Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
Tag: MALWARE
HollowGraph Malware Abuses Microsoft 365 Calendars for Covert Command-and-Control
The malware component HollowGraph is using Microsoft 365 mailbox calendars to hide its C2 channels and traffic, enabling the bad actors to communicate…
HollowFrame Loader and Matryoshka Malware Used in Spear-Phishing Attack
Experts discovered a recently undocumented Go-based loader framework termed HollowFrame and a Rust-based malware strain called Matryoshka. Spear-phishing…
Suspected Chinese-Speaking Threat Actor Targets Central Asian Governments With New OctLurk and SilkLurk Malware
Government organizations across Central Asia are facing a cyber espionage campaign that employs two newly identified malware families, OctLurk and…
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images,…
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related…
CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
A newly identified malware strain named CrashStealer is targeting macOS users by disguising itself as Apple’s legitimate crash reporting utility. Designed…
Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These…
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network,…
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively…
Astaroth Banking Trojan Adds WhatsApp Web Spambot to Spread Malware Across Brazil
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts…
AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens
Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand’s Finance Ministry. South Carolina’s AnMed reopened some physician…
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web…
PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.…
Malwarebytes for Windows, now available on the Microsoft Store
Install Malwarebytes for Windows from the Microsoft Store with the same full protection and features.
We rebuilt Malwarebytes Mobile Security for the scams of today
Your phone needs more than a lock screen to stay safe. We’ve rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger…
AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected…
Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain…