News

StreamRat Android Trojan Hijacks Devices

The StreamRat Android Trojan can gain near-complete control of infected devices. Researchers found the malware through a fake television streaming campaign. The campaign targeted Spanish-speaking Android users through social media ads. However, the attackers disguised the malware as a legitimate streaming application. The campaign mainly focused on users in Spain. Researchers estimated that about 570,950 …

StreamRat Android Trojan Hijacks Devices Read More »

Attackers Turn Trusted Node.js Runtime Into Malware

Attackers turn trusted Node.js runtime tools into malware delivery systems. Researchers found this technique in several targeted attacks since February 2026. The campaigns affected government groups, technology firms, and hotels. However, the attackers use a legitimate developer tool to avoid attention. Node.js normally runs JavaScript programs on Windows computers. Its main executable carries a valid …

Attackers Turn Trusted Node.js Runtime Into Malware Read More »

BraZetsu Turns Hacked PCs Into Criminal Assets

BraZetsu malware turns hacked Windows computers into assets for a criminal marketplace. Security researchers recently uncovered the Python-based malware framework. The malware helps criminals find, study, and sell access to infected systems. Therefore, one infection can create opportunities for several later attacks. Researchers say BraZetsu differs from typical information-stealing malware. Instead, it works as a …

BraZetsu Turns Hacked PCs Into Criminal Assets Read More »

Manic Malware Steals Data From Offline Phones

A New Android Threat Emerges A newly discovered malware called Manic is actively targeting Android users across Europe. Researchers first spotted it attacking Ukrainian banks, government services, and messaging apps. However, its reach extends further. It also hits Russian and European financial institutions, fintech platforms, and cryptocurrency services. Manic blends two dangerous categories into one. …

Manic Malware Steals Data From Offline Phones Read More »

StopAndProtect Hits WordPress Sites With Malware

StopAndProtect uses hacked WordPress sites to spread malware and steal data. Researchers found nearly 2,000 compromised sites linked to the campaign. However, the attackers do not rely on one malware program. Instead, they use several tools for theft, surveillance, spreading, and ransomware. The campaign starts with a ClickFix social engineering trick. Visitors see a fake …

StopAndProtect Hits WordPress Sites With Malware Read More »

AmnesiaStealer macOS Malware Hijacks Sessions

AmnesiaStealer macOS malware can hijack browser sessions through remote control features. The malware targets macOS users through fake download pages and ClickFix attacks. However, it does more than steal files and passwords. It can copy browser profiles and use existing login sessions. Therefore, attackers may access online accounts without needing the victim’s password again. Security …

AmnesiaStealer macOS Malware Hijacks Sessions Read More »

Mercenary Spyware Threatens Users Worldwide

Mercenary spyware has triggered fresh warnings for users across 110 countries. Researchers say these attacks target a small number of specific people. However, the attacks can use highly advanced tools and expensive techniques. The latest alerts add to notifications sent across more than 150 countries since 2021. Therefore, affected users should treat these warnings as …

Mercenary Spyware Threatens Users Worldwide Read More »

AI Mind Viruses Can Spread Between Agents

AI mind viruses can spread between agents through persistent prompt files. Security researchers demonstrated the technique in controlled experiments. The payload can survive between sessions and reach another AI agent. However, researchers found no evidence of successful spread in real-world systems. Therefore, the threat remains limited but deserves attention. The researchers tested the technique in …

AI Mind Viruses Can Spread Between Agents Read More »

AmnesiaStealer Hijacks Chrome Sessions on Mac

Cybersecurity researchers have uncovered AmnesiaStealer, a new malware targeting macOS users. The Rust-based stealer focuses on browser data, passwords, and active sessions. However, it can also give attackers live control of Chromium browsers. Therefore, the malware poses a serious privacy and account security risk. The attack starts with a fake software download page. Moreover, the …

AmnesiaStealer Hijacks Chrome Sessions on Mac Read More »

737 Chrome VPN Extensions Hide Proxy Risks

Researchers have uncovered 737 Chrome VPN Extensions linked to hidden proxy services. Most extensions target users seeking access to blocked online services. However, the tools can route browser traffic through servers controlled by one provider. Therefore, users may expose their browsing activity without knowing it. The extensions appeared across at least 40 developer accounts. Together, …

737 Chrome VPN Extensions Hide Proxy Risks Read More »

WindRelay Android Malware Fuels Payment Fraud

Cybersecurity researchers have uncovered WindRelay Android Malware used in contactless payment fraud. The malware turns infected phones into live NFC relays. Therefore, criminals can capture payment card data in real time. The campaign also uses a remote access trojan to control infected devices. As a result, victims may lose control of their phones and payment …

