Researchers uncovered an Android malware chain combining SpyNote and WindRelay to enable remote phone control, banking fraud, and live NFC card abuse.
Tag: MALWARE
Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware
A “Bring Your Own EDR” attack abuses trusted SentinelOne components to turn endpoint protection into a powerful malware shield. The research was presented…
AI Agents Don’t Stop When Malware Fails, They Write Another Tool and Keep Attacking
AI agents are changing the shape of cyberattacks. Instead of relying on a fixed piece of malware, an agent can test an approach, see it fail, write a…
WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Apple now uses iPhone alerts for targets of mercenary spyware
Apple explains how Threat Notifications help protect iPhone users targeted by mercenary spyware.
US courts will start publishing how often the government uses spyware
The Administrative Office of the U.S. Courts told TechCrunch that it will start disclosing how many times judges authorized the use of spyware to wiretap…
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
A new DCRat campaign is using a familiar image format to hide a dangerous malware archive. The operation begins with phishing emails that pose as legal…
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals
Criminal services that hide malware are becoming easier to buy. These services, known as crypters, change a malicious file so that security tools struggle…
Dysphoria Botnet Turns Compromised Routers and Cameras Into DDoS Bots and C2 Relay Nodes
Dysphoria has turned a large number of everyday internet-connected devices into a potential attack network. The botnet is linked to roughly 296,000…
Agentic AI Models Rebuild Malware and Sustain Real-World Cyber Intrusions, SentinelOne Warns
Four incidents involving OpenAI, Anthropic, Meta and the UK AI Security Institute (AISI) describe AI agents reaching systems belonging to other…
New Android malware relays bank cards to fraudsters while victims still hold them
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it…
HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel
A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The…
Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnet
The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000…
24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors…
New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL
Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass…
Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2
Aeternum is a new botnet loader designed to resist takedowns. It stores instructions on Polygon, a public blockchain, creating a widely replicated control…
Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attacks
Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of…
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
Aeternum Hides Malware Commands on Polygon Blockchain Where Server Takedowns Can’t Erase Them
A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to…