< ciso
brief />
Tag Banner

All news with #malware tag

968 articles

ToxicPanda Android malware adds VPN and ADB abuse

🛡️ ToxicPanda 2.0 now requests VPN service permissions to create a local interface that can block Google Play and Google Play Services, enabling it to interfere with app verifications, updates, and Play Protect checks. After establishing the VPN, the malware extracts and installs payloads, requests Accessibility Service permissions, and automates Wireless ADB to gain shell-level access. Zimperium reports distribution via AWS-hosted buckets and notes support for 167 remote commands and overlays targeting 349 financial apps across 16 countries.
read more →

Supply-chain malware infects Android car head units

🔍 Kaspersky researchers say a supply-chain attack abused a legitimate DoFun update app to deliver JarService malware to Android-based car head units, attributing the campaign to the MoYu group. The loader retrieves encrypted payloads and exposes nine remote commands used to collect device metadata, run code, open URLs, and perform network checks. Operators primarily install a reverse-proxy module named zhima to convert head units into proxy nodes for ad fraud and monetization, while DoFun says it has remediated the issue.
read more →

Android head-unit malware expands automotive botnets

🔍 In June 2026, researchers discovered malware targeting Android-based car head units that is delivered via an automatic firmware-update service. The attackers exploit DoFun’s TWCore updater to install a hidden dropper called JarService, which downloads a clicker and a proxy module to enroll head units in a botnet. Infected devices are used for ad fraud and to provide residential proxy services, degrading performance and exposing cars to further payloads.
read more →

North Korean Supply Chain Attack Targets Rust Ecosystem

🔒 Wiz researchers linked a recent supply chain attack in the Rust ecosystem to state-sponsored North Korean actors. The campaign compromised maintainer accounts on crates.io to alter manifests and import a typosquatted dependency, allowing malicious build-time code to run during compilation. The backdoor aimed to harvest browser credentials, crypto wallets and developer secrets, affecting widely used crates including arrayref, internment and append-only-vec.
read more →

Agent Tesla v4 uses emoji obfuscation to evade detection

🛡️ KnowBe4 has identified a new Agent Tesla v4 campaign using emoji-based obfuscation and a JScript dropper to bypass detection and steal credentials. The lure leveraged a convincing BEC email spoofing a Philippine bank and instructing finance staff to open an attachment. The dropper embeds Unicode emoji characters to disrupt signature matching, then uses DonutLoader for reflective PE injection so the final binary never touches disk. Researchers advise updating email security and creating YARA rules that combine emoji patterns with JScript function calls to detect the threat.
read more →

Manic Android Malware Targets Banks and Messaging

🛡️ Manic is a recently observed Android threat combining banking malware and mobile spyware to target Ukrainian banks, government and identity services, messaging apps, and financial institutions across Europe. It is distributed via phishing sites and dropper apps impersonating utilities and abuses Android accessibility and notification permissions to capture credentials and perform device takeover. The family includes wrappers and implants with enhanced anti-analysis checks and can exfiltrate data via a novel multi-hop Wi‑Fi mesh relay using nearby compromised devices. ThreatFabric attributes active development to early 2026 with new deployments in July that introduced stronger lock-screen phishing and expanded capabilities.
read more →

ToxicPanda 2.0 and GoldDigger Expand Global Targeting

🛡️ Zimperium zLabs and IBM Trusteer detail updated Android banking trojans: ToxicPanda 2.0 and a new GoldDigger campaign. ToxicPanda now includes 167 remote commands, enhanced PIN-harvesting for over 140 banking and crypto apps, and ADB-based escalation techniques. GoldDigger leverages sophisticated packing and accessibility abuse to drive fraud, with active campaigns in South Africa and the U.K.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

ToxicPanda 2.0 Expands Targeting of Financial Apps

🔒 Security researchers at zLabs discovered ToxicPanda 2.0, an Android banking Trojan that now targets 140 banking and cryptocurrency apps and uses overlay-based credential theft against 349 financial institutions. The variant abuses the Android Accessibility Service to enable wireless debugging and attempts to obtain shell access via ADB, bypassing runtime prompts and enforcing persistence. New capabilities include stealing device lock credentials through screen overlays. Recommended defenses include blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging via MDM.
read more →

40 Malicious Firefox Extensions Target Web3 Wallets

🛡️ A cluster of 40 malicious Mozilla Firefox extensions has been identified stealing cryptocurrency wallet secrets by impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. Socket Threat Research attributes the extensions to a broader set of 77 related add-ons with shared code and infrastructure, a campaign they call Offside Wallet Theft Factory, active since March 2026. The threat actors used Supabase projects, Cloudflare Workers, and hard-coded C2 to exfiltrate recovery phrases, private keys, and credentials, often hiding malicious payloads behind benign sports-score or utility shells. Researchers warn the economics of disposable extensions and repurposing identities make the Firefox Add-ons ecosystem an attractive target.
read more →

