A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud…
Tag: MALWARE
New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used…
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted…
Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis
Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a…
Gigabud Android Trojan Clones Banking Apps
Group-IB researchers have identified a sophisticated Android banking trojan called Gigabud that exploits Android’s work profile feature to conduct…
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly…
New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root…
Peer Pressure: Inside the Sality Botnet Disruption Operation
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Peer Pressure: Inside the Sality Botnet Disruption Operation
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Anthropic reveals how criminal groups are increasingly targeting AI vendors’ own infrastructure, including to steal a pre-release Claude model.
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an…
NetScaler vulnerability exploited, AdaptHealth suffers breach, new Android malware
Critical NetScaler vulnerability exploited in attacks AdaptHealth data breach impacts 4.1 million people MantaxOtax Android malware delivers ransomware…
Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
Cisco Talos has warned that threat actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. These…
Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cisco Talos has confirmed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) Software, with…
Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a…
REVSTEALER Malware Disables Windows Security to Run a Crypto Miner
A new malware campaign associated with the REVSTEALER information stealing malware has been discovered using another four additional malicious programs to…
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities