New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Tag: MALWARE
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Windows users looking for a familiar cleanup utility are being steered toward a convincing counterfeit download page. The file they receive installs…
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
A new Android fraud operation shows how quickly a convincing phone call can turn into financial loss. The campaign combines the SpyNote remote-control…
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
CAV3RN is a modular espionage framework that is becoming harder to see on a network. Its newest communication component hides remote-control traffic…
Google Chrome Blocks Abusive Notifications Used to Deliver Malware and Scams
Google Chrome has implemented enhanced defenses aimed at disrupting abusive web push notifications that are often used to distribute malware, phishing…
Malicious CCleaner Installer Patches Chrome Security Extension to Deploy Browser Spyware
A counterfeit installer for the widely used PC-cleaning utility CCleaner is being used to compromise Windows systems and deploy a malicious Chrome…
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Sandworm has turned the routine job interview into a route for compromising IT workers. The campaign uses convincing recruiter conversations, live video…
Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and…
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant…
Fake CCleaner installs GhostDesk Chrome spyware
A convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome.
Kimsuky Brings AI Closer to Its Malware and Phishing Operations
North Korean cyber-espionage group Kimsuky appears to be moving beyond occasional use of public AI services by assembling a local artificial intelligence…
Hackers Hide Malware Infrastructure on Polygon Blockchain and Trick Users Into Running It With ClickFix
Hackers are using the Polygon blockchain to keep parts of a malware operation out of plain sight. The campaign, tracked as ErrTraffic, turns hacked…
Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware
Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote…
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and…
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
GitHub Expands Supply Chain Malware Detection From npm to 8 Package Registries
GitHub has expanded its malware detection capabilities beyond npm, providing developers with broader protection against malicious open-source packages.…
Fake The Odyssey Downloads Are Hiding Password-Stealing Malware
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
Android users are facing a fresh reminder that a familiar app-store listing can hide a financial threat. Researchers have observed malicious loaders on…
Meccha Chameleon Vulnerability Allowed Malware to Spread Through Steam Workshop Maps
A security vulnerability in the game Meccha Chameleon enabled malicious custom maps stored on Steam Workshop to infect users with malware. The…
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running…