< ciso
brief />
Tag Banner

All news with #malware tag

1036 articles · page 3 of 52

Mass scanning of exposed Vite dev servers steals cloud secrets

🛡️ A large-scale campaign is scanning internet-exposed Vite development servers to extract AWS and Azure credentials by exploiting CVE-2026-39364 in affected Vite versions. F5 detected over 800 attacks and ~32,000 events, observing attackers append parameters like ?raw or ?import&raw to bypass file access controls and retrieve sensitive files. The operation targeted environment files, cloud credential/config files, Terraform and serverless state, and system files, using traversal and encoding tricks for evasion.
read more →

Smart TV and Set‑Top Box Proxyware Risks

🛡️ A recent analysis shows cheap smart TVs and TV boxes are increasingly recruited into proxyware and botnets, turning household devices into gateways for malicious traffic. Infected devices often run multiple proxy clients concurrently and can expose internal network resources, allowing remote attackers to reach router admin panels and other devices. The study of a popular SuperBox model revealed persistent malware, remote code execution via firmware flaws, and over 1,300 attacks in three weeks. Users are advised to monitor network traffic, avoid dubious apps and devices, disconnect compromised hardware, and protect routers with strong unique passwords and reputable security tools.
read more →

Threat Actors Exploit Trusted AI Platforms

🛡️ Huntress warns that attackers are abusing trusted AI platform features—like shareable artifacts, public conversation links, and sponsored search placements—to distribute malware and social-engineer victims. Over nine months, campaigns used real domain content (claude.ai, chatgpt.com, grok.com) and SEO or sponsored results to surface malicious install guides and troubleshooting advice. These short-lived deceptive pages and shared links leveraged user trust in platform branding to execute stealer and RAT payloads before removal.
read more →

Early Access creates blind spots for malicious apps

🔍 New research from Bitdefender Labs finds Google's Early Access program can shield deceptive apps from public scrutiny, since users cannot rate or review apps while they remain in Early Access. Analysts identified thousands of suspicious apps — including fake casino and reward games, misleading utilities, and apps using known trademarks — many promoted via social media and some using deepfake ads. Researchers warn certain utilities request unusual permissions or exhibit behaviors that could expose enterprise devices to serious risks.
read more →

Mantax Otax Android malware combines ransomware, spyware

🔒 A new Android threat, Mantax Otax, combines ransomware and spyware to encrypt files, steal sensitive data, and harass victims. Distributed via malicious APKs outside Google Play by Indonesian operators, it requests Accessibility permissions to gain extensive control and retrieves its C2 domain from GitHub. The malware targets older Android versions for encryption, abuses Firebase and WebSockets for commands, and includes remote-control, data-exfiltration, and intimidation features. Up-to-date devices with Play Protect are generally protected, and users are advised to avoid sideloading APKs and granting Accessibility access to untrusted apps.
read more →

MantaxOtax Android malware blends ransomware and spying

🛡️ Zimperium's zLabs detailed the MantaxOtax Android threat, linking it to Indonesian actors and noting distribution via sideloaded packages. The malware requests extensive privileges including Accessibility and device admin, enabling file encryption on older Android versions and broad surveillance on all supported devices. Operators resolve C2 domains via a GitHub-hosted pointer and use Firebase for extortion chats, with a misconfiguration exposing some dialogues. Variants add persistent locking, overlays, recording, and other disruptive behaviors to coerce victims.
read more →

Stealth rootkit targets F5 BIG‑IP APM webtops

🔒 Sophos analyzed a Linux rootkit that hides web shells inside compromised F5 BIG‑IP APM environments by modifying PHP content in memory rather than writing files to disk. The implant hooks Apache’s PHP-loading process, targets specific BIG‑IP APM PHP files, and serves altered in‑memory versions so file‑integrity checks appear normal. It also provides a secondary access channel via a local UNIX socket, complicating detection and response.
read more →

GuardBreaker: AI-targeted evasion in malware comments

🛡️ ESET researchers discovered a VBScript used by Russia-aligned UAC-0099 that embeds a decoy comment requesting guidance on building a nuclear weapon to trip LLM-based code scanners and halt analysis before malicious payloads are reached. The technique, named GuardBreaker, exploits prompt-injection weaknesses by placing adversarial content in plain sight within comments, without affecting runtime behavior, and was used to deliver the MATCHBOIL loader. The finding highlights attackers adapting to AI-assisted defenses and the need for layered validation and human oversight.
read more →

Kaspersky Adds App Cleaner to macOS Premium

🧹 Kaspersky for macOS now includes an App Cleaner that removes applications along with their related files, caches, and helper services. The tool locates leftovers from apps previously deleted and moves removals to the Trash first so they can be restored if needed. App Cleaner identifies files using bundle IDs and common macOS locations and displays what will be deleted and how much space it frees up. The feature is part of Kaspersky Premium and complements other protections like Hard Disk Health Monitor.
read more →

F5 BIG-IP APM in-memory PHP web shell analysis

🛡️ Sophos on September 7 detailed malware targeting F5 BIG-IP Access Policy Manager that injects a PHP web shell into memory rather than writing it to disk. The malware hooks Apache and libphp, rewrites file-handling calls, and places a web shell in-memory when specific .php3 scripts are loaded, evading file-based detection. Related installer components modify /usr/sbin/httpd and other binaries and may persist through install images, with links to CVE-2025-53521 and mitigation guidance.
read more →

