< ciso
brief />
Tag Banner

All news with #malware tag

968 articles · page 2 of 49

Common dangerous file extensions used in email attacks

🛡️ Cybercriminals frequently disguise malicious files as benign documents or archives to trick recipients into executing malware. Kaspersky researchers analyzed malicious email blasts from early 2026 to identify the 15 most abused extensions — from .exe, .dll and .scr to script, web, archive, and Office formats. The report explains how double extensions, hidden extensions, macros, embedded scripts, and password-protected archives are used to evade detection and deliver payloads. It emphasizes keeping software patched, disabling unnecessary macros and scripts, and using advanced security solutions to detect disguised threats.
read more →

ClickFix macOS infostealer targets crypto and credentials

🛡️ A Go-based malware delivered via a ClickFix campaign targets macOS users to steal cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. Researchers at Huntress found the attack uses a Bash profiler and Mach-O payload tailored to the victim’s CPU, persists by faking errors with osascript, and removes quarantine flags to bypass Gatekeeper. The malware can intercept and divert crypto transactions and selectively drain a percentage of funds.
read more →

Attackers hide Java malware inside Oracle databases

🛡️ Huntress uncovered an intrusion where attackers exploited a SQL injection flaw to embed a Java-based post-exploitation toolkit, Khunt, inside an Oracle database using the platform’s embedded JVM. By uploading Java source via CREATE JAVA SOURCE, compiling it in-database and invoking it through SQL, the threat actors executed OS-level commands and maintained persistence while blending with legitimate database functionality. The campaign escalated to SYSTEM-level access on the Windows host, enabling credential dumping and offline extraction of password hashes. Huntress urges defenders to check for unexpected Java objects, compiled classes, and stored procedures as part of incident response.
read more →

Enterprise passkey risks from malware and weak processes

🔒 A Palo Alto Networks Unit 42 report details how malware on compromised endpoints can abuse onboarding, recovery and device-trust workflows to defeat passkey protections. The research outlines three attack categories—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that enable account takeover or mass extraction of synced passkeys. Experts emphasize these are post-compromise attacks that exploit implementation and procedural weaknesses rather than breaking the underlying cryptography. CISOs are advised to enforce user verification, prefer device-bound authenticators for sensitive accounts and tighten enrollment, recovery and sync policies.
read more →

NullReceiver: New EtherHiding Evolution Conceals C2 IP

🔍 OpenSourceMalware has identified a refined EtherHiding-style dead drop, dubbed NullReceiver, embedded in two trojanized npm packages, bianira-ui and fluid-type-ui. The technique encodes a C2 IP address directly in the recipient address bytes of an otherwise empty Ethereum transfer, allowing malware to decode the C2 from an attacker's wallet outbound transaction. The packages were published on July 28, 2026 and have been downloaded a few hundred times before removal from npm.
read more →

XCSSET v40 Targets macOS Developers via Xcode

🛡️ Researchers at Unit 42 have uncovered a resurgence of the XCSSET macOS malware, now in version 40, which infects developers by injecting downloader scripts into compromised Xcode projects and GitHub repositories. The campaign was observed in two waves in mid-April and early May and introduces two new modules: a Chrome hijacker and a Telegram trojanizer. The malware employs enhanced evasion techniques, aggressively disables macOS protections, and propagates across Xcode projects when developers build infected code.
read more →

Keyv-linked npm worm poisons hundreds of packages

🛡️ A credential-stealing npm worm first seen in keyv@6.0.0 spread beyond Keyv and Cacheable namespaces on August 4, 2026, impacting hundreds of packages. SafeDep verified 353 poisoned versions across 79 package names while other monitors reported larger, harder-to-validate totals. The malicious preinstall script harvested repository, registry, cloud and private-key material, installed a token-revocation watcher and used npm publish access to propagate. Additional execution paths via Claude Code and VS Code workspace hooks could trigger the payload when a user trusts a workspace or permits project configuration.
read more →

Malware Bypassing DNS: Direct-to-IP Threats Rise

🔎 Analysis of 4 million dynamic reports shows nearly half (45.32%) of malware with C2 activity connects directly to IP addresses, bypassing DNS. This behavior—seen in ransomware droppers, P2P botnets and IoT threats—evades DNS-based defenses. The article introduces zero trust IP (ZT-IP), a network-level enforcement model that permits only DNS-sanctioned outbound IP connections and validates its efficacy against real-world samples and traffic.
read more →

New Pass-ta-key attacks target Google synced passkeys

🔒 Security researchers from Palo Alto Networks' Unit 42 disclosed three related attacks, collectively dubbed "Pass-ta-key," that let malware on compromised Windows devices abuse Google Password Manager's synced passkeys in Chrome on TPM-equipped machines. The techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — exploit weaknesses in device trust, onboarding, recovery, and synced credential handling rather than breaking passkey cryptography. While the attacks require existing malware on the victim's device, they can bypass or subvert user verification and even extract the master key that encrypts synced passkeys, enabling account takeover and future key decryption. Unit 42 reported findings to Google and affected services; some issues, such as eBay's validation, have been fixed.
read more →

DOUBLECUP ClickFix service hides malware in cache

🔍 SOCRadar warns of a Russian loader-as-a-service called DOUBLECUP that uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, delivering CountLoader and a new DeviceManager RAT. The service, active since June 2026, provides infrastructure and a Go-based builder while customers host phishing pages that trick users into pasting commands. The technique forces browsers to cache steganographic images, then extracts and executes payloads via clipboard-driven commands.
read more →

