< ciso
brief />
Tag Banner

All news with #malware tag

968 articles · page 3 of 49

Cruciferra Crypter Enables Advanced BYOVD and Evasion

🛡️ Proofpoint reveals that the China-linked crypter Cruciferra is being used to deliver diverse RATs and stealers, employing advanced evasion like BYOVD-based EDR tampering, IAT unhooking, and a custom Process Ghosting variant. The service, advertised since fall 2025, offers polymorphic encryption and modular payload delivery via DLL side-loading, affecting sectors such as finance, healthcare, government, and education.
read more →

New TELESHIM campaign abuses Telegram for C2

🛡️ Zscaler ThreatLabz has detected an East Asia–linked campaign targeting Middle Eastern government entities that deploys three previously unreported malware families: TELESHIM, MIXEDKEY, and BINDCLOAK. The attack begins with an ISO that sideloads a rogue DLL to run a 32‑bit backdoor (TELESHIM) which uses the Telegram API for command-and-control, then stages additional payloads via DLL side‑loading and a reflective loader (MIXEDKEY). TELESHIM and MIXEDKEY employ heavy obfuscation and anti-analysis checks, while the final 64‑bit implant BINDCLOAK communicates with an external C2 server; observed activity occurred between July 7–9, 2026.
read more →

Steam forum ClickFix attacks deliver XMRig miners

🛡️ Threat actors are abusing Steam discussion forums with ClickFix social engineering posts that instruct users to run PowerShell commands purportedly to fix game or system issues. The commands download and run an XMRig cryptominer disguised as a Windows optimization utility named msf utility \ PC Opt, which fakes maintenance progress while installing a miner as C:\Windows\Background\system.exe and persisting via a scheduled task. Victims are advised to check for the Background folder, Defender exclusions, and scheduled tasks named 'XMRig-[computer name]' and to run antivirus scans or consider OS reinstall.
read more →

Malvertising builds malware in browser memory

🛡️ A widespread malvertising campaign uses fake Solana, Luno, and TradingView pages with malicious JavaScript that assembles malware directly in the browser's memory. The operation, active since late 2024 across 12 countries, filters out researchers and scanners while delivering customized payloads to retail traders and crypto investors. Confiant found the pages register service and shared workers to piece together a unique executable from remote components and local bytes, avoiding transmission of a finished file to evade detection.
read more →

Weekly ThreatsDay Bulletin: Multifaceted Cyber Risks

🛡️ This week's ThreatsDay Bulletin catalogs varied, evolving threats that masquerade as useful software or ordinary files. Highlights include npm and PyPI supply-chain risks, a rogue VS Code extension, a fake Claude app delivering SectopRAT, and Android apps posing as civil-defense tools that instead enable surveillance. The report also details PLC-targeting activity linked to Iranian-affiliated actors and new AI-related exploitation techniques.
read more →

TrickBot shifts to DNS tunneling for C2 communications

🛡️ Fortinet researchers uncovered a TrickBot variant that abandons HTTP for a custom DNS tunneling C2 channel, embedding encrypted commands and payloads within malformed DNS queries. The modular malware uses single-byte XOR encoding, hex-encoding and 63-character domain chunking for outbound beacons, while inbound data hides in multiple IPv4 addresses returned by resolvers. Persistence relies on Windows Task Scheduler with NTFS ADS, and command handling retains prior modular capabilities for executing modules, DLLs, PowerShell and shellcode.
read more →

Massive FakeGit campaign leverages GitHub to spread malware

🔎 Researchers uncovered the FakeGit campaign using some 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, amassing over 14 million download events. Many repos impersonated legitimate tools and AI skills, employing an AgentBaiting technique to attract AI agents and developers. The campaign reused tactics from a prior Lumma Stealer operation, and Island recommends isolating and vetting AI skills, rotating secrets, and validating publishers.
read more →

HollowGraph: Malware Using Microsoft 365 Calendar C2

🛡️ Group-IB discovered a .NET espionage implant called HollowGraph that uses a hijacked Microsoft 365 calendar as a covert command-and-control channel, reading operator instructions from a calendar event dated 2050-05-13 and exfiltrating stolen files as attachments. The implant uses the Microsoft Graph API to blend with legitimate traffic and avoids contacting attacker-owned servers directly. A secondary DNS-based channel supplies Entra ID client credentials via IPv6 AAAA records, written to a log file named logAzure.txt. Group-IB links the malware to the Cavern code family and recommends monitoring calendar events, application-driven Graph activity, and suspicious DNS AAAA queries.
read more →

OnlyFans creators help CISOs curb site abuse

🔒 Security researchers report that OnlyFans creators are using DMCA takedown rights and search engine mechanisms to disrupt scam networks that host stolen adult content on compromised government and university websites. These operations — called SEO parasites — route traffic from hijacked entry pages to monetized scam or malware sites. The takedowns not only remove illicit content from search results but also prompt site owners to investigate and remediate vulnerabilities.
read more →

Shadow Token via Remote Debug: OAuth mailbox hijack

🔒 Kaspersky researchers describe a covert technique named Shadow Token via Remote Debug (STRD) used by the ToddyCat APT to gain persistent access to Google Workspace mailboxes without user interaction. The attackers deploy malware (Umbrij) that duplicates a browser profile, launches a headless debugging browser, and programmatically authorizes a third-party OAuth app to obtain an access token. This approach can survive password resets and evades endpoint detection when properly executed.
read more →

