< ciso
brief />
Tag Banner

All news with #malware tag

1036 articles · page 4 of 52

Counterfeit installers enable persistent system compromise

🛡️ Microsoft Defender Experts are tracking an active campaign that uses counterfeit software-download sites impersonating trusted vendors to distribute malicious installers. The campaign targets users seeking popular software and has caused compromises across multiple industries, with a concentration on China-based operations and Chinese-speaking users. The malicious installers establish persistence, evade defenses, and communicate with attacker infrastructure; Microsoft disrupted activity and recommends enabling protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR.
read more →

Weekly cybersecurity recap: espionage, AI, and breaches

⚠️ This week’s recap highlights major disruptions and ongoing campaigns, from an FBI takedown of a Chinese proxy network to AI agents and supply-chain failures. Coverage includes router backdoors, chained PaperCut flaws, malware delivered via fake CAPTCHAs, and the evolving tactics of China-linked actors like Fire Ant. Patch and verify trusted infrastructure controls to reduce risk.
read more →

ValleyRAT backdoor concealed in signed adware

🛡️ Kaspersky attributes a campaign to Silver Fox that hides the ValleyRAT backdoor inside a legitimately signed Chinese adware installer, QN Wallpaper. The attackers use DLL sideloading to run a malicious libcef.dll within the signed QnWallpaper.exe, disable Windows Defender, add autorun entries, and escalate privileges with runas. ValleyRAT can steal keystrokes and screenshots, mark its process as critical to induce BSOD on termination, and contacts several C2 servers and domains.
read more →

Trusted Chrome and Edge extensions weaponized

🔍 Researchers at Socket found a supply-chain campaign that turned 19 Chrome and Edge extensions into malware by acquiring or publishing updates to previously legitimate extensions. The attackers used automatic extension updates to push malicious JavaScript payloads that stole cryptocurrency, captured form input, hijacked active sessions, and exfiltrated social media access and browsing history. Several extensions had substantial user bases, underscoring the reach of the operation.
read more →

Exotic file formats create detection blind spots

🛡️ This article examines how threat actors increasingly use less-obvious file types to bypass defenses and deliver malware. It outlines disk image formats (ISO, IMG, VHD, VMDK) that mount natively and can evade scanning, Office-related formats like .one and .xll that hide scripts or DLLs, and SVG files that can contain JavaScript. The piece also describes polyglot files and a notable IcedID campaign that chained ZIP→ISO→CHM→mshta to deploy payloads, and stresses the need for comprehensive scanning of these formats by security tools.
read more →

Attackers Abuse npm Mirrors to Host Phishing Pages

📄 Threat actors are abusing npm packages and public mirrors to host malicious HTML that impersonates Cloudflare CAPTCHA pages and redirects visitors to attacker-controlled sites. Security researchers found multiple npm packages containing a single index.html that, when served through mirrors like unpkg, renders from legitimate domains and executes obfuscated JavaScript to redirect users. Some payloads fetch remote configuration (via api.keyval.org) allowing attackers to change redirect targets without republishing packages. OX Security warns mirrors can act as free frontend hosts for phishing content and recommends treating direct HTML requests to npm mirrors as suspicious.
read more →

Weedhack malware spread via fake Minecraft clients

🛡️ McAfee Labs found ongoing campaigns distributing the Weedhack malware by impersonating popular Minecraft clients and hosting convincing lookalike sites. The attacks use SEO poisoning, Discord and file-hosting links to redirect victims and deploy multi-stage JAR payloads that collect system data and disable security protections. Threat actors even used an AI site builder to create believable malicious domains that outrank legitimate sources.
read more →

Malicious Firefox Add‑Ons Target Crypto Wallets

🔒 Security researchers at Socket uncovered a campaign of linked Firefox add‑ons designed to steal cryptocurrency wallet seed phrases and browser credentials. Dubbed the "Offside Wallet Theft Factory," the operation has been active since at least March 2026 and uses minimal‑permission extensions that switch behavior via a Supabase backend. Some extensions pose as wallets, VPNs, or utilities while others impersonate sports score tools, and attackers remotely toggle malicious pages to harvest recovery phrases and passwords. Out of 77 linked add‑ons, 40 were confirmed to steal data, illustrating how shared code and infrastructure enable rapid weaponization.
read more →

ToxicPanda Android malware adds VPN and ADB abuse

🛡️ ToxicPanda 2.0 now requests VPN service permissions to create a local interface that can block Google Play and Google Play Services, enabling it to interfere with app verifications, updates, and Play Protect checks. After establishing the VPN, the malware extracts and installs payloads, requests Accessibility Service permissions, and automates Wireless ADB to gain shell-level access. Zimperium reports distribution via AWS-hosted buckets and notes support for 167 remote commands and overlays targeting 349 financial apps across 16 countries.
read more →

Supply-chain malware infects Android car head units

🔍 Kaspersky researchers say a supply-chain attack abused a legitimate DoFun update app to deliver JarService malware to Android-based car head units, attributing the campaign to the MoYu group. The loader retrieves encrypted payloads and exposes nine remote commands used to collect device metadata, run code, open URLs, and perform network checks. Operators primarily install a reverse-proxy module named zhima to convert head units into proxy nodes for ad fraud and monetization, while DoFun says it has remediated the issue.
read more →