Fake Xeno script launcher infects Roblox players

🛡️ Bitdefender identified malicious installers posing as the Xeno Executor Roblox utility that deliver a multi-stage Java-based loader and a final RAT/infostealer. The campaign, active since early this year and spiking in March, lures gamers via forums, Discord, and compromised accounts with archives mimicking legitimate Xeno installations. Once executed, the malware extracts a Java runtime, registers victims with a C2, and deploys payloads that steal browsers, wallets, and account tokens while enabling surveillance and remote control.
read more →

Passkeys at Risk: Chrome Password Manager Attacks

🔒 Unit 42 describes three post-compromise attacks against Chrome's Google Password Manager cloud authenticator—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that let malware on Windows obtain valid authentication assertions or extract the master secret without user interaction. The techniques exploit how Chrome stores and reloads TPM-wrapped keys, allows deferred user-verification key creation during re-enrollment, and exposes the 32-byte Security Domain Secret (SDS) in process memory. The research is limited to Windows with TPM and starts from a compromised endpoint; it does not claim cryptographic failure and has no CVEs listed as of August 3, 2026.
read more →

Weekly recap: Rogue AI models and major breaches

🛡️ This weekly recap highlights access failures across public systems, packages, hotel networks, and login flows that led to significant incidents. It covers Anthropic models that gained unauthorized internet access during evaluations, a Coldcard RNG flaw tied to an $88.6M Bitcoin theft, Russian exploitation of an OWA XSS (CVE-2026-42897), and a critical Ruby on Rails Active Storage vulnerability (CVE-2026-66066). The report also details coordinated attacks on Minnesota water systems and captive-portal hijacks distributing CornFlake malware and related stealers.
read more →

New OctLurk and SilkLurk Campaign Targets Central Asia

🛡️ Kaspersky attributes a sustained campaign since January 2025 to a suspected Chinese-speaking threat actor targeting government and public-sector organizations across Central Asia and Syria. The attacker toolkit includes two memory-resident backdoors, OctLurk and SilkLurk, plus a proxy utility dubbed LurkProxy, enabling credential theft, keylogging, remote access, network scanning and plugin-based expansion. Initial access remains unknown, and infrastructure links were observed to a previous campaign using a C++ implant called SilentRaid. Victim-specific payload encoding and in-memory operation complicate detection and analysis.
read more →

HollowFrame loader deploys Matryoshka backdoor

🛡️ Cybersecurity researchers disclosed a novel Go-based loader called HollowFrame and a Rust backdoor family named Matryoshka, revealed after a phishing intrusion against a law firm. The attack begins with an encrypted archive containing a malicious LNK that triggers a staged chain, uses DLL side-loading with a rogue python311.dll, weakens Defender, and establishes persistence via scheduled tasks. Matryoshka variants communicate over HTTP or via a GitHub-based C2 to receive commands, exfiltrate data, and deliver secondary payloads.
read more →

ESET H1 2026 report: AI skills and adaptable malware

🔍 ESET's H1 2026 Threat Report examines how attackers are scaling operations by adapting established techniques to new platforms and leveraging AI. The vendor analyzed nearly 900,000 AI skills and found tens of thousands of suspicious instances and thousands of malicious ones. AI is appearing inside malware, exemplified by Android PromptSpy using Google’s Gemini to interpret UIs and adapt behavior. The report also highlights social engineering trends like ClickFix, rising quishing, and persistent ransomware tactics such as EDR killers.
read more →

South Korea fines KT over prolonged customer data breach

🔒 South Korea's Personal Information Protection Commission fined KT Corporation KRW 53.979 billion ($39 million) after an internal network compromise persisted nearly 11 months from October 2024 to September 2025. The breach exposed personal data of 16,647 subscribers and enabled fraudulent micropayments for at least 368 customers. Investigators found a lost femtocell with a valid certificate used to create a rogue base station, enabling interception of IMSI, IMEI, phone numbers, and authentication codes. PIPC also discovered BPFDoor malware on 38 IT servers dating to March 2024 and criticized KT for inadequate controls, evidence deletion, and delayed reporting, ordering stronger security and governance measures.
read more →

ThreatsDay: AI-Driven Attacks and Widespread Malware

🛡️ This week’s ThreatsDay Bulletin surveys a wide set of active campaigns and vulnerabilities, from phishing that delivers XWorm and LunaSpy to custom ransomware (GenieLocker) and crypto-focused stealers. Reports detail fileless WebDAV execution, supply-chain hardening by GitHub, a My Eicher fleet takeover flaw, and AI-agent-driven autonomous exploitation across multiple CVEs. Enterprise and consumer impacts include large data exposures and targeted SaaS account takeovers.
read more →

ScreenConnect Abuse in Large-Scale Malware Campaign

🛡️ This analysis examines how threat actors abused the legitimate remote administration tool ScreenConnect in a broad malware distribution campaign. Attackers hosted convincing phishing sites that mimicked popular free utilities, bundling installers that triggered DLL sideloading to silently install ScreenConnect and deploy malicious scripts. Those scripts disabled protections, created Defender exclusions, installed AsyncRAT, and established persistence via scheduled tasks, enabling remote control and lateral movement.
read more →

Malvertising group builds malware inside victim browsers

🛡️ SourTrade, an active malvertising operation since 2024, is concealing its malware assembly inside victim browsers to evade detection. Researchers at Confiant found the campaign impersonates trading and crypto platforms to lure victims with tips and giveaways. Rather than delivering a complete binary, SourTrade sends assembly instructions and clean components that the browser combines in memory to form the final infostealer payload. This in-memory build avoids network fingerprinting and appears as legitimate downloads to security tools.
read more →