U.S. warns of AI-driven attacks on Siemens PLCs

🔒 U.S. cybersecurity agencies issued a joint advisory warning that threat actors are using AI-generated Python scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) within U.S. critical infrastructure. The agencies—NSA, CISA, FBI, DOE, and EPA—noted ongoing activity that targets exposed PLCs by abusing vulnerabilities, outdated software, and weak authentication to gain read/write access and disguise tools as legitimate OT monitoring software. Operators are urged to inventory devices, apply updates, block internet access, and strengthen monitoring and access controls to reduce risk.
read more →

StopAndProtect: Operation Exposed by OPSEC Failures

🔍 Check Point Research uncovered a unique case where OPSEC mistakes exposed a global cyber crime operation named StopAndProtect. The investigation revealed accessible victim logs, screenshots, source code, and references to nearly 2,000 compromised WordPress domains, showing how attackers repurposed legitimate sites to host malware and manage campaigns. Researchers warn organizations to beware of unexpected CAPTCHA prompts and to keep systems and security software updated.
read more →

New macOS infostealer hijacks browsers for remote control

🛡️ Jamf Threat Labs uncovered a multi-stage macOS infostealer named AmnesiaStealer that uses a fake GitHub download page to trick victims into running a Terminal command which installs malware. The Rust-based loader retrieves a password-protected ZIP, deploys a universal Mach-O payload and collects passwords, Keychain items, browser data and other sensitive files. A distinct stream_module converts the victim’s Chromium browser into a remotely controlled session via WebSocket, allowing attackers to export cookies and perform browsing actions.
read more →

Infostealers Harvest 1.7 Billion Credentials in H1 2026

🔍 Flashpoint reports 7.4 million devices infected by infostealer malware in H1 2026, marking a 27% increase from the previous half-year. The company recorded 1.7 billion harvested credentials, with Vidar, StealC and Lumma as the top variants, and highlighted a shift to automated credential-processing ecosystems. The report also details rising vulnerability disclosures and growing underground AI-driven threats.
read more →

AmnesiaStealer targets macOS Chromium sessions

🛡️ Researchers disclosed a new Rust-based macOS infostealer, AmnesiaStealer, delivered via a fake GitHub “Download for macOS” page that tricks users into pasting a Base64 command into Terminal. The multi-stage dropper retrieves a password-protected ZIP and executes a Rust payload that harvests Keychain items, browser data, Apple Notes, Telegram, and files, while using the captured system password for privileged access. A second-stage remote_stream module enables operator-driven browser control over Chromium-family browsers via the Chrome DevTools Protocol to steal live sessions and evade detection.
read more →

WindRelay NFC Android Relay Malware Emerges

🔒 WindRelay is a new Android NFC relay malware deployed alongside the SpyNote RAT to enable contactless payment fraud. First observed in August 2025, it captures live card data via NFC and streams it in real time to fraudsters. Attackers use personalized social engineering and remote access to sideload the NFC reader covertly, turning the victim's phone into a payment proxy. The scheme pairs a victim-side reader with an attacker-side emulator and a shared C2 channel to relay EMV commands and enable card-present cashouts.
read more →

Fake CCleaner installer enables Chrome credential theft

🛡️ Researchers discovered a multi-stage Windows malware campaign that uses a fake CCleaner download to install a malicious Chrome extension called GhostDesk. The payload abuses Chrome to capture credentials, cookies, keystrokes, screenshots, and to inject arbitrary JavaScript into active tabs. Variants impersonating 7-Zip and Adobe Acrobat share the same C2 infrastructure and delivery mechanism. Malwarebytes recommends verifying download sources and using up-to-date anti-malware protections.
read more →

Chrome reduces Android notification abuse by billions

🔔 Google reports that Chrome's anti-abuse systems blocked over 7 billion unwanted Android notifications per day in Q1 2026. The company says notification abuse has become a vector for scams, malware, phishing, and fraudulent payment requests, prompting a layered "Swiss cheese" defense model. Chrome now auto-revokes notification permissions from inactive or repeatedly abusive sites and allows users to review and restore access via Safety Hub. The browser also limits message rates for disruptive sites and adjusted permission prompts to be less intrusive on Android.
read more →

Rise of polyglot file attacks and defenses

🛡️ Files created with the polyglot technique are increasingly used in cyberattacks to evade filters and confuse investigators. Attackers craft files that can be interpreted as multiple formats (for example, PNG or ZIP) so different applications or scanners see different contents. Real-world campaigns have used EXE/ZIP, PDF/DOC, MSI/JAR, DLL/HTML and multi-archive polyglots to deploy malware like PhantomPyramid, StrRAT, Ratty and IcedID. Defenses rely on consistent security hygiene and targeted testing of detection tools.
read more →

Real emails and clipper attacks hijacked payments

🛡️ Gen Threat Labs examined two H1 2026 campaigns where attackers used legitimately compromised accounts and local system manipulation to intercept payments. The first campaign abused corporate mailboxes to deliver JavaScript droppers that progressed through PowerShell and shellcode to modify proxy and browser settings for banking fraud. The second used a Rust-based clipboard clipper that replaced copied crypto addresses and read C2 pointers from Binance Smart Chain smart-contract data.
read more →