WindRelay Android Malware Fuels Payment Fraud Read More »

HollowFrame Loader Targets Law Firms

Cybersecurity researchers have discovered a new malware campaign using HollowFrame Loader. However, the attackers also deploy a backdoor called Matryoshka. The campaign begins with carefully crafted spear-phishing emails. Therefore, victims unknowingly install malware after opening a fake file. The attack focuses on gaining long-term access to targeted systems. Researchers found that the campaign targeted a …

HollowFrame Loader Targets Law Firms Read More »

Greatness PhaaS Adds Device Code Phishing

Cybersecurity researchers have found major updates to the Greatness phishing platform. However, the toolkit now supports device code phishing attacks. This technique bypasses multi-factor authentication with legitimate login processes. Therefore, attackers can steal authentication tokens instead of only passwords. The upgrade makes phishing campaigns more dangerous than before. Researchers also found support for adversary-in-the-middle attacks. …

Greatness PhaaS Adds Device Code Phishing Read More »

Researchers Report 84 Flaws in 4G and 5G Cores

Security researchers have discovered 84 security flaws in 4G and 5G core networks. However, these weaknesses could expose mobile networks to serious cyberattacks. Attackers may launch denial-of-service attacks or hijack user sessions. Therefore, both network operators and users face increased security risks. The findings highlight weaknesses in modern mobile network infrastructure. The researchers examined several …

Researchers Report 84 Flaws in 4G and 5G Cores Read More »

Chinese Threat Actor Targets iPhones With DarkSword

Cybersecurity researchers have uncovered a new campaign targeting iPhone users. However, the attackers use a leaked exploit kit called DarkSword. The campaign installs GHOSTBLADE malware on vulnerable devices. Therefore, attackers can steal sensitive information from infected iPhones. The activity highlights the growing misuse of leaked cyberattack tools. Researchers found more than 100 malicious websites linked …

Chinese Threat Actor Targets iPhones With DarkSword Read More »

DOUBLECUP Uses ClickFix to Spread Hidden Malware

Cybersecurity researchers have discovered a new malware campaign called DOUBLECUP. However, this loader-as-a-service platform uses ClickFix tricks to infect victims. The attack hides malicious code inside PNG image files. Therefore, users may not notice the infection at first. The campaign eventually installs advanced malware on targeted devices. Researchers found that the attackers hide the first …

DOUBLECUP Uses ClickFix to Spread Hidden Malware Read More »

Fake Adobe and Zoom Updates Spread Remote Access Malware

Cybersecurity researchers have uncovered a new phishing campaign. The attack uses fake Adobe and Zoom updates. However, the campaign also uses fake document reviews and system maintenance tools. These tricks convince users to install remote access software. As a result, attackers gain long-term access to infected devices. The researchers named the campaign SMOKE#SCREEN. Moreover, the …

Fake Adobe and Zoom Updates Spread Remote Access Malware Read More »

Malvertising Sends Malware Through Browser Tricks

Malvertising Sends Malware Using Browser Assembly Cybersecurity researchers have uncovered a new Malvertising Sends Malware campaign targeting cryptocurrency investors and retail traders. Instead of downloading a complete malware file, victims unknowingly let their browsers assemble it. As a result, the attack becomes harder to detect. Furthermore, attackers use trusted software components to hide malicious activity. …

Malvertising Sends Malware Through Browser Tricks Read More »

Golden Chickens Unleashes New Malware

A new Golden Chickens campaign has introduced four new malware families for cybercriminal operations. Researchers found that the malware platform continues to evolve despite previous public exposure. The new tools improve stealth, flexibility, and attack capabilities. Therefore, organizations face an increasing risk from modular malware. The attackers also continue using social engineering to infect victims. …

Golden Chickens Unleashes New Malware Read More »

DevMan RaaS Centralizes Ransomware Operations

Cybersecurity researchers have uncovered new details about DevMan RaaS, a ransomware platform built for affiliates. The operation provides a dedicated web portal for managing ransomware campaigns. Moreover, the platform helps affiliates create malware, monitor victims, and track payments. Researchers believe this setup makes cybercrime more efficient. As a result, attackers can organize operations from one …

DevMan RaaS Centralizes Ransomware Operations Read More »

