A newly identified macOS infostealer, named AmnesiaStealer, targets users via ClickFix social-engineering campaigns that impersonate GitHub download…
Tag: MALWARE
Apple Urges Mercenary Spyware Targets to Enable Lockdown Mode Immediately
Apple has quietly rolled out a new wave of high-confidence “Apple Threat Notification” alerts, warning selected iPhone users in 110 countries that their…
If Apple sends you a push notification alerting you to a spyware attack, take it seriously
Apple now sends out push notifications to iPhone lock screens when the company identifies government spyware targeting someone’s devices.
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant…
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
A newly identified macOS infostealer called AmnesiaStealer is spreading via a convincing fake GitHub download page, tricking Mac users into pasting a…
Fake CCleaner installs GhostDesk Chrome spyware
A convincing fake CCleaner website delivers a multi-stage malware attack that installs a spyware extension inside Chrome.
Kimsuky Brings AI Closer to Its Malware and Phishing Operations
North Korean cyber-espionage group Kimsuky appears to be moving beyond occasional use of public AI services by assembling a local artificial intelligence…
Jewelbug Uses Public Google Docs as Malware Command-and-Control Delivery Channel
A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly…
Multi-Functional Linux Botnet “Evooo1Bot”
FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders
OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn’t matter, and that changes the playbook for investigating intrusions.
New Android malware lets criminals use your bank card in real time
Social engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It’s no joke. Together, they can empty your bank account.
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Kimwolf v7 is raising the stakes for attacks launched from everyday Android TV boxes and set-top devices. The latest version can make disruptive web…
Bad Advice and Myths Around Malware Prevention
Have you ever given advice like “opening PDFs is safe”, “exploits are extremely rare” or “browsers are secure”? Please don’t.
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running…
Meccha Chameleon Vulnerability Allowed Malware to Spread Through Steam Workshop Maps
A security vulnerability in the game Meccha Chameleon enabled malicious custom maps stored on Steam Workshop to infect users with malware. The…
Go-Based macOS Malware Steals Crypto and Secrets
A macOS malware variant has been detected stealing crypto, passwords and more
WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Windows users looking for a familiar cleanup utility are being steered toward a convincing counterfeit download page. The file they receive installs…
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
A new Android fraud operation shows how quickly a convincing phone call can turn into financial loss. The campaign combines the SpyNote remote-control…