LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day

malware news

231 stories · page 5 of 5
threat actor

UAT-7810 continues building ORB networks using new malware

Cisco Talos is tracking an advanced persistent threat (APT) actor known as UAT-7810, which is actively developing and deploying new malware to expand its "Operational Relay Box" (ORB) networks. These networks are believed to be used by secondary threat actors to conduct attacks against high-value targets. UAT-7810 was previously identified as the entity responsible for the LapDogs ORB network.

malware

Fake IT support calls on Microsoft Teams push EtherRAT malware

Threat actors are leveraging Microsoft Teams voice calls to impersonate IT support staff and trick employees into installing the EtherRAT malware, according to research from Palo Alto Networks' Unit 42. This tactic grants attackers initial access to corporate networks. The operation combines phishing emails, Teams voice calls, legitimate remote management tools, and a custom malware loader to…

ransomware

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

This week's cybersecurity landscape saw a surge in vulnerabilities affecting seemingly ordinary components, from home streaming devices to fundamental web elements. Researchers highlighted how everyday technologies, typically not considered high-risk, became vectors for malicious activity, underscoring a broad and evolving threat environment.

phishing

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

A sophisticated cyber-espionage campaign, attributed to a threat actor with suspected ties to China, has been identified targeting Indian taxpayers, tax professionals, and corporate finance departments. The objective of this operation appears to be the deployment of a remote access trojan (RAT) known as DcRAT, with the ultimate goal of exfiltrating sensitive data from compromised systems.

breach

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

Researchers have developed a novel method, dubbed TrojPix, capable of exfiltrating data from air-gapped systems by manipulating on-screen pixels. This technique exploits the electromagnetic emissions generated by video cables to transmit sensitive information.

malware

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

Security researchers have identified a new Java-based remote access trojan (RAT) named QuimaRAT, which is designed to operate across Windows, Linux, and macOS operating systems. This cross-platform capability makes it a versatile tool for attackers targeting a wide range of user environments.

malware

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Researchers have developed a technique called SkillCloak that allows malicious AI agent skills to evade static analysis scanners. This method utilizes self-extracting packing to disguise the malicious code, rendering it undetectable by current security tools. The findings come from a study conducted by researchers at the Hong Kong University of Science and Technology.

ransomware

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

A newly identified modular malware framework, dubbed Avalon, has been observed incorporating the capabilities of the CrownX ransomware. This sophisticated framework is being distributed through a multi-stage phishing campaign designed to circumvent standard security measures.

apthigh

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign

A newly identified threat actor, dubbed Armored Likho, has been observed conducting targeted phishing campaigns against government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. This group, also referred to as Eagle Werewolf based on circumstantial evidence, employs a sophisticated toolkit that includes a previously undocumented information stealer named BusySnake…

malware

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation, in collaboration with industry partners, has seized hundreds of domains associated with NetNut, a large residential proxy service operated by the Israeli company Alarum Technologies. This action follows recent reports from security firms that linked NetNut to the Popa botnet, a network of at least two million compromised devices.

malware

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

A newly identified malware strain, dubbed Umbrij, is being employed by the threat actor group ToddyCat to gain unauthorized access to Gmail accounts. This malware leverages the Google API to achieve its objectives, potentially compromising sensitive email communications.

vulnerability

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

A new Remote Access Trojan (RAT) named ChocoPoC is being distributed through deceptive proof-of-concept (PoC) exploit repositories on GitHub, specifically targeting vulnerability researchers. These malicious repositories masquerade as legitimate sources for code demonstrating newly discovered vulnerabilities, aiming to trick security professionals into downloading and executing the malware.

malware

And the Winner in Dominant Malware Delivery? ClickFix

A sophisticated social engineering tactic, previously considered an outlier, has become a prevalent method for delivering malware, according to security researchers. This technique, which leverages user interaction to facilitate malicious payloads, is now frequently employed in cyberattacks.

banking trojanhigh

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

Researchers have observed a new campaign by the banking Trojan Ousaban, which is actively targeting users in Spain and Portugal. This malware, previously known for its activity in Brazil, is being distributed via a sophisticated phishing scheme that employs geofencing and environmental checks to limit its reach.

