< ciso
brief />
Tag Banner

All news with #malware tag

1036 articles

Stored XSS in WordPress plugins leads to site takeovers

🛡️ Researchers observed threat actors exploiting stored cross-site scripting (XSS) flaws in two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create hidden admin accounts. Both high-severity issues require an authenticated session and are tracked as CVE-2026-94504 and CVE-2026-93836. The campaign delivered identical JavaScript from imgcdn1[.]com to plant a malicious plugin and establish multiple persistence mechanisms, including a secret login URL and a concealed administrator account.
read more →

ClingSTUN backdoor exploits unpatched IoT flaws

🔍 FortiGuard Labs has identified a Linux proxy backdoor named ClingSTUN that leverages unpatched internet-facing IoT vulnerabilities to turn devices into remotely controlled proxy nodes. The malware abuses legitimate public STUN servers to keep NAT bindings open and blend its traffic with normal VoIP/WebRTC communications. Operators deployed the campaign in three waves, expanding exploited vulnerabilities to at least 24 CVEs and adding hard-coded exploits to aid propagation. FortiGuard urges device inventory, prioritised patching and compensating controls where updates are unavailable.
read more →

Weekly Recap: NetScaler, FortiMail, and Major Threats

📰 This week’s recap highlights multiple actively exploited vulnerabilities, high-profile arrests, and evolving malware techniques that take advantage of small oversights. Notable items include Citrix NetScaler and FortiMail zero-days, arrests tied to ShinyHunters and KillSec operations, and novel attack methods like RedFlick delivering the CosmicPulse backdoor. The report stresses urgent patching and improved basic hygiene to reduce exposure.
read more →

Alleged Ploutus ATM Malware Author Appears in Court

🔒 The U.S. Department of Justice says the alleged developer of Ploutus malware, accused of orchestrating ATM jackpotting that stole millions, has appeared in U.S. court following his arrest. Known as "Prometheus" or "The Engineer," 50-year-old Anibal Alexander Canelon Aguirre faces multiple federal charges tied to attacks from February 2024 to December 2025. Authorities allege the stolen funds were laundered and transferred to accounts controlled by the Tren de Aragua criminal gang, which has been designated by U.S. agencies.
read more →

Android 17 locks Accessibility API under Advanced Protection

🔒 Google announced that Android 17 will restrict access to the AccessibilityService API to verified apps labeled as Accessibility Tools when Advanced Protection is enabled. The change aims to close a frequent attack vector abused by banking trojans and spyware while preserving assistive capabilities. Android 17 also introduces features like Intrusion Logging, USB Protection, Disabled WebGPU, Failed Authentication Lock, and visibility into apps checking Advanced Protection status.
read more →

WordPress backdoor rebuilds itself via multi‑vector persistence

🔍 Researchers detail a resilient WordPress backdoor, codenamed SC, that uses multiple persistence mechanisms across files, the database, and shared memory to continuously rebuild itself. The malware employs obfuscated code and a substitution-cipher decoder, hiding payloads in eight locations including drop-ins, themes, mu-plugins, cache, ZIP bundles, and System V shared memory. It communicates using the Ethereum blockchain for C2, fingerprints infected sites, creates hidden admin accounts, and can deploy skimmers or arbitrary PHP/JS. Sucuri warns the infection acts as a system rather than a single file, restoring itself on the next request from any surviving copy.
read more →

CloudSyncD macOS backdoor hidden in fake Zoom installer

🛡️ A new macOS backdoor, CloudSyncD, has been distributed inside a fake Zoom installer that prompts users for their login password before launching an embedded second-stage payload. Jamf Threat Labs first observed development builds on September 15 and identified samples targeting live C2 infrastructure two days later, indicating active deployment. The installer instructs users to bypass Gatekeeper, presents a bogus authorization prompt, and validates the entered password locally before using it to escalate the second-stage payload.
read more →

Custom ChatGPT variants used to push RAT malware

🔒 Researchers at Huntress found threat actors publishing malicious custom GPTs on OpenAI that steer users to a Google Sites page hosting a fake Cloudflare check and a PowerShell command. If executed, the command installs an MSI that sideloads a modified DLL to deliver a remote access trojan (RAT) with remote desktop, audio/camera capture, reconnaissance and persistence functionality. OpenAI removed one GPT by September 25, but variants persisted; the campaign leverages legitimate ChatGPT hosting to increase credibility and employs an encrypted custom archive to conceal components.
read more →

Star Blizzard adopts RedFlick to streamline malware delivery

🛡️ Since January 2026, Microsoft observed Russian state-affiliated actor Star Blizzard refine large-scale phishing, use compromised-site accounts, and adopt a novel malware delivery technique called RedFlick. RedFlick leverages scheduled tasks to deploy the actor’s Python backdoor CosmicPulse, reducing required user interaction to a single response and improving evasion. Microsoft details observed TTPs, IOCs, mitigations, and detection guidance to help organizations defend against this evolving threat.
read more →

RatHat C2 evolves into malware-as-a-service hub

🔍 Research shows the RatHat Android banking trojan's backend evolved far more than the implant itself, with successive C2 panels that can build malware, manage infected devices and use AI to prioritize victims. Cleafy observed three panel generations and a rebrand from BlackCat to Panda Workshop between late 2025 and September 2026, with nearly 100 deployments since April 2026. Panels now support operator 2FA, phishing page builders, role-based accounts and the ability to deploy a native Go service for shell-level persistence outside app permissions.
read more →

