Malware

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant…

3 hours ago

Hackers Target Hotels With Fake Guest Complaints to Deploy Blockchain-Based RAT Malware

Hackers are targeting hotels with fabricated guest complaints and negative reviews to distribute EtherRAT and TONResolver, two malware families that…

7 hours ago

PoeLLM Malware Hijacks 3,400+ Servers for Crypto Mining and Botnet Expansion

A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing…

11 hours ago

Partisan Zmiy Malware Campaign Uses Telegram and DNS Tunneling to Target Healthcare Networks

A prolonged Partisan Zmiy intrusion into a medical organization, exposing an updated malware toolkit that combined Telegram command channels, DNS…

1 day ago

ClingSTUN Malware Turns Vulnerable IoT Devices Into Persistent Remote Proxy Nodes

ClingSTUN, a Linux backdoor that exploits unpatched internet-facing devices and converts them into persistent, remotely controlled proxy nodes. The malware…

2 days ago

Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware

A growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update…

6 days ago

Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks

A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware. The…

1 week ago

SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets

A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access…

1 week ago

OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection

Threat actors behind the OpenSUpdater malware family are concealing a reflective loader inside recompiled 7-Zip self-extracting archive components, allowing malicious…

1 week ago

DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware

DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new Ethereum-based recovery channel…

1 week ago