Fake TTF loader used in global phishing campaign

🛡️ Fortinet's FortiGuard Labs reports a global phishing campaign using obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font (.ttf) to evade detection. The attack chain delivers RATs and infostealers such as Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant, employing in-memory execution and various anti-analysis techniques. Researchers noted business- and payment-themed lures, compressed archives with script loaders, and Donut shellcode to avoid writing payloads to disk. Defenders are advised to combine identity controls, application restrictions, and behavior-based detection.
read more →

OkoBot framework deploys 20+ payloads to steal crypto

🛡️ A new modular malware framework named OkoBot delivers over 20 payloads to steal cryptocurrency seed phrases, credentials, and other sensitive data. The campaign uses ClickFix lures and malicious GitHub repositories, sometimes trojanizing legitimate tools, and evolved from the earlier TookPS activity. Kaspersky found the campaign active since January and primarily targeting victims in Brazil, Vietnam, Canada, Mexico, and Turkey. Notable modules include browser injectors, SeedHunter for wallet recovery prompts, keyloggers, and spyware that records wallet and password manager windows.
read more →

Patch surge strains defenders amid AI‑driven finds

🔥 This week’s Threat Source highlights a record Microsoft Patch Tuesday that fixed 622 vulnerabilities, including two zero‑days being actively exploited. Cisco Talos discloses UAT‑11795, a Russian‑speaking group using trojanized installers to deliver the Python-based Starland RAT and an in-memory PowerShell implant called WLDR agent. The newsletter outlines detection guidance and emphasizes the operational stress on IT teams facing accelerated vulnerability discovery driven by frontier AI research.
read more →

Weekly roundup: emerging cyber threats and takedowns

🛡️ This week’s roundup highlights a wave of opportunistic attacks where familiar software and weak defaults are abused to escalate damage quickly. Reports include malicious NuGet packages that deliver spyware via game cheats, trojanized installers distributing sophisticated RATs, and a fast-spreading Rust ransomware incident that encrypted a network within 24 hours. Additional items cover actively exploited CVEs added to CISA’s KEV, guidance for coordinated vulnerability disclosure, large-scale fraud and money‑laundering disruptions in Europe, evasive Windows bind-link techniques, fake GitHub repos spreading an infostealer, and misuse of Chrome Sync for covert surveillance.
read more →

ClickLock macOS stealer leverages ClickFix social lure

🛡️ Group-IB researchers describe a new macOS stealer called ClickLock that combines a ClickFix "paste-a-command" lure with a coercion routine that disables the desktop until a password is surrendered. The modular campaign downloaded four components from compromised WordPress sites to steal Keychain and browser credentials, exfiltrate wallet data, and install a GSocket backdoor. Operators forced compliance by killing system processes in loops, suppressing warnings and relaunching credential prompts; exfiltration used Telegram bots and modules self-deleted, leaving a stealthy backdoor.
read more →

TELEPUZ modular malware spreads via ClickFix attacks

🛡️ Elastic Security Labs disclosed a new lightweight, modular malware named TELEPUZ that has been propagated through ClickFix (pastejacking) lures since late April 2026. The campaign delivers a Go-based Vidar stealer variant which then fetches a C-based TELEPUZ stager and main DLL, with artifacts hosted on a domain linked to the campaign. TELEPUZ includes extensive obfuscation, anti-VM and geofencing checks, AMSI/ETW unhooking, privilege escalation, service persistence, and WebSocket-based C2 with fallback retrieval via Telegram, Steam, DNS and a Polygon smart contract.
read more →

PhantomEnigma Abuses Brazilian Government Sites

🛡️ ANY.RUN uncovered an active PhantomEnigma campaign that hijacked over 20 Brazilian government websites to deliver malware. The operation used authenticated emails, compromised mailboxes, and trusted .gov.br hosts to redirect victims to malicious installers and a modular index.js backdoor. Researchers linked hundreds of sandbox sessions to reveal the campaign’s infrastructure, delivery chains, and detection guidance.
read more →

Smashing Security podcast episode 476 recap

🎧 In episode 476 of the Smashing Security podcast Graham Cluley and Geoff White discuss Geoff's new podcast season on the Conti ransomware gang, personal scam attempts, and a startling prank targeting e-rickshaws in India. They describe how an app called BatBMS — intended for battery management — has been misused to remotely disable electric rickshaws, creating safety and livelihood risks for drivers. The hosts also cover sponsors and lighthearted anecdotes about smartphone pranks.
read more →

Google Gemini CLI abused to operate malware botnet

🔍 A Russian-speaking actor called "bandcampro" leveraged Google's open-source Gemini CLI as an AI hacking agent and to run a small botnet targeting at least eight systems in a dental clinic. Over 200 sessions between May and April, the AI executed migration, troubleshooting, and operational improvements, storing credentials and following a built-in C2 playbook. Trend Micro found the setup tiny and unsophisticated, with Python HTTP and PowerShell agents and persistence via scheduled tasks, WMI, and registry changes.
read more →

LabubaRAT Rust RAT Masquerades as NVIDIA Runtime

🛡️ Cybersecurity researchers disclosed a previously undocumented Rust-based remote access trojan, LabubaRAT, which impersonates an NVIDIA runtime executable to evade detection and establish persistent access. The implant supports multiple communication channels including HTTPS, WebView2, and DNS tunneling, accepts runtime configuration via command-line arguments or Base64 payloads, and stores its settings in a local SQLite database. Once active, it profiles hosts for browsers and security products, captures screenshots, executes commands, handles files and archives, and proxies traffic via SOCKS5, enabling hands-on operations without a separate loader.
read more →