NeedyMantis malware enables persistent access

🔒 Microsoft analyzed a malware family called NeedyMantis, used to maintain long-term access in targeted intrusions affecting telecoms, universities, medical nonprofits, intergovernmental organizations, and contractors. The activity dates back to at least October 2025 and was discovered while investigating the DAEMON Tools supply chain compromise. NeedyMantis operates via DLL sideloading: a legitimate program, a malicious DLL, and an encrypted archive load in sequence to unpack and run a main component that connects to a C2 over HTTPS and WebSocket. Microsoft published file hashes, domains, file paths, hunting queries, and Defender detection names to help defenders identify and remediate infections.
read more →

RatHat Android banking trojan console exposed

🛡️ Cleafy links the RatHat Android banking trojan to a web-based control console used in nearly 100 deployments since April 2026. The console stores stolen data from infected phones and can build, sign, and publish malicious apps automatically. Its latest variant uses Google's Gemini AI to estimate victims' bank balances and prioritize high-value targets. Operators gain one-click shell access via ADB and a Go-based agent that streams the screen without permission prompts on older Android versions.
read more →

NeedyMantis: Modular post‑compromise malware analysis

🛡️ Microsoft Threat Intelligence describes NeedyMantis, a modular post‑compromise malware family observed since October 2025 in targeted intrusions against telecoms, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware is typically deployed after initial access to maintain persistent access and support follow‑on operations. NeedyMantis uses multiple loaders, a custom encrypted archive format, a bespoke executable layout, and modular components to evade analysis and extend capability. Microsoft links observed activity to Storm‑3069 and activity consistent with Chinese‑aligned threat actors, and provides IOCs, Defender detections, and mitigations.
read more →

Carbonato botnet exploits exposed Docker daemons

🔍 Cybersecurity researchers disclosed a new botnet named Carbonato that targets unauthenticated Docker daemons to deploy the open-source Hermes Agent AI framework. The malware installs the agent, overwrites its SOUL.md persona to accept Telegram commands, and uses privileged containers, reverse SSH tunnels, cron jobs and watchdogs to maintain persistence and propagate. ThreatDown traced artifacts to an exposed Docker registry and found the campaign includes other malicious operations such as trojanized crypto wallets.
read more →

Lunex Stealer abuse of AMD driver escalates threat

🛡️ Ontinue details a four-stage attack chain distributing Psychedelic (LunexStealer) via compromised Ukrainian sites using ClickFix-like CAPTCHA lures. The chain uses bogus MSI installers to deploy LunexLoader, bypass UAC, and leverage a vulnerable AMD Radeon driver (PDFWKRNL.sys, CVE-2023-20598) for BYOVD-based defense evasion before installing a PowerShell-backed native messaging host. The stealer harvests browser credentials, cookies, and desktop and extension cryptocurrency wallets while persisting via registry, scheduled tasks, and a malicious Chrome extension.
read more →

Compromised GitHub Actions Reenabled, Risk Renewed

🔒 Two GitHub Actions that were compromised in May 2026 and disabled by GitHub were re-enabled on September 16, 2026, restoring access to repositories containing unremediated malicious release tags. Socket researcher Karlo Zanki warned that workflows referencing the affected tags resumed downloading and executing the May 18 payload, which harvests CI/CD secrets and exfiltrates them. Developers are urged to pin to pre‑compromise SHAs, rotate secrets, audit workflow history, and remove or replace the affected actions.
read more →

MacSync uses iCloud calendars to load payloads

📌 A new MacSync variant for macOS now leverages public iCloud calendar events to deliver follow-on payloads. Kaspersky found the Swift-based infostealer being distributed via ClickFix-style social engineering and fake apps, with a downloader extracting commands from calendar DESCRIPTION fields to fetch archives hosted on iCloud. The malware retains broad credential-stealing capabilities and added an Objective-C backdoor that persists via LaunchAgents, .zshrc changes, and Git hooks.
read more →

Carbonato malware hijacks exposed Docker hosts

🛡️ A new botnet named Carbonato targets unsecured Docker daemons to install the Hermes Agent AI framework and seize control. Researchers from Malwarebytes ThreatDown found evidence from October 2024 to August 2026 showing worm-like spreading via unauthenticated Docker APIs on port 2375. The malware launches privileged containers, opens reverse SSH tunnels, installs operator keys, and establishes persistence mechanisms while reporting deployments over Telegram.
read more →

Weekly ThreatsDay: AI Search Poisoning and Malware

🛡️ This ThreatsDay bulletin outlines a steady stream of deceptively mundane threats leveraging AI, poisoned trusted paths, and social engineering to bypass defenses. Highlights include an AI-assisted Android banking trojan, AI code privacy concerns from Z.ai, and FBI/CISA guidance on ICS integrator access. Also covered are super-app surveillance findings, browser-in-the-browser phishing, novel EDR evasion, and large-scale AI search poisoning campaigns targeting major brands.
read more →

Sophisticated npm Malware Evades Defenses

🔒 The article describes a sophisticated malware campaign delivered via npm packages that appears to be highly advanced. The author notes the complexity and capabilities suggest a nation-state level actor, though no definitive attribution exists. Posted on September 24, 2026, the brief entry highlights concern about supply-chain risks and the ability of such packages to bypass existing defenses. The post is succinct and calls attention to the evolving threat landscape.
read more →