iranhigh

Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool

A cyber-espionage group identified as TAG-182, believed to be operating on behalf of the Iranian government, is actively distributing a surveillance tool known as MarkiRAT. This malware is being disseminated through fake applications designed to mimic legitimate services like VPNs and media players, with the apparent aim of collecting intelligence on Iranian targets both within and outside the…

phishing

Phishers Gain Persistence at EU, Asia Hospitality Orgs

Cybercriminals are employing sophisticated phishing campaigns targeting organizations in the European Union and Asia, leveraging malicious zip files and social engineering tactics to gain a foothold and establish persistence. These attacks, observed by Microsoft and Trend Micro, utilize obfuscation techniques and even exploit blockchain technology to evade detection and deliver malware.

malware

USB drives carrying China-linked malware infected Japanese military networks for nearly a year

Internal documents indicate that counterfeit USB drives infected with malware, linked to Chinese state-sponsored operations, were used on sensitive Japanese military networks for nearly a year. The Ground Self-Defense Force (JGSDF) reportedly received these compromised drives in March 2024, during disaster relief efforts following an earthquake in central Japan. This bypass of standard…

breach

Iran, Russia, China Target Water Systems for Sabotage

Nation-state actors, reportedly from Iran, Russia, and China, have successfully infiltrated industrial control systems within the water sector, exploiting basic security vulnerabilities rather than advanced malware. These attacks have targeted Programmable Logic Controllers (PLCs) that manage critical water infrastructure operations.

malware

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

A Russian advanced persistent threat group known as Gamaredon has reportedly updated its toolkit, necessitating new defensive strategies. The group, also referred to as Primitive Bear or Callisto Group, has been active for several years, primarily targeting entities in Ukraine.

gamaredonhigh

Gamaredon Group Evolves Tactics With New Tools and Alliances

The Russia-aligned advanced persistent threat (APT) group Gamaredon, also known as UAC-0010, maintained a high operational tempo throughout 2025, primarily targeting governmental and military institutions in Ukraine. The group, which the Security Service of Ukraine (SSU) attributes to the 18th Center of Information Security of Russia's FSB, significantly evolved its tactics, tools, and…

supply chainhigh

OpenClaw Skill Marketplace Faces AI Supply Chain Threat

OpenClaw, a platform for AI agents that execute third-party skills from its dedicated marketplace, ClawHub, has been targeted by persistent and evolving malicious campaigns. These attacks leverage the unique architecture of AI agent ecosystems, where skills, defined by markdown-driven packages, possess broad access to local systems, making ClawHub a critical vulnerability in the agentic…

macoshigh

macOS Backdoor Uses Fake Messages to Evade AI Analysis

A newly identified macOS backdoor, tracked as macOS.Gaslight, employs a sophisticated technique to evade security analysis by embedding fabricated system messages designed to mislead AI-powered security tools. Researchers have assessed with high confidence that this implant is linked to North Korean state-aligned threat activity.

supply chain attackhigh

Miasma Worm Exploits Developer Credentials in Supply Chain Attacks

A sophisticated supply chain attack campaign, dubbed Miasma, has targeted multiple organizations by exploiting stolen developer credentials, leading to the compromise of numerous software packages. The campaign, which began on June 1, affected packages within Red Hat, Vapi.ai, and Microsoft Azure repositories. Researchers observed that the malicious packages generated by Miasma included valid…

malwarehigh

Lost in relocation: analysis of a new loader distributing CASTLESTEALER

A newly identified malware loader, dubbed OXLOADER, is being distributed through malicious Google advertisements, aiming to deliver the CASTLESTEALER information-stealing malware. Security researchers have observed OXLOADER employing a range of sophisticated obfuscation techniques to evade detection by static analysis tools and sandbox environments.

malware

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

A sprawling Android-based botnet known as Popa, which has been active for four years, has been linked to NetNut, a residential proxy service operated by the publicly-traded Israeli firm Alarum Technologies Ltd. Researchers have concluded that Popa, which forces millions of consumer TV boxes to relay internet traffic, is used for advertising fraud, account takeovers, and extensive data-scraping…

phishing

Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed

AI coding assistants can be tricked into leaking sensitive company information through specially crafted bug reports, bypassing traditional security measures like phishing emails or malware. This vulnerability arises from the extensive trust and access granted to these AI tools, which can read code, browse file systems, and execute commands.

malwarehigh

Threat Actors Weaponize AI Hype to Deliver AsyncRAT

Cybercriminals are leveraging the widespread interest in artificial intelligence to distribute malware, according to a recent analysis by FortiGuard Labs. Threat actors are creating malicious files that appear to be guides or resources related to AI, aiming to trick individuals searching for information on the technology.

