Malware

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The…

6 hours ago

New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks

A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root…

9 hours ago

Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware

A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain…

2 days ago

GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks

GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the…

2 days ago

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with…

4 days ago

Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems

A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can…

1 week ago

Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning

A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to…

1 week ago

Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme

Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines…

1 week ago

AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks

BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised…

1 week ago

SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications

A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation,…

1 week ago