Packed Android RAT with ADB worm spreads via exposed services

🔍 Dark Atlas researchers detailed a packed Android remote access trojan (RAT) tracked as THost9 that conceals a loader inside an app and loads a second-stage payload, tc9.dex. The loader decodes and decompresses an embedded asset, starts a foreground service, and can enable an accessibility service when permissions allow. The second stage adds shell execution, file transfer, tunneling, reverse shell and downloadable modules, and includes a worm that scans for exposed Android Debug Bridge (ADB) services to propagate. Analysts linked infections to public ADB and Redroid exposures and recommend removing public ADB access and auditing accessibility services and persistent Redroid data.
read more →

BengalSEO campaign poisons Bing to deliver malware

🔍 Cybersecurity researchers disclosed a long-running SEO poisoning campaign, codenamed BengalSEO, which has been active since at least 2015 and operates out of Rajasthan, India. The group uses black hat SEO techniques, malicious lure pages, and a sophisticated traffic distribution system to deliver a custom malware called MayaBot or to funnel victims into tech-support scams. The campaign leverages legitimate hosting and analytics services to fingerprint visitors and evade detection before delivering payloads or social-engineering victims into calling scam call centers.
read more →

Compiled V8 JavaScript Malware Evades Defenses

🔒 Check Point Research analyzed JSCeal, a sophisticated compiled V8 JavaScript malware used to harvest credentials, surveil victims, and intercept traffic. Operators deliver JSCeal via malvertising and fake trading sites, using Node.js runtimes and obfuscated payloads assembled in memory. The malware targets many Chromium-based browsers to extract cookies, passwords, OAuth tokens, and can replay sessions to access Google accounts. JSCeal also sets up local proxies, installs certificates, and applies service-specific request and response modifications to target crypto platforms and trading services.
read more →

Coder registry compromise delivered malicious Terraform modules

🔒 Coder disclosed that an attacker gained access to its Cloudflare-backed registry infrastructure and added unauthorized IPs that served a tampered copy of the project's package registry. Between 07:35 UTC and 21:45 UTC on August 31, some requests were routed to attacker-controlled servers that delivered modified Terraform modules containing credential-stealing code. The malicious modules searched for a wide range of secrets and exfiltrated data to a lookalike domain; Coder advises rotating affected secrets, examining logs, and purging cached packages prior to upgrading to patched releases.
read more →

BraZetsu malware fuels access-as-a-service market

🛡️ Cybersecurity researchers detail a Python-based Windows malware framework named BraZetsu that powers an underground marketplace selling access to compromised hosts. The modular toolkit, linked to the Exilware group, targets Iberian and Latin American organizations and uses generative AI for reconnaissance, triage, and prioritization. BraZetsu harvests browser histories, certificates, and CNAB financial files and maintains persistent communication with the marketplace via WebSocket.
read more →

Counterfeit installers enable enterprise breaches

🔒 Microsoft warns that attackers are compromising enterprises via counterfeit download sites imitating vendors like Microsoft Edge, Kaspersky, and Razer, delivering trojanized installers that establish persistence and weaken security. The campaign, tied to the public Silver Fox/Yinhu activity, uses look-alike domains and server-generated payloads whose hashes change on each download to evade file-based detection. Once executed, installers abuse legitimate Windows components and scheduled tasks to persist, modify Defender settings, and stage further payloads.
read more →

Russian Extradition in Major Freelance Platform Malware Case

📰 A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited to the US and appeared in federal court on charges alleging he helped distribute malware to roughly 80,000 users of a freelance employment platform between 2016 and 2017. The indictment accuses him and co-conspirators of using fake messaging accounts to send malicious Excel attachments that installed remote access trojans, harvesting credentials and PII to support fraud. He faces multiple charges including conspiracy, unauthorized access and aggravated identity theft and remains in federal custody pending further proceedings.
read more →

Chinese-speaking group weaponises Brazilian sites

🛡️ Check Point Research attributes a sustained SEO fraud and phishing campaign to a Chinese-speaking cluster dubbed Gambling Goblin, active since mid-2025. Attackers implanted custom Apache modules to act as reverse proxies on compromised Brazilian government, education and commercial websites, redirecting specific visitors to localized phishing pages that impersonated app stores and promoted betting. The operation leveraged a broad Linux malware toolkit including AlphaAgent, oRAT and credential stealers, plus reconnaissance tools to map targets.
read more →

Malicious Apache Modules Hijack High‑Reputation Sites

🔍 A Chinese-speaking cybercrime cluster called Gambling Goblin has been observed installing malicious Apache modules on compromised Brazilian government and educational servers to redirect visitors to attacker-controlled pages promoting online gambling. Check Point Research has tracked the campaign since mid-2025 and found modules that reverse-proxy traffic while stripping security headers so injected content can run. The actors use multiple Linux and reconnaissance tools including DownPro, AlphaAgent, oRAT, and a 3snake-based credential stealer, and the operation appears aimed at large-scale SEO manipulation using high-reputation domains.
read more →

Meta ad campaign pushed new StreamRat Android trojan

🛡️ ThreatFabric disclosed StreamRat, a sophisticated Android banking trojan promoted via fake streaming ads targeting Spanish-speaking users on Meta. The campaign, active from June 11 to July 3, 2026, reached roughly 570,950 EU Meta accounts and lured victims to sideload a malicious APK that requests Accessibility and VPN-like permissions. Once granted, the malware can capture keystrokes, take screenshots, display overlays, and remotely control devices.
read more →