A new Linux cryptomining campaign has surfaced using a rare trick to stay hidden inside compromised networks. Instead of behaving like typical malware,…
Tag: MALWARE
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance…
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
AI-Generated Phishing No Longer Needs Malware: It Can Steal Your Session Inside the Browser
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where…
What the Trojan horse gets right (and wrong) about AI security
Agentic AI didn’t invent new risk. It removed the friction that used to keep environments in check.
CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
A newly identified malware strain named CrashStealer is targeting macOS users by disguising itself as Apple’s legitimate crash reporting utility. Designed…
Iran infrastructure warning, ChatGPT global outage, self-assembling malware
U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends…
Tengu botnet reboots Linux devices to survive removal
A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another…
Stairwell launches Backstory, pioneering agentic investigation for malware blast radius
Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces…
Android Malware Scanners Are Flagging Legitimate Apps and Missing Threats Without Context
Android malware scanners are increasingly misaligning with real-world risk by over-flagging legitimate, high-permission applications while quietly missing…
AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
A dangerous supply chain attack struck the AsyncAPI project on the npm registry, putting developers and automated build systems at risk. Attackers…
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in…
Android malware detection collapses when the context stage comes out
A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine…
AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens
Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand’s Finance Ministry. South Carolina’s AnMed reopened some physician…
Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with…
PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.…
We rebuilt Malwarebytes Mobile Security for the scams of today
Your phone needs more than a lock screen to stay safe. We’ve rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
Dysphoria Botnet Infects 200,000 IoT Devices and Hides C2 Behind Blockchain Domains
Dysphoria has emerged as a fast-moving IoT botnet that has infected an estimated 200,000 devices worldwide. The malware targets routers, cameras,…
New Tengu Mirai Botnet Reboots Your IoT Device When You Try to Kill It
Tengu, a newly observed Mirai-based botnet, is making infected IoT devices far harder to clean. It targets internet-facing embedded Linux systems,…