North Korean-linked attackers are using a new way to hide the servers that control malware. The method places a command server address inside an empty…
Tag: MALWARE
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by…
Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint
New research reveals that malware already sitting on a compromised Windows PC can hijack Google’s synced passkeys and take over accounts without ever…
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at…
Russian spies turn public Wi-Fi into malware delivery systems
Keyloggers, audio-visual surveillance, and token theft on CaptivePortal’s agenda as hospitality sector put on alert
Mapping the malware blast radius a single alert won’t show you
In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works…
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
HollowGraph Malware Abuses Microsoft 365 Calendars for Covert Command-and-Control
The malware component HollowGraph is using Microsoft 365 mailbox calendars to hide its C2 channels and traffic, enabling the bad actors to communicate…
HollowFrame Loader and Matryoshka Malware Used in Spear-Phishing Attack
Experts discovered a recently undocumented Go-based loader framework termed HollowFrame and a Rust-based malware strain called Matryoshka. Spear-phishing…
Suspected Chinese-Speaking Threat Actor Targets Central Asian Governments With New OctLurk and SilkLurk Malware
Government organizations across Central Asia are facing a cyber espionage campaign that employs two newly identified malware families, OctLurk and…
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images,…
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related…
CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
A newly identified malware strain named CrashStealer is targeting macOS users by disguising itself as Apple’s legitimate crash reporting utility. Designed…
Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These…
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network,…
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively…
Astaroth Banking Trojan Adds WhatsApp Web Spambot to Spread Malware Across Brazil
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts…
AI agent hacks national finance ministry, Botnet uses blockchain, Healthcare chain reopens
Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand’s Finance Ministry. South Carolina’s AnMed reopened some physician…
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web…