ENCFORGE Ransomware Targets AI Model Files

A new ENCFORGE ransomware campaign is targeting AI model files through vulnerable Langflow servers. Researchers linked this attack to the same threat actor behind an earlier campaign. The attackers exploit exposed Langflow instances to gain remote access. Therefore, AI environments face an increasing ransomware risk. The campaign focuses on encrypting valuable AI assets instead of …

ENCFORGE Ransomware Targets AI Model Files Read More »

FakeGit Campaign Spreads SmartLoader Malware

A new FakeGit Campaign is spreading SmartLoader malware through fake GitHub repositories. Researchers discovered nearly 7,600 malicious repositories during the investigation. Many of these repositories imitate AI skills and Model Context Protocol servers. Therefore, developers and organizations face a growing cybersecurity threat. The attackers use trusted platforms to distribute malware and steal sensitive information. Fake …

FakeGit Campaign Spreads SmartLoader Malware Read More »

NadMesh Botnet Targets Exposed AI Services

A new NadMesh Botnet campaign is targeting exposed AI services to steal cloud credentials and Kubernetes tokens. Researchers first detected the malware in early July. The botnet scans internet-facing AI platforms for weak security settings. Therefore, organizations running exposed services face a growing cybersecurity risk. The attackers focus on valuable cloud access instead of the …

NadMesh Botnet Targets Exposed AI Services Read More »

OtterCookie Malware Hides in SVG Images

A new OtterCookie malware campaign targets software developers through fake job offers and coding tests. Attackers hide malicious code inside SVG image files. As a result, victims unknowingly install malware while completing technical assignments. The malware steals sensitive information and cryptocurrency wallet data. Therefore, developers face a growing cybersecurity risk. Fake Job Offers Deliver the …

OtterCookie Malware Hides in SVG Images Read More »

GoSerpent Malware Targets Government Networks

A new GoSerpent malware campaign targets government and diplomatic organizations across Southeast Asia. Attackers use the malware to maintain long-term access to compromised systems. As a result, they collect sensitive files and valuable credentials over several months. They also deploy additional tools to expand their operations. Therefore, the campaign presents a serious cyber espionage threat. …

GoSerpent Malware Targets Government Networks Read More »

TELEPUZ Malware Spreads Through ClickFix

A new TELEPUZ malware campaign targets Windows users through ClickFix attacks. The malware tricks users into running malicious commands themselves. As a result, attackers gain access to sensitive data and system controls. They also install additional malware during the infection. Therefore, the campaign creates a serious cybersecurity threat. ClickFix Starts the Infection Researchers found that …

TELEPUZ Malware Spreads Through ClickFix Read More »

Student Proxy Botnet Turns Browsers Into Attackers

A new student proxy botnet campaign abused fake npm packages to launch hidden cyberattacks. The packages appeared to offer web proxy services for students. However, they secretly turned visitors’ browsers into attack tools. As a result, users joined a distributed denial-of-service attack without knowing it. Therefore, the campaign exposed both students and organizations to serious …

Student Proxy Botnet Turns Browsers Into Attackers Read More »

Microsoft Entra Passkey Scam Steals Accounts

A new Microsoft Entra passkey scam targets Microsoft 365 users through phone-based social engineering. Attackers pretend to offer security assistance during the call. As a result, victims believe they must register a new passkey. They unknowingly approve attacker access to their accounts. Therefore, organizations face a higher risk of data theft and extortion. How the …

Microsoft Entra Passkey Scam Steals Accounts Read More »

GigaWiper Windows Backdoor Hides Destructive Tools

A new GigaWiper Windows backdoor gives attackers several ways to damage infected computers. It combines disk wiping, fake ransomware, and spyware in one tool. As a result, attackers can steal information before destroying important data. They also control infected systems from a distance. Therefore, this malware creates a serious cybersecurity threat. How the Malware Works …

GigaWiper Windows Backdoor Hides Destructive Tools Read More »

GodDamn Ransomware Disables Security Tools

A new GodDamn ransomware campaign is targeting organizations with advanced attack methods. The malware uses a malicious driver to disable security software. As a result, attackers can avoid detection before encrypting files. They also move across networks more easily. Therefore, the threat poses a serious risk to many businesses. How the Attack Begins Researchers found …

GodDamn Ransomware Disables Security Tools Read More »

HalluSquatting Attack Tricks AI Assistants

A new cyberattack called HalluSquatting attack targets AI coding assistants. It exploits how these tools invent missing project names. As a result, attackers can register fake repositories first. They then wait for AI assistants to download the wrong resource. Therefore, users may unknowingly install malicious software. How the HalluSquatting Attack Works The attack starts when …

