The FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments.
Tag: MALWARE
LightSpy Spyware Expands Global Reach, Targeting Devices Across More Than a Dozen Countries
Cybersecurity researchers have uncovered new evidence suggesting that the Chinese-linked LightSpy spyware operation has expanded significantly, with…
AI Speeds Up Malware Development, Not Its Success Rate: Analysis
Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool
Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware
Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access…
Spyware for Babies
The New York Times has a long article ( alt link ) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to…
Beware of fake Indeed interview apps used to install spyware
Scammers are posing as employers on Indeed to trick job seekers into installing fake Android interview apps that deliver malware.
New CoreRAT Malware Gives Core Werewolf Hackers Full Control of Compromised Systems
A new remote access trojan called CoreRAT is giving the Core Werewolf threat group a way to take over infected Windows systems. The malware appeared in…
Hackers Hide Malware Inside Plain English Words to Infect Windows Users With Amatera Stealer
Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The…
Core Werewolf Hackers Deploy New CoreRAT Malware Against Russian Government and Defense Organizations
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian…
Android Car Systems Infected With Malware Through Software Updates
Kaspersky uncovered malware spreading via software updates on Android-based car head units, turning infected systems into proxy nodes in a botnet.
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text,…
ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps
ToxicPanda 2.0 now targets 349 financial apps across 16 countries while abusing VPN, Accessibility and Android debugging features for deeper control.
That fake Grand Theft Auto VI demo is actually just malware
Grand Theft Auto fans, eager for news about one of the most anticipated video games of all time, appear especially vulnerable to this new cyberattack.
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into…
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously…
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal…
First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown
A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.