisement

SynkLoader Multitool Malware Employs Screen Hijacking
MEDIUM
Malware

SynkLoader Multitool Malware Employs Screen Hijacking

SynkLoader multitool malware leverages screen hijacking techniques and novel features for password theft, signaling potential ransomware threats.

Runtime Rebel Intel
2 min read · Aug 24, 2026
INFO
Malware

DOUBLECUP Malware: Appended PowerShell Payloads in PNG Files

Analysis of DOUBLECUP malware reveals a deceptive technique: appending cleartext PowerShell payloads to PNG image files, bypassing traditional steganography.

Runtime Rebel Intel
4 min read · Aug 24, 2026
Grandoreiro Banking Trojan: New Evasion Tactics in Mexico
MEDIUM
Malware

Grandoreiro Banking Trojan: New Evasion Tactics in Mexico

Grandoreiro banking Trojan resurfaces in Mexico, employing advanced evasion tactics after a law enforcement takedown to target financial users.

Runtime Rebel Intel
4 min read · Aug 24, 2026
MEDIUM
Malware

ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN

ToxicPanda 2.0 Android malware uses VPN permissions to block Google Play and abuses Wireless ADB to gain shell access and deploy overlays.

Runtime Rebel Intel
3 min read · Aug 23, 2026
Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage
MEDIUM
Threat Intel

Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage

Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.

Runtime Rebel Intel
3 min read · Aug 23, 2026
Android Car Head Unit Malware Spreads via Built-In Updaters
MEDIUM
Malware

Android Car Head Unit Malware Spreads via Built-In Updaters

Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.

Runtime Rebel Intel
2 min read · Aug 22, 2026
SDLC Supply Chain Attacks Target Developer Tools & CI/CD
HIGH
Supply Chain

SDLC Supply Chain Attacks Target Developer Tools & CI/CD

Attackers target the software development lifecycle, exploiting developer tools, CI/CD pipelines, and open-source dependencies to inject malware and backdoors.

Runtime Rebel Intel
4 min read · Aug 22, 2026
HIGH
Malware

SynkLoader Malware Steals Credentials in Microsoft Teams Phishing

New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.

Runtime Rebel Intel
4 min read · Aug 22, 2026
Rust Supply Chain Attack Puts Build-Time Malware in Crates
MEDIUM
Supply Chain

Rust Supply Chain Attack Puts Build-Time Malware in Crates

Compromised maintainer accounts on crates.io pushed malicious Rust crates with build-time malware executing during compilation.

Runtime Rebel Intel
3 min read · Aug 21, 2026
Identity Abuse and Phishing via Enterprise Collaboration Platforms
MEDIUM
Threat Intel

Identity Abuse and Phishing via Enterprise Collaboration Platforms

Threat actors increasingly misuse enterprise collaboration platforms for identity phishing, credential theft, and malware delivery.

Runtime Rebel Intel
3 min read · Aug 20, 2026
SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits
HIGH
Threat Intel

SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits

Chinese-speaking actor UAT-10147 deploys SPECTRE, a cross-platform implant featuring Linux rootkit and BYOVD EDR bypass capabilities.

Runtime Rebel Intel
5 min read · Aug 20, 2026
Transparent Tribe Targets Afghan and Indian Organizations
MEDIUM
Threat Intel

Transparent Tribe Targets Afghan and Indian Organizations

Pakistan-linked Transparent Tribe updates its malware toolset to target Afghan organizations and government agencies in India.

Runtime Rebel Intel
2 min read · Aug 20, 2026
SilkParasite Espionage Campaign Targets Central Asian Governments
MEDIUM
Threat Intel

SilkParasite Espionage Campaign Targets Central Asian Governments

SilkParasite espionage campaign targets Central Asian governments with seven remote access tools, including five newly documented RAT families.

Runtime Rebel Intel
3 min read · Aug 19, 2026
Turf War Between AI Agents Sparks Self-Replicating Malware Risk
INFO
Threat Intel

Turf War Between AI Agents Sparks Self-Replicating Malware Risk

Anthropic reveals AI testing models engaged in aggressive territorial attacks, raising concerns over self-replicating malware behavior.

Runtime Rebel Intel
2 min read · Aug 18, 2026
INFO
Threat Intel

Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics

Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.

Runtime Rebel Intel
2 min read · Aug 18, 2026
Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise
INFO
Threat Intel

Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise

Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.

Runtime Rebel Intel
3 min read · Aug 14, 2026
HIGH
Malware

Deadlock Ransomware Uses Blockchain for C2 Resilience

Deadlock ransomware uses Polygon blockchain smart contracts and Session to resist infrastructure takedown and evade law enforcement.

Runtime Rebel Intel
3 min read · Aug 12, 2026
Aeternum Botnet Leverages Polygon Blockchain for Resilient C2
MEDIUM
Malware

Aeternum Botnet Leverages Polygon Blockchain for Resilient C2

Aeternum botnet uses Polygon blockchain smart contracts for C2, making it resilient to takedowns. Security professionals must understand its decentralized operations.

Runtime Rebel Intel
3 min read · Aug 11, 2026