HalluSquatting Attack Tricks AI Assistants Read More »

SCMBANKER Malware Targets Banking Users

A new cyberattack campaign is targeting banking users in Mexico. The attackers focus on bank customers, payment services, digital finance platforms, and cryptocurrency users. They use fake verification pages to trick people into installing malware. As a result, victims unknowingly give attackers access to their devices. The malware is known as SCMBANKER malware. Fake Verification …

SCMBANKER Malware Targets Banking Users Read More »

PamStealer Steals Mac Login Passwords

Researchers Discover a New macOS Threat PamStealer is a new information-stealing malware targeting macOS users. Researchers found that attackers disguise the malware as a trusted clipboard application. Moreover, they distribute it through fake websites that closely resemble the real software page. Therefore, users may install the malware without realizing the danger. The malware focuses on …

PamStealer Steals Mac Login Passwords Read More »

North Korean Hackers Spread Malicious Packages

Researchers Discover an Ongoing Campaign North Korean Hackers are running a large campaign that targets software developers. Researchers found more than 100 malicious packages and browser extensions. Moreover, the attackers distributed them across several popular software repositories. Therefore, developers face a growing supply chain security risk. Researchers believe the campaign remains active today. However, attackers …

North Korean Hackers Spread Malicious Packages Read More »

Armored Likho Targets Government Networks

Researchers Uncover a Growing Cyber Threat Armored Likho is a threat group targeting government organizations and the power sector. Researchers observed attacks in several countries, including Russia, Brazil, and Kazakhstan. Moreover, the group combines financial crime with cyber espionage. Therefore, its campaigns create risks for both public institutions and critical infrastructure. Researchers explained that the …

Armored Likho Targets Government Networks Read More »

VEIL#DROP Malware Delivers PureLogs Stealer

Researchers Identify a New Malware Campaign VEIL#DROP Malware is a new attack that spreads the PureLogs Stealer. Researchers recently uncovered this multi-stage malware campaign. Moreover, attackers rely on social engineering to trick users. Therefore, the attack can infect systems without raising suspicion. The infection usually starts through phishing emails or compromised websites. However, both methods …

VEIL#DROP Malware Delivers PureLogs Stealer Read More »

Ousaban Banking Trojan Targets Banking Users

Researchers Discover a New Banking Attack Ousaban Banking Trojan is targeting online banking users in Spain and Portugal. Researchers recently discovered the campaign targeting Windows devices. Moreover, attackers use fake PDF files to deliver the malware. Therefore, banking customers in these countries face a higher security risk. The malware focuses on stealing online banking credentials. …

Ousaban Banking Trojan Targets Banking Users Read More »

New ChocoPoC RAT Hides in Fake PoC Repositories

Researchers Uncover a New Malware Campaign New ChocoPoC RAT is targeting vulnerability researchers through fake proof-of-concept repositories. Attackers disguise the malware inside exploit code for newly disclosed security flaws. As a result, researchers may infect their own systems while testing vulnerabilities. Therefore, this campaign creates serious risks for cybersecurity professionals. Researchers found that the malware …

New ChocoPoC RAT Hides in Fake PoC Repositories Read More »

Phantom Squatting Threats Targets AI Fake Domains

Researchers Discover a New AI Security Threat Phantom Squatting is a growing cyber threat that targets AI-generated web addresses. Researchers found that attackers register fake domains created by AI models. Moreover, these domains often look trustworthy to users and developers. As a result, attackers can launch phishing campaigns and malware attacks. Therefore, organizations should understand …

Phantom Squatting Threats Targets AI Fake Domains Read More »

Microsoft Warns AI Agents Can Leak Data

Researchers Reveal a New AI Security Risk Microsoft Warns AI Agents Can Leak Data through a new attack method. Researchers discovered that attackers can abuse poisoned tool descriptions. Moreover, the attack can trick AI agents into sharing sensitive company information. The agent follows its normal instructions during the process. Therefore, the attack can remain unnoticed …

Microsoft Warns AI Agents Can Leak Data Read More »

AI-Generated Ransomware Attack Web Browser

Researchers Discover a New Browser-Based Attack AI-Generated Browser Ransomware has introduced a new security concern for browser users. Researchers recently found malware that works entirely inside a web browser. Moreover, the attack uses existing browser features instead of traditional malware methods. This approach allows attackers to avoid installing separate software. Therefore, security experts believe this …

AI-Generated Ransomware Attack Web Browser Read More »

RustDuck Botnet Rebuilds in Rust for Bigger DDoS Attacks

RustDuck Botnet is targeting routers, servers, IP cameras, and Android TV boxes to launch large-scale DDoS attacks. Researchers discovered the malware in early 2026 and found that it continues to evolve rapidly. However, the biggest concern is not its current size but its advanced development. Therefore, security experts urge organizations to strengthen their defenses before …

RustDuck Botnet Rebuilds in Rust for Bigger DDoS Attacks Read More »

AirDrop and Quick Share Flaws Expose Nearby Devices

AirDrop and Quick Share flaws could allow nearby attackers to crash wireless file-sharing services without permission. Researchers found six security issues that affect popular file-sharing features on millions of devices. However, the attacks only work when the attacker is within wireless range. Therefore, users should install the latest updates and avoid unnecessary file-sharing visibility. Researchers …

AirDrop and Quick Share Flaws Expose Nearby Devices Read More »

AI Browsers Can Leak User Credentials

BioShocking Exposes a New AI Security Risk AI Browsers can leak user credentials through a newly discovered attack called BioShocking. Researchers recently demonstrated this technique against several AI-powered browsers and assistants. The attack convinced AI agents to reveal private login information. Therefore, the findings raise serious concerns about AI browser security. Unlike traditional browsers, AI …

AI Browsers Can Leak User Credentials Read More »

ClickFix Campaigns Use New Tricks to Spread Malware

ClickFix Campaigns Continue to Evolve Cybersecurity researchers have identified several new ClickFix campaigns. These attacks deliver different malware loaders to victim devices. According to multiple researcher reports, the campaigns use advanced delivery methods. Therefore, they pose a growing threat to organizations and individual users. The attacks mainly target Windows systems through social engineering techniques. ClickFix …

ClickFix Campaigns Use New Tricks to Spread Malware Read More »

New Rokarolla Android Malware Drains Bank Accounts

New Rokarolla Android Malware Targets Mobile Users Security researchers have identified a new Android banking threat called Rokarolla. The malware targets banking and cryptocurrency applications. According to a researcher report, it can attack more than 200 financial apps. Therefore, Android users face a serious security risk. The malware also includes many remote control features that …

New Rokarolla Android Malware Drains Bank Accounts Read More »

Malicious JetBrains Plugins Steal AI Keys

Cybersecurity researchers have uncovered a large malware campaign targeting software developers. The campaign uses fake AI coding tools to steal valuable AI service keys. These plugins appear helpful at first glance. However, they secretly send user credentials to attacker-controlled servers. As a result, developers may lose access to paid AI services and face unexpected costs. …

Malicious JetBrains Plugins Steal AI Keys Read More »

Fake Microsoft Alerts Spread NarwhalRAT Malware

Cybercriminals Use Fake Security Warnings Fake Microsoft Alerts are being used in a new cyberattack campaign. Researchers recently discovered that a state-backed hacking group used these messages to spread malware. The emails looked like legitimate account security notifications. Therefore, many users could mistake them for genuine alerts. The campaign relied on fear and urgency to …

Fake Microsoft Alerts Spread NarwhalRAT Malware Read More »

Microsoft 365 Copilot Flaw Exposed Sensitive Data

Introduction A newly discovered Microsoft 365 Copilot Flaw could have allowed attackers to steal sensitive information with a single click. Researchers recently uncovered a chain of security weaknesses that created a powerful data theft path. The attack required no password and no additional user interaction. Instead, a victim only needed to click a trusted link. …

Microsoft 365 Copilot Flaw Exposed Sensitive Data Read More »

Agentjacking Attack Tricks AI Tools Into Running Malware

Introduction A newly discovered cybersecurity threat called Agentjacking Attack can trick AI coding tools into running malicious code. Researchers recently revealed this technique after testing it against popular AI development assistants. The attack targets AI agents that developers trust every day. However, it does not require phishing emails or server breaches. Instead, attackers abuse trusted …

Agentjacking Attack Tricks AI Tools Into Running Malware Read More »

Chrome Wallpaper Extensions Linked to Hidden Adware

Chrome Wallpaper Extensions Raise Security Concerns Chrome Wallpaper Extensions are under scrutiny after researchers uncovered a large network of suspicious browser add-ons. These extensions appeared as attractive live wallpaper tools for new browser tabs. However, researchers found that many of them carried hidden adware-related functions. The operation involved 152 browser extensions spread across dozens of …

Chrome Wallpaper Extensions Linked to Hidden Adware Read More »

China-Linked Hackers Hidden in Linux Login Systems for Years

China-Linked Hackers Stay Hidden for Years China-Linked Hackers managed to stay hidden inside Linux systems for nearly a decade. Researchers recently uncovered a long-running operation that targeted critical login software. Instead of using obvious malware, the attackers altered trusted system components. Therefore, their activity blended into normal system operations. As a result, defenders struggled to …

China-Linked Hackers Hidden in Linux Login Systems for Years Read More »

Popular WordPress Plugin Backdoor Attack Exposed

Trusted Scripts Turn Into a Serious Threat A recent security incident has put many website owners at risk. Researchers discovered that attackers tampered with trusted JavaScript files used by a popular WordPress plugin ecosystem. As a result, the modified files secretly created backdoors on affected websites. The attack targeted websites using three widely installed plugins. …

Popular WordPress Plugin Backdoor Attack Exposed Read More »

AI Agent Tricked Into Leaking User Secrets

AI Agent Faces New Security Risks AI Agent has become the focus of new security research. Two separate research teams recently uncovered serious weaknesses. As a result, attackers may trick the agent into running commands or exposing sensitive data. Researchers demonstrated different attack methods. However, both attacks reached the same goal. Attackers gained influence over …

AI Agent Tricked Into Leaking User Secrets Read More »

Microsoft 365 Android Apps Exposed User Tokens

Microsoft 365 Android Apps Hit by Security Flaw Microsoft 365 Android Apps recently faced a serious security issue. Researchers discovered a development flag that remained active in production versions. As a result, the flaw weakened account protection on several Android apps. The issue allowed untrusted apps to request account tokens. Therefore, attackers could gain access …

Microsoft 365 Android Apps Exposed User Tokens Read More »

Google DoubleClick Abused to Spread Malware

Google DoubleClick Abused in New Malware Campaign Google DoubleClick Abused is the key phrase security researchers used to describe a new phishing campaign. Researchers recently uncovered an attack that uses a trusted advertising domain to bypass security checks. As a result, attackers can make malicious links appear more legitimate. This method helps cybercriminals avoid early …

Google DoubleClick Abused to Spread Malware Read More »

Fake Sites Mimicking Open-Source Tools Trick Users

Fake Sites Mimicking Open-Source Tools Rise on Search Results Fake Sites Mimicking Open-Source Tools have become a growing cybersecurity threat. Researchers recently uncovered a large campaign targeting software users. These websites imitate trusted open-source projects. Therefore, many visitors believe the sites are legitimate. The fake portals closely resemble real project websites. In some cases, they …

Fake Sites Mimicking Open-Source Tools Trick Users Read More »

FlutterShell Backdoor Targets macOS Through Ads

FlutterShell Backdoor Emerges in New Campaign FlutterShell Backdoor is the latest threat targeting macOS users. Researchers recently uncovered a large malvertising campaign spreading this malware. The operation uses fake advertisements to lure victims. Therefore, users may unknowingly install infected applications. Researchers believe this campaign evolved from an earlier malware operation. The threat group behind both …

FlutterShell Backdoor Targets macOS Through Ads Read More »

Chinese Hackers Expand Atlas RAT Attacks

Chinese Hackers Target European Organizations Chinese hackers have expanded their cyberattack campaigns into Europe. Researchers observed a sharp increase in activity during recent months. The group focuses on financial gain through cybercrime operations. However, some of its tools also support surveillance activities. Therefore, security experts continue monitoring the threat closely. The attackers previously focused on …

Chinese Hackers Expand Atlas RAT Attacks Read More »

Google DoubleClick Delivers RAT Through Malspam

Google DoubleClick Used in New Malware Campaign Google DoubleClick has been abused in a new phishing campaign. Researchers discovered that attackers use the platform to hide malicious activity. The campaign ultimately delivers a remote access trojan called DesckVB RAT. Therefore, attackers can avoid early detection mechanisms. As a result, victims face a greater risk of …

Google DoubleClick Delivers RAT Through Malspam Read More »

Malicious Sicoob NuGet Steals Banking Data

Malicious Sicoob NuGet Targets Developers Malicious Sicoob NuGet packages have emerged as a serious threat. Researchers recently uncovered a package that steals sensitive banking data. The package pretends to be a legitimate software development toolkit. However, it secretly collects authentication information from developers. Therefore, organizations using the package face significant security risks. The malicious package …

Malicious Sicoob NuGet Steals Banking Data Read More »

AI Chatbot Recommendations Spread Malware

AI Chatbot Recommendations Fuel New Threats AI chatbot recommendations are helping attackers spread malware. Researchers recently uncovered a cryptojacking campaign using this method. Instead of relying only on search engines, attackers now exploit AI-generated responses. Therefore, malicious websites gain greater visibility. As a result, more users may unknowingly download harmful software. Researchers observed users asking …

AI Chatbot Recommendations Spread Malware Read More »

Grandoreiro Malware Targets Banks and Users

Grandoreiro Malware Expands Across Regions Grandoreiro malware continues to target users across Europe and Latin America. Researchers recently identified new campaigns affecting multiple countries. The attacks focus on both businesses and financial institutions. In addition, cybercriminals target users who rely on online banking services. Therefore, the threat remains a major concern. Researchers observed attacks in …

Grandoreiro Malware Targets Banks and Users Read More »

Malicious npm Package Steals Claude AI Files

Malicious npm Package Targets AI User Data A malicious npm package has been discovered on a popular software repository. Researchers found that the package contains information-stealing capabilities. The threat specifically targets files linked to an AI development environment. As a result, users may unknowingly expose sensitive information. Therefore, the discovery raises concerns about software supply …

Malicious npm Package Steals Claude AI Files Read More »

GlassWorm Malware Takedown Stops Supply Chain Threats

GlassWorm Malware Campaign Targets Developers GlassWorm malware has disrupted software developers since early 2025. The campaign targeted people with access to critical development systems. These systems included source code repositories and cloud platforms. In addition, attackers focused on package registries and CI/CD pipelines. Therefore, a single breach could affect many organizations. Researchers reported that developers …

GlassWorm Malware Takedown Stops Supply Chain Threats Read More »

MuddyWater DLL Side-Loading Attacks Hit 9 Nations

MuddyWater DLL Side-Loading Attacks Hit 9 Nations A cyber espionage campaign linked to MuddyWater has affected organizations in nine countries. The attacks occurred during the first quarter of 2026. Several industries became targets during the operation. These included manufacturing, education, finance, and public services. Moreover, the campaign reached victims across four continents. Researchers observed attacks …

MuddyWater DLL Side-Loading Attacks Hit 9 Nations Read More »

Trapdoor Ad Fraud Scheme Hits Android Users

Trapdoor Ad Fraud Scheme Spreads Through Fake Apps A new Trapdoor ad fraud scheme targets Android users through fake utility apps and hidden advertising attacks. Researchers found 455 harmful apps connected to the operation. In addition, the campaign used 183 malicious control domains to support multi-stage fraud activities. Users often downloaded simple tools, such as …

Trapdoor Ad Fraud Scheme Hits Android Users Read More »

Malicious npm Packages Spread Data-Stealing Malware

Malicious npm Packages Target Developers Cybersecurity researchers recently discovered four malicious npm packages that spread dangerous malware to developers. The infected packages appeared harmless at first. However, they secretly delivered information-stealing tools and botnet malware after installation. Researchers found that one package copied code from a previously leaked malware project. Therefore, attackers quickly reused public …

Malicious npm Packages Spread Data-Stealing Malware Read More »

Hackers Used AI to Crack 2FA Security

Hackers Used AI in New Cyberattacks Researchers recently uncovered a dangerous cybercrime campaign using artificial intelligence. The attackers reportedly developed a zero-day exploit with AI assistance. Furthermore, researchers believe this marks a major shift in cyber threats. The exploit targeted a popular web-based administration platform. However, researchers did not reveal the platform’s name publicly. The …

Hackers Used AI to Crack 2FA Security Read More »

Fake Call History Apps Tricked Millions

Fake Call History Apps Spread Across Android Cybersecurity researchers recently uncovered a large Android scam campaign. The campaign used fake apps on the official app marketplace. These apps claimed to provide call records for any phone number. However, the apps delivered fake information after users paid subscription fees. Researchers discovered 28 harmful apps connected to …

Fake Call History Apps Tricked Millions Read More »

TCLBANKER Trojan Spreads Through Messaging Apps

TCLBANKER Trojan Targets Financial Users Security experts recently uncovered a new banking trojan called TCLBANKER. The malware mainly targets users in Brazil. However, researchers warn that the threat could spread wider over time. The trojan attacks banking, fintech, and cryptocurrency platforms. In total, it targets 59 financial services. Furthermore, the malware spreads through messaging and …

TCLBANKER Trojan Spreads Through Messaging Apps Read More »

Windows Phone Link Exploited to Steal OTPs

Windows Phone Link Becomes Attack Target Windows Phone Link exploited attacks now threaten users who sync phones with computers. Researchers uncovered a campaign using a remote access trojan called CloudZ. However, the attackers also deployed a custom plugin named Pheno. Therefore, the malware gained access to sensitive synced mobile data. The attack focused on stealing …

Windows Phone Link Exploited to Steal OTPs Read More »

Facebook Accounts Hacked Through Phishing Emails

Facebook Accounts Hacked in Large Campaign Facebook accounts hacked through phishing attacks have affected nearly 30,000 users worldwide. Researchers uncovered a large operation linked to Vietnam. However, the attackers used trusted online services to avoid detection. Therefore, many victims believed the phishing emails were legitimate. The operation focused mainly on Facebook Business account owners. Moreover, …

Facebook Accounts Hacked Through Phishing Emails Read More »

Mirai-Based Botnet Hijacks IoT Devices

Mirai-Based Botnet Targets IoT Devices Mirai-based botnet attacks now threaten internet-connected devices worldwide. Researchers recently uncovered a new malware strain called xlabs_v1. However, the botnet mainly targets devices with exposed Android Debug Bridge services. Therefore, many smart devices face serious security risks. The malware infects Android TV boxes, smart TVs, and set-top boxes. Moreover, it …

Mirai-Based Botnet Hijacks IoT Devices Read More »

Python Backdoor Steals Browser Credentials

Python Backdoor Targets Sensitive Data Python backdoor attacks now threaten users and organizations worldwide. Researchers discovered a stealthy malware framework called DEEP#DOOR. However, the campaign appears limited and targeted for now. Therefore, experts continue monitoring its activity closely. The malware uses Python to create persistent remote access. Moreover, it collects sensitive information from infected systems. …

Python Backdoor Steals Browser Credentials Read More »

Phishing Campaign Abuses Remote Access Tools

Phishing Campaign Targets Many Organizations Phishing campaign attacks have hit more than 80 organizations since April 2025. Most victims operate in the United States. However, researchers believe the campaign may spread further. Therefore, security teams now monitor the activity closely. The attackers use legitimate remote management software during the attacks. For example, they install trusted …

Phishing Campaign Abuses Remote Access Tools Read More »

MuddyWater Uses Microsoft Teams to Steal Logins

MuddyWater Attack Targets Organizations MuddyWater uses Teams to steal login credentials in new cyberattacks. Researchers linked the campaign to an Iranian-backed hacking group. However, the attackers disguised the operation as ransomware activity. Therefore, many victims first believed criminals caused the breach. The campaign appeared in early 2026. Researchers observed attackers using social engineering tactics through …

MuddyWater Uses Microsoft Teams to Steal Logins Read More »

BlackFile Extortion Group Fuels Global Vishing Attacks

Overview of the Threat New BlackFile extortion group drives a rise in vishing attacks. However, this group focuses on retail and hospitality sectors. Researchers report increased incidents since early 2026. Therefore, organizations now face higher risks of data theft. The attackers aim to steal credentials and demand large ransoms. As a result, businesses may suffer …

BlackFile Extortion Group Fuels Global Vishing Attacks Read More »

Threat Actor Uses Microsoft Teams for Malware

Overview of the Attack Threat actor uses Microsoft Teams to launch a new malware campaign. However, this attack relies heavily on social engineering tactics. Researchers discovered a custom malware suite called “Snow.” Therefore, attackers aim to steal sensitive data after gaining access. They focus on deep network compromise and credential theft. As a result, organizations …

Threat Actor Uses Microsoft Teams for Malware Read More »

Popular WordPress Redirect Plugin Hid Backdoor

Overview of the Issue Popular WordPress redirect plugin hid a hidden backdoor for years. However, many users remained unaware of the threat. Researchers discovered the issue after multiple sites triggered alerts. Therefore, the finding raised serious concerns about plugin security. The plugin had over 70,000 active installations. As a result, the potential impact is very …

Popular WordPress Redirect Plugin Hid Backdoor Read More »

Fake CAPTCHA IRSF Scam Triggers Costly SMS

Overview of the Scam Fake CAPTCHA IRSF scam campaigns are targeting mobile users worldwide. However, these scams use simple tricks to cause real financial damage. Researchers found that victims unknowingly send international SMS messages. Therefore, users face unexpected charges on their phone bills. The attackers earn money from these hidden fees. As a result, this …

Fake CAPTCHA IRSF Scam Triggers Costly SMS Read More »

Scroll to Top