Friday, August 28, 2026
Follow on LinkedIn

Malware

GhostContainer Malware Hacking Exchange Servers in the Wild Using N-day Vulnerability

A highly sophisticated malware campaign targeting Microsoft Exchange servers in government and high-tech organizations across Asia.  The malware, dubbed GhostContainer, exploits known N-day vulnerabilities to establish persistent backdoor access to critical infrastructure. Key Takeaways1. GhostContainer uses CVE-2020-0688 vulnerability to create persistent...

New AsyncRAT Forks Unveiled with Features from Screamer to USB Malware Spreader

A comprehensive analysis of AsyncRAT's expanding ecosystem, revealing a labyrinthine network of malware variants that have evolved far beyond the original remote access trojan's capabilities.  The open-source nature of AsyncRAT, first released on GitHub in 2019, has spawned numerous sophisticated...

SparkKitty Malware Attacking iOS and Android Device Users to Steal Photos From Gallery

A sophisticated Trojan malware known as SparkKitty has been actively targeting iOS and Android devices since early 2024, infiltrating both official app stores and untrusted websites to steal images from users' device galleries. This malware campaign, which appears to...

Anatsa Android Banking Malware from Google Play Targeting Users in the U.S. and Canada

ThreatFabric researchers have identified a sophisticated new campaign by the Anatsa banking trojan specifically targeting mobile banking customers across the United States and Canada, marking the malware's third major offensive against North American financial institutions. The latest campaign represents a...

Weaponized Chrome Extension from Webstore With Verification Badge Infected 1.7 Million Users

A sophisticated malware campaign has infected over 1.7 million Chrome users through eleven seemingly legitimate browser extensions, all of which carried Google's verified badge and featured placement on the Chrome Web Store. The "Malicious11" campaign, discovered by cybersecurity researchers...

Atomic macOS Info-Stealer Upgraded With New Backdoor to Maintain Persistence

The notorious Atomic macOS Stealer (AMOS) malware has received a dangerous upgrade that significantly escalates the threat to Mac users worldwide. For the first time, this Russia-affiliated stealer is being deployed with an embedded backdoor, allowing attackers to maintain...

Weaponized Versions of PuTTY and WinSCP Attacking IT Admins Via Search Results

A sophisticated SEO poisoning campaign targeting system administrators with malicious backdoor malware. Arctic Wolf security researchers have uncovered a dangerous search engine optimization (SEO) poisoning and malvertising campaign that has been targeting IT professionals since early June 2025. The campaign uses...

New Slopsquatting Attack Leverage Coding Agents Workflows to Deliver Malware

Researchers have identified a sophisticated new supply-chain threat targeting AI-powered development workflows, where malicious actors exploit coding agents' tendency to "hallucinate" non-existent package names to distribute malware. This emerging attack vector, dubbed "slopsquatting," represents an evolution of traditional typosquatting...

NightEagle APT Attacking Industrial Systems by Exploiting 0-Days and With Adaptive Malware

A sophisticated APT group dubbed "NightEagle" (APT-Q-95) has been conducting targeted attacks against China's critical technology sectors since 2023.  The group has demonstrated exceptional capabilities in exploiting unknown Exchange vulnerabilities and deploying adaptive malware to steal sensitive intelligence from high-tech...

New “123 | Stealer” Advertised on Underground Hacking Forums for $120 Per Month

A new credential-stealing malware dubbed "123 | Stealer" has surfaced on underground cybercrime forums, being marketed by threat actor "koneko" for $120 per month.  This malware-as-a-service (MaaS) offering represents the latest evolution in information stealer technology, combining sophisticated data exfiltration...

Latest News

Latest News