fifa world cup

Cybercriminals Are Targeting the FIFA World Cup 2026

Cybercriminals are actively targeting the upcoming FIFA World Cup 2026, establishing infrastructure and launching various scams to exploit the event's global appeal, according to research from FortiGuard Labs. The tournament, set to begin on June 11, 2026, is expected to attract significant attention and drive a high volume of digital transactions, creating a fertile ground for malicious actors.

iothigh

Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO

FortiGuard Labs has identified a new variant of the Gafgyt botnet, dubbed C0XMO, which exhibits cross-platform propagation capabilities by exploiting a vulnerability in DD-WRT router firmware. The malware, discovered in March, utilizes CVE-2021-27137 to gain initial access. A notable characteristic of C0XMO is its separation of lateral movement functions into a distinct Python script, allowing…

espionagehigh

Gamaredon Facilitated Turla's Access to Ukrainian Targets

ESET researchers have uncovered evidence of collaboration between the Gamaredon and Turla espionage groups, with Gamaredon actively enabling Turla's access to Ukrainian targets. Between February and June 2025, Gamaredon's tools were used to deploy Turla's Kazuar backdoor and restore access. This partnership highlights a division of labor where one group establishes access and the other deploys advanced espionage tools.

phishinghigh

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

A recent phishing campaign is distributing a variant of the PureLogs malware, designed to steal sensitive data from compromised Windows systems. The campaign employs a multi-stage attack chain involving obfuscated JavaScript, PowerShell, and process hollowing techniques.

malware

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities have arrested a 23-year-old Ottawa man, Jacob Butler, also known online as "Dort," on charges related to the creation and operation of the Kimwolf botnet. The botnet, which allegedly enslaved millions of Internet of Things devices, was used in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. Butler faces criminal hacking charges in…

malwarehigh

Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows

Microsoft's legacy HTML Application Host (MSHTA) utility continues to be a significant tool for cybercriminals to distribute various types of malware on Windows systems, according to recent analysis. Despite being an older component, MSHTA's ability to execute VBScript and JavaScript from both local and remote files makes it a valuable asset for attackers seeking to deploy everything from…

CVE-2025-55182high

EtherRat and TukTuk Malware Campaigns Lead to The Gentleman Ransomware

Malware campaigns utilizing EtherRat and TukTuk have culminated in the deployment of The Gentleman ransomware, according to recent analyses. These campaigns demonstrate a sophisticated, multi-stage approach, leveraging various tools and techniques to achieve initial access, maintain persistence, exfiltrate data, and ultimately encrypt systems.

CVE-2025-29927high

Cloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts

A newly identified cloud worm, dubbed PCPJack, is actively targeting exposed cloud infrastructure to steal credentials and remove any artifacts associated with the threat actor group TeamPCP. SentinelLabs researchers discovered the framework, which operates as a credential theft toolset that propagates across cloud environments.

chromehigh

Protecting Cookies with Device Bound Session Credentials

Google's Chrome browser is introducing a new security feature called Device Bound Session Credentials (DBSC) for Windows users, with support for macOS planned for the near future. This development is designed to significantly enhance protection against session hijacking, a common attack vector where attackers gain unauthorized access to user accounts by stealing session cookies.

malwarehigh

Windsurf IDE Extension Drops Malware via Solana Blockchain

Security researchers have identified a malicious extension for the Windsurf Integrated Development Environment (IDE) that leverages the Solana blockchain to deploy a multi-stage malware payload. The extension, masquerading as a support tool for the R programming language, was designed to steal sensitive data from Chromium-based browsers.

breach

Bypassing Administrator Protection by Abusing UI Access

A security researcher has detailed multiple vulnerabilities in Windows' User Account Control (UAC) system, specifically concerning the "UI Access" feature, which were present even before the introduction of Administrator Protection. These bypasses, totaling nine discovered by James Forshaw, have since been addressed by Microsoft. This article focuses on five of these issues, stemming from the…

vulnerability

Bypassing Windows Administrator Protection

Microsoft's Administrator Protection feature, intended to replace User Account Control (UAC) with a more secure system for granting administrator privileges in Windows 11, has been found to be bypassable. The feature, introduced in Windows 11 version 25H2, aims to allow local users to access administrative rights only when necessary, creating a more robust security boundary. However, security…