malware news
231 stories · page 2 of 5
First Malware Built Specifically for Car Head Units Fuels Botnet
Security researchers at Kaspersky have reportedly identified the first known malware specifically designed to target car head units. This novel threat has been linked to thenet, a botnet that has already compromised millions of devices globally. The discovery marks a significant development in the landscape of embedded system security, extending the reach of sophisticated malware to an…

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown
A widespread malware campaign targeting Minecraft players, dubbed "WeedHack," has continued to evolve and spread despite the takedown of its initial infrastructure in July. Cybersecurity researchers reported that over 6,300 attempts to access malicious sites associated with WeedHack were blocked in the past month, indicating ongoing activity.

Crooks push Mac malware through fake OpenAI Codex ads
Cybercriminals are leveraging sponsored search results to distribute macOS malware, impersonating legitimate AI coding assistants like OpenAI's Codex. The campaign, identified by researchers at Cato Networks, targets developers searching for these tools, directing them to deceptive download pages that prompt the execution of malicious commands.

The cybercrime supply chain has five stages, each with a price
The modern cybercrime ecosystem operates as a sophisticated, multi-stage supply chain, a significant departure from the outdated image of a lone attacker. This intricate structure involves distinct specialized roles, each with its own pricing model, allowing for a division of labor that enhances efficiency and profitability for criminal enterprises.

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
A zero-day elevation-of-privilege vulnerability, tracked as CVE-2026-69414 and dubbed "ShieldBreak," has been discovered in the Microsoft Malware Protection Engine, which is integral to Microsoft Defender. This flaw allows a local attacker with low privileges to escalate to SYSTEM-level access on affected Windows systems.

Foul Language: WordlistLoader Disguises Malware as Ordinary Text
A new report indicates that threat actors are employing a novel technique, dubbed "WordlistLoader," to obfuscate malware delivery, specifically targeting campaigns that resemble "ClickFix" operations. This method reportedly disguises malicious payloads as ordinary text files, making them more difficult for security systems to detect and analyze. The primary payload identified in these…

Fake GTA 6 Extended Look and demo sites deliver an infostealer
Cybercriminals are exploiting the widespread anticipation for Grand Theft Auto VI by distributing password-stealing malware through fake websites impersonating Rockstar Games. These sites, which appear in search results for a "GTA 6 demo" or "Official Download," lure visitors into downloading a malicious executable disguised as a game installer.

Tricky 'SynkLoader' Multitool May Herald Ransomware
Security researchers have identified a sophisticated new malware family, dubbed "SynkLoader," which exhibits advanced capabilities including screen hijacking for credential theft and a range of novel features. This multitool malware is believed to be a precursor to more damaging attacks, potentially including ransomware deployments, and is notable for its multilingual support and a return to…

Fake Codex Download Uses Google Sites to Deliver macOS Malware
A new campaign is leveraging sponsored search results and legitimate Google Sites pages to distribute macOS malware, tricking users into executing malicious commands under the guise of installing OpenAI's Codex. The campaign was detailed in a technical write-up published on August 24 by researchers at Cato Networks.

ToxicPanda Banking Trojan Matures into Enterprise Threat
The Android banking Trojan known as ToxicPanda has reportedly evolved, incorporating new features that significantly broaden its capabilities beyond financial application targeting. This maturation suggests a strategic shift by its operators, moving from primarily consumer-level financial fraud to potentially impacting enterprise environments and a wider array of user data. The expanded global…

Android car head units infected with proxy botnet malware through built-in software updaters
Kaspersky researchers have identified a new Android malware strain that infects car head units through their built-in software update mechanisms, turning these devices into tools for ad fraud and nodes in a proxy botnet. This marks the first documented instance of malware specifically targeting car head units with an infection chain tailored to such devices.

ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has undergone significant evolution, expanding its targeting to 349 applications across 16 countries and supporting 167 remote commands. A key new feature is its use of VPN service permissions to establish a local network interface, allowing it to control network traffic. This capability, observed in ToxicPanda 2.0, enables the malware to block communications…

Hackers infect Android car head units with proxy botnet malware
A supply-chain attack has compromised Android-based car head units, leveraging a legitimate device-update application to distribute malware that enlists affected devices into a proxy botnet or uses them for ad fraud. Cybersecurity researchers attribute the operation to the MoYu group, a threat actor previously linked to the BadBox malware botnet. This incident marks the first documented…

Malware Hijacks Android Car Head Units
Cybersecurity researchers have uncovered a new Android malware variant that leverages legitimate firmware update mechanisms in car head units to establish a proxy botnet. The malware, dubbed BADBOX by researchers, was first identified in June 2026 and represents the first documented instance of malware specifically targeting automotive infotainment systems through their native update channels.

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
Recent reports highlight the ongoing threat posed by several prominent banking Trojans, specifically identifying Manic, Grandoreiro, and ToxicPanda 2.0. These malware families are currently active, with Manic noted for its spyware capabilities, Grandoreiro for a persistent campaign across Latin America and Europe, and ToxicPanda 2.0 for an expanded operational scope. The collective activity of…

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
A sophisticated new software supply chain attack, dubbed "ChainDrop," has been observed infecting over 400 npm packages, including widely used libraries such as `keyv` and `cacheable-request`. This attack leverages a three-step process to steal credentials and propagate itself, highlighting a growing trend of attackers targeting the tools and environments developers use rather than just…

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
A recent report indicates that security researchers have uncovered 14 malicious npm packages designed to deploy a Linux backdoor identified as RedC2 4.0. These packages were reportedly masquerading as legitimate utilities related to calendar and streak tracking functionalities within the npm ecosystem. The discovery highlights an ongoing threat vector targeting developers and systems reliant…

New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously undocumented malware family, named SynkLoader, is being distributed through phishing campaigns targeting Microsoft Teams users. The attacks aim to steal credentials by presenting victims with a deceptive lock screen.

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
A novel malware family has been identified that specifically targets Android-based car head units, utilizing their built-in firmware update mechanisms for propagation. This sophisticated threat, reportedly linked to the MoYu Group, is designed to engage in ad fraud and to establish a proxy botnet. This marks a significant development as it is described as the first documented instance of…

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
A recent report highlighted several security incidents and developments, including a "Zombie Card" attack, a distributed denial-of-service (DDoS) attack against Threema, and the emergence of the Evooo1Bot Linux botnet. Additionally, T-Mobile reportedly severed a cable in an attempt to thwart attackers, while GitHub denied that artificial intelligence was responsible for a specific bug.…

Malware injected into popular Rust packages to steal developer credentials
The Rust Security Response Team has disclosed a supply chain attack that injected malware into several popular Rust packages, turning routine software builds into a mechanism for delivering infostealer malware to developers' machines. The incident was initially reported to the Rust team by Nextron Systems' research team.

New Agent Tesla Malware Variant Boosts Evasion Capabilities
A new variant of the Agent Tesla infostealer, designated version 4, has been identified by KnowBe4 researchers, incorporating enhanced evasion techniques and credential harvesting capabilities. This updated malware was observed in a sophisticated business email compromise (BEC) campaign specifically targeting finance departments.

Attackers impersonate popular AI brands to spread malware
Cybersecurity researchers have identified a widespread campaign where attackers impersonate popular artificial intelligence brands such as Perplexity, Claude, ChatGPT, and Copilot to distribute various forms of malware, including information stealers, backdoors, and malicious browser extensions. The findings are based on an analysis of 38 confirmed incidents over a 12-month period, from July…

Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are employing a novel technique to deliver two previously undocumented remote access trojans (RATs), E4del and PINHOLE, by embedding malicious commands within FTP server banners. This unusual method was first observed in July 2026 by MalwareHunterTeam and subsequently investigated by researchers at SOCRadar, who confirmed its continued use into August 2026.

The invisible passenger in your car
A new multi-stage Android malware, dubbed "The Invisible Passenger," has been discovered infecting Android-based automotive head units through their built-in software update mechanisms. The malware's ultimate goal is to facilitate ad fraud and establish a proxy botnet. This marks the first documented instance of malware specifically designed to target car head units through their unique update…

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive urging organizations to immediately patch critical vulnerabilities found in TrueConf software. This advisory comes as the Head Mare hacktivist group is reportedly actively exploiting these flaws to facilitate the distribution of PhantomCore malware. The directive underscores the urgency for all entities…

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads
A supply chain attack targeting the Rust ecosystem was recently reported, involving the brief availability of malicious versions of three popular Rust crates on crates.io, the official package repository. The incident stemmed from a compromised maintainer account, which was used to publish the tainted releases. These malicious versions incorporated a build script designed to download and…

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware
A sophisticated espionage campaign, dubbed "SilkParasite," has been uncovered, targeting government entities across Central Asia with previously undocumented malware strains, some of which show signs of AI-assisted development. Cybersecurity firm Bitdefender identified seven distinct malware families in use, five of which had not been previously documented, and linked the operation to…

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
A new Android malware, dubbed Manic, has been identified by ThreatFabric's Mobile Threat Intelligence team, active since at least February 2026. The malware, which is still under development as of July, combines features of banking malware and mobile spyware, enabling financial fraud, surveillance, and device control.

Hackers poison arrayref Rust crate to push infostealer malware
A widely used Rust library, arrayref, was compromised through its maintainer account to distribute infostealer malware during compilation, affecting developers' systems. The attack, which occurred on August 20, also impacted two other crates, append-only-vec and internment, within a 23-minute window.

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
This week's cybersecurity reporting highlights a diverse array of threats and developments, including the exploitation of legitimate signed drivers for malicious kernel operations, a significant cyber espionage campaign attributed to an Iran-based threat actor targeting academic institutions, and the proliferation of malware leveraging DLL sideloading techniques. The landscape also includes…

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
A new zero-day vulnerability, dubbed ShieldBreak and tracked as CVE-2026-69414, has been identified in the Microsoft Malware Protection Engine, a core component of Microsoft Defender. This elevation-of-privilege flaw allows a local attacker with low privileges to escalate their access to SYSTEM level on affected Windows systems.

