PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.
Tag: MALWARE
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.…
Malwarebytes for Windows, now available on the Microsoft Store
Install Malwarebytes for Windows from the Microsoft Store with the same full protection and features.
We rebuilt Malwarebytes Mobile Security for the scams of today
Your phone needs more than a lock screen to stay safe. We’ve rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure.
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger…
AtlasRAT Uses Four-Stage In-Memory Loader to Keylog and Inject Malware Into WeChat
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected…
Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain…
Linux Cryptomining Campaign Weaponizes PAM to Hide XMRig Botnet Activity
A new Linux cryptomining campaign has surfaced using a rare trick to stay hidden inside compromised networks. Instead of behaving like typical malware,…
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance…
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
AI-Generated Phishing No Longer Needs Malware: It Can Steal Your Session Inside the Browser
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where…
What the Trojan horse gets right (and wrong) about AI security
Agentic AI didn’t invent new risk. It removed the friction that used to keep environments in check.
CrashStealer Malware Targets macOS Users by Posing as Apple Crash Reporter
A newly identified malware strain named CrashStealer is targeting macOS users by disguising itself as Apple’s legitimate crash reporting utility. Designed…
Iran infrastructure warning, ChatGPT global outage, self-assembling malware
U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends…
Tengu botnet reboots Linux devices to survive removal
A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another…
Stairwell launches Backstory, pioneering agentic investigation for malware blast radius
Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces…
Android Malware Scanners Are Flagging Legitimate Apps and Missing Threats Without Context
Android malware scanners are increasingly misaligning with real-world risk by over-flagging legitimate, high-permission applications while quietly missing…
AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
A dangerous supply chain attack struck the AsyncAPI project on the npm registry, putting developers and automated build systems at risk. Attackers…
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in…
Android malware detection collapses when the context stage comes out
A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine…