A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick researchers rarely see in the wild: when an infected phone has no internet connection of its own, it can...
A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to authenticate to Microsoft Entra ID, enabling attackers to gain cloud access without the victim’s password, PIN,...
A newly discovered remote access Trojan called MedusaHVNC lets attackers open a hidden virtual desktop on a victim's own computer, quietly loading their real browser profile, cookies, and logged-in sessions without any visible sign of intrusion.
Sold as malware-as-a-service through...
Cybercriminals continued to lean on a familiar arsenal of malware last week, with information stealers and remote access trojans (RATs) dominating the threat landscape as the primary tools for initial access, credential theft, and long-term system control.
Topping the list...
A large-scale malware campaign has been uncovered on GitHub after a researcher identified more than 10,000 repositories distributing Trojan-laced archives, raising concerns about abuse of the platform’s trust model and limitations in automated detection.
The investigation began when the researcher...
Hackers are increasingly abusing trusted enterprise platforms such as Microsoft Teams and Google Drive to deploy stealthy remote access malware, with a newly observed campaign leveraging social engineering and cloud-based command-and-control to evade detection.
In early April 2026, eSentire’s Threat...
Gamaredon, a Russian state-backed espionage group, is deploying a new VBScript worm that hides inside native Windows features while using popular cloud services as covert command-and-control (C2) channels in an ongoing campaign against Ukrainian targets.
The operation showcases a modular...
New Android malware dubbed BTMOB is arming even low-skilled attackers with full remote control over infected phones by combining a powerful RAT engine with a no-code campaign builder toolkit.
The threat, first seen in 2025, is now evolving rapidly through...
A financially motivated threat actor known as Fox Tempest has been operating a sophisticated malware-signing-as-a-service (MSaaS) platform that abused Microsoft’s Artifact Signing infrastructure to generate trusted digital signatures for malicious code.
This activity enabled cybercriminals to bypass security controls and...
A large-scale international cybercrime crackdown dubbed Operation Ramz has led to the seizure of 53 servers, the arrest of 201 individuals, and the identification of 382 additional suspects across the Middle East and North Africa (MENA) region.
The coordinated operation, led...