'Grandoreiro' Malware Resurfaces With Mexico Campaign
The Grandoreiro banking Trojan has reportedly resurfaced, targeting entities within Mexico. This reappearance follows a previous law enforcement takedown operation against the malware. The current iteration of Grandoreiro is noted for incorporating new features designed to complicate its detection and analysis by security researchers and defensive systems.

Grok chat duped into swallowing injected instructions
xAI's Grok web chat agent is vulnerable to a novel prompt injection technique that utilizes encrypted instructions to bypass security filters, according to security researchers at Adversa AI. This method, dubbed "cryptographic context injection," allows an attacker to embed malicious, encrypted instructions on a webpage, which a summarizing AI model can then decrypt and execute.

Your Mac already has a built-in firewall. Here’s how to get more from it
macOS includes a built-in firewall designed to manage incoming network connections, providing a layer of security by determining which requests from applications and other devices are permitted or blocked. While the default settings are often sufficient for many users, adjusting them for specific scenarios, such as public Wi-Fi use or fine-tuning application access, can be complex due to the…

New Manic Android malware can exfiltrate data through nearby devices
A new Android malware, dubbed Manic, has been identified with a unique data exfiltration method that utilizes nearby infected devices when a direct connection to its command-and-control (C2) server is unavailable. This sophisticated malware has been active since at least February and combines capabilities for spyware, banking fraud, and remote control.

Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
Security researchers have identified a new variant of the ToxicPanda Android banking Trojan, dubbed ToxicPanda 2.0, which significantly expands its targeting capabilities. The zLabs team at Zimperium, a mobile security vendor, detailed their findings in a report published on August 19.

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
A newly identified cybercrime operation, dubbed "StopAndProtect" by researchers at Check Point, has co-opted nearly 2,000 compromised WordPress websites, transforming them into a criminal network for malware distribution, data exfiltration, surveillance, and ransomware deployment. The campaign was first observed in May 2026.

AI agent suggested installing a malware package. Engineer almost took its advice
An engineer at the software development firm Softjourn narrowly avoided installing a malicious software package after an AI programming assistant recommended it. The incident highlights a new supply chain attack vector where threat actors register packages with names "hallucinated" by AI models, a practice dubbed "slopsquatting."

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
A new malware-as-a-service (MaaS) campaign has been identified that integrates three distinct services: ClickFix for social engineering, ErrTraffic for malware delivery, and Cruciferra as a loader. This combination allows attackers to distribute malware while simultaneously disabling endpoint security measures.

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A new cyber espionage campaign, designated "SilkParasite," has been identified targeting government entities within Central Asian nations. The operation is notable for its use of seven distinct remote access tool (RAT) families, with five of these tools being previously undocumented. These newly identified RATs have been named DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT.…

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Cybersecurity researchers have uncovered a global cybercrime operation, dubbed "StopAndProtect," that leverages nearly 2,000 compromised WordPress websites to facilitate its malicious activities. The operation reportedly uses these hacked sites as a distributed infrastructure to spread various malware strains, maintain control over infected systems, and exfiltrate sensitive data, including…
Hunting MacSync Stealer infrastructure through behavioral pivots
Microsoft Defender Experts have reportedly identified and are actively tracking the infrastructure supporting the MacSync Stealer, an information-stealing malware targeting macOS systems. The malware is characterized by its use of rapidly rotating command-and-control (C2) domains, a tactic designed to evade detection and make tracking difficult. However, researchers have found that despite…

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
A new Mirai-based botnet, dubbed Evooo1Bot, has been observed targeting Linux-based routers and IoT devices since July 2026. The botnet, disclosed by Fortinet's FortiGuard Labs in mid-August, is designed for distributed denial-of-service (DDoS) attacks, credential theft, and establishing criminal proxy services.

Cavern C2 Framework Evolves With DNS and Google Apps Script
New analysis indicates that the Cavern command-and-control (C2) framework, attributed to Iranian nation-state actors, has undergone significant evolution. Researchers have observed the integration of DNS and Google Apps Script into the framework's operational mechanisms. This development suggests an effort to improve the stealth and resilience of the C2 infrastructure, particularly in…

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
A new Linux botnet, dubbed Evooo1Bot, has reportedly expanded its capabilities significantly beyond the typical distributed denial-of-service (DDoS) attacks commonly associated with Mirai-derived malware. This evolution marks a shift towards more sophisticated and persistent forms of compromise, according to recent reports.

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities
A financially motivated cybercrime group, identified as Storm-0501, has evolved its ransomware tactics to target cloud environments, specifically Microsoft Azure. This group, which Microsoft has been tracking since 2024, is noted for its ability to bridge on-premises Active Directory systems with cloud-native Microsoft Entra ID and Azure environments.

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110
A new multi-stage Rust-based macOS information stealer, dubbed AmnesiaStealer, has been identified as capable of hijacking Chromium-based browsers to give attackers live control over victims' sessions. This malware is part of a broader trend of evolving cyber threats, which includes the Kimsuky APT group integrating artificial intelligence into its attack operations, from generating decoy…