A highly sophisticated malware campaign targeting Microsoft Exchange servers in government and high-tech organizations across Asia.
The malware, dubbed GhostContainer, exploits known N-day vulnerabilities to establish persistent backdoor access to critical infrastructure.
Key Takeaways1. GhostContainer uses CVE-2020-0688 vulnerability to create persistent...
A comprehensive analysis of AsyncRAT's expanding ecosystem, revealing a labyrinthine network of malware variants that have evolved far beyond the original remote access trojan's capabilities.
The open-source nature of AsyncRAT, first released on GitHub in 2019, has spawned numerous sophisticated...
A sophisticated Trojan malware known as SparkKitty has been actively targeting iOS and Android devices since early 2024, infiltrating both official app stores and untrusted websites to steal images from users' device galleries.
This malware campaign, which appears to...
ThreatFabric researchers have identified a sophisticated new campaign by the Anatsa banking trojan specifically targeting mobile banking customers across the United States and Canada, marking the malware's third major offensive against North American financial institutions.
The latest campaign represents a...
A sophisticated malware campaign has infected over 1.7 million Chrome users through eleven seemingly legitimate browser extensions, all of which carried Google's verified badge and featured placement on the Chrome Web Store.
The "Malicious11" campaign, discovered by cybersecurity researchers...
The notorious Atomic macOS Stealer (AMOS) malware has received a dangerous upgrade that significantly escalates the threat to Mac users worldwide.
For the first time, this Russia-affiliated stealer is being deployed with an embedded backdoor, allowing attackers to maintain...
A sophisticated SEO poisoning campaign targeting system administrators with malicious backdoor malware.
Arctic Wolf security researchers have uncovered a dangerous search engine optimization (SEO) poisoning and malvertising campaign that has been targeting IT professionals since early June 2025.
The campaign uses...
Researchers have identified a sophisticated new supply-chain threat targeting AI-powered development workflows, where malicious actors exploit coding agents' tendency to "hallucinate" non-existent package names to distribute malware.
This emerging attack vector, dubbed "slopsquatting," represents an evolution of traditional typosquatting...
A sophisticated APT group dubbed "NightEagle" (APT-Q-95) has been conducting targeted attacks against China's critical technology sectors since 2023.
The group has demonstrated exceptional capabilities in exploiting unknown Exchange vulnerabilities and deploying adaptive malware to steal sensitive intelligence from high-tech...
A new credential-stealing malware dubbed "123 | Stealer" has surfaced on underground cybercrime forums, being marketed by threat actor "koneko" for $120 per month.
This malware-as-a-service (MaaS) offering represents the latest evolution in information stealer technology, combining sophisticated data exfiltration...