Android head-unit malware expands automotive botnets

🔍 In June 2026, researchers discovered malware targeting Android-based car head units that is delivered via an automatic firmware-update service. The attackers exploit DoFun’s TWCore updater to install a hidden dropper called JarService, which downloads a clicker and a proxy module to enroll head units in a botnet. Infected devices are used for ad fraud and to provide residential proxy services, degrading performance and exposing cars to further payloads.
read more →

North Korean Supply Chain Attack Targets Rust Ecosystem

🔒 Wiz researchers linked a recent supply chain attack in the Rust ecosystem to state-sponsored North Korean actors. The campaign compromised maintainer accounts on crates.io to alter manifests and import a typosquatted dependency, allowing malicious build-time code to run during compilation. The backdoor aimed to harvest browser credentials, crypto wallets and developer secrets, affecting widely used crates including arrayref, internment and append-only-vec.
read more →

Agent Tesla v4 uses emoji obfuscation to evade detection

🛡️ KnowBe4 has identified a new Agent Tesla v4 campaign using emoji-based obfuscation and a JScript dropper to bypass detection and steal credentials. The lure leveraged a convincing BEC email spoofing a Philippine bank and instructing finance staff to open an attachment. The dropper embeds Unicode emoji characters to disrupt signature matching, then uses DonutLoader for reflective PE injection so the final binary never touches disk. Researchers advise updating email security and creating YARA rules that combine emoji patterns with JScript function calls to detect the threat.
read more →

Manic Android Malware Targets Banks and Messaging

🛡️ Manic is a recently observed Android threat combining banking malware and mobile spyware to target Ukrainian banks, government and identity services, messaging apps, and financial institutions across Europe. It is distributed via phishing sites and dropper apps impersonating utilities and abuses Android accessibility and notification permissions to capture credentials and perform device takeover. The family includes wrappers and implants with enhanced anti-analysis checks and can exfiltrate data via a novel multi-hop Wi‑Fi mesh relay using nearby compromised devices. ThreatFabric attributes active development to early 2026 with new deployments in July that introduced stronger lock-screen phishing and expanded capabilities.
read more →

ToxicPanda 2.0 and GoldDigger Expand Global Targeting

🛡️ Zimperium zLabs and IBM Trusteer detail updated Android banking trojans: ToxicPanda 2.0 and a new GoldDigger campaign. ToxicPanda now includes 167 remote commands, enhanced PIN-harvesting for over 140 banking and crypto apps, and ADB-based escalation techniques. GoldDigger leverages sophisticated packing and accessibility abuse to drive fraud, with active campaigns in South Africa and the U.K.
read more →

Manic Android malware steals data via nearby devices

🛡️ Manic is a multifaceted Android malware active since at least February that combines spyware, banking fraud, and remote-control features, primarily targeting users in Ukraine and across Europe. It abuses Android Accessibility and notification access to capture PINs, SMS codes, credentials, files, and location, and uses transparent overlays to log keypad input. When direct C2 access is unavailable, Manic can exfiltrate encrypted data through nearby compromised devices over Wi‑Fi Direct or Bluetooth, using multi‑hop relays. Users should avoid installing APKs from untrusted sources, deny Accessibility permissions to untrusted apps, and run Play Protect scans.
read more →

ToxicPanda 2.0 Expands Targeting of Financial Apps

🔒 Security researchers at zLabs discovered ToxicPanda 2.0, an Android banking Trojan that now targets 140 banking and cryptocurrency apps and uses overlay-based credential theft against 349 financial institutions. The variant abuses the Android Accessibility Service to enable wireless debugging and attempts to obtain shell access via ADB, bypassing runtime prompts and enforcing persistence. New capabilities include stealing device lock credentials through screen overlays. Recommended defenses include blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging via MDM.
read more →

40 Malicious Firefox Extensions Target Web3 Wallets

🛡️ A cluster of 40 malicious Mozilla Firefox extensions has been identified stealing cryptocurrency wallet secrets by impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. Socket Threat Research attributes the extensions to a broader set of 77 related add-ons with shared code and infrastructure, a campaign they call Offside Wallet Theft Factory, active since March 2026. The threat actors used Supabase projects, Cloudflare Workers, and hard-coded C2 to exfiltrate recovery phrases, private keys, and credentials, often hiding malicious payloads behind benign sports-score or utility shells. Researchers warn the economics of disposable extensions and repurposing identities make the Firefox Add-ons ecosystem an attractive target.
read more →

U.S. warns of AI-driven attacks on Siemens PLCs

🔒 U.S. cybersecurity agencies issued a joint advisory warning that threat actors are using AI-generated Python scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) within U.S. critical infrastructure. The agencies—NSA, CISA, FBI, DOE, and EPA—noted ongoing activity that targets exposed PLCs by abusing vulnerabilities, outdated software, and weak authentication to gain read/write access and disguise tools as legitimate OT monitoring software. Operators are urged to inventory devices, apply updates, block internet access, and strengthen monitoring and access controls to reduce risk.
read more →

StopAndProtect: Operation Exposed by OPSEC Failures

🔍 Check Point Research uncovered a unique case where OPSEC mistakes exposed a global cyber crime operation named StopAndProtect. The investigation revealed accessible victim logs, screenshots, source code, and references to nearly 2,000 compromised WordPress domains, showing how attackers repurposed legitimate sites to host malware and manage campaigns. Researchers warn organizations to beware of unexpected CAPTCHA prompts and to keep systems and security software updated.
read more →