< ciso
brief />
Tag Banner

All news with #malware tag

968 articles · page 4 of 49

macOS infostealer poses as Apple crash reporter

🛡️ A new macOS infostealer named CrashStealer impersonates Apple's crash-reporting component to trick users into installing a password-stealing payload. Delivered via a signed, notarized disk image called "Werkbit Setup," the dropper bypasses Gatekeeper and fetches a downloader that installs the C++-based stealer. Once active, it prompts for system credentials and exfiltrates browser-stored logins, crypto wallet access and keychain data, using client-side encryption and anti-analysis techniques.
read more →

Malicious Python Packages and Supply Chain Risks

🐍 This report examines how the convenience and popularity of Python have attracted supply chain abuse, showing how malicious packages can execute code during installation and persist via .pth files or sitecustomize hooks. It outlines the installation layers (hosting, installation, environment), distribution formats (sdist, wheel), and common abuse techniques, emphasizing the rapid impact of compromised packages on development and enterprise assets.
read more →

148 npm Packages Masked as Student Proxies Abused

🔍 JFrog researchers found 148 npm packages posing as student web proxies that converted visitors' browsers into a DDoS botnet for roughly two weeks in May. The packages hosted a proxy UI but loaded a mutable remote script and a WebSocket flood generator, allowing attackers to run volumetric and control-plane attacks from unsuspecting users' tabs. Many packages have since been removed, but remnants and mutable loaders remain active, so network and build mitigations are advised.
read more →

Japan’s largest taxi operator halts systems after attack

🚨 Nihon Kotsu, Japan's largest taxi and chauffeur operator, has shut down parts of its IT infrastructure after detecting unauthorized external access and a malware infection early Saturday. The outage has affected the taxi dispatch system, web booking, reservation management, phone dispatch services, and some internal systems, leaving key services offline while the company investigates. Nihon Kotsu has engaged external cybersecurity experts, warned customers to avoid suspicious attachments and links, and has not yet confirmed any data leakage or any claim of responsibility by ransomware groups.
read more →

CrashStealer macOS info stealer uses signed dropper

🛡️ Jamf Threat Labs discovered a new native C++ macOS information stealer named CrashStealer that harvests credentials, browser data, cryptocurrency wallet extensions, password manager entries, and keychain material. The campaign uses a signed and Apple-notarized disk image dropper served from a gated site and persists via LaunchAgent after re-signing itself. Collected files are AES-GCM encrypted before exfiltration to an attacker-controlled server, and the malware employs multiple analysis-resistance techniques.
read more →

Weekly recap: ShareFile warning and broad threats

🛡️ Progress urged ShareFile customers to shut down Windows Storage Zone Controllers amid a credible external threat, temporarily disabling access while investigating; there are no signs of account or data compromise. Other top stories include a critical Zimbra XSS patch, a compromised Jscrambler npm package distributing a multi-platform Rust stealer, and Microsoft detailing the destructive GigaWiper backdoor. Large-scale web shell operations (SHELLSTORM), HalluSquatting attacks against AI assistants, and many actively exploited CVEs round out the week's threats.
read more →

RedHook Android Malware Abuses Wireless ADB

🛡️ Researchers at Group-IB describe a new RedHook Android malware variant that abuses Wireless ADB to gain shell-level (UID 2000) privileges without a wired computer connection. The malware tricks victims into granting Accessibility permissions to enable Developer Options and Wireless Debugging, retrieves the pairing code, and connects via the loopback interface. It leverages a Shizuku-based framework to execute shell commands, silently install apps, modify protected settings, and perform RAT functions like screen streaming and keystroke interception. Distribution relies on social engineering directing victims to fake Play stores; users are urged to install apps only from official sources, review permissions, and enable Play Protect.
read more →

GigaWiper: Unified backdoor blends espionage and wiping

🛡️ Microsoft has identified GigaWiper, a versatile Golang backdoor that consolidates espionage and multiple destructive wiping capabilities into a single implant. The tool merges components from at least three prior malware families, enabling command-and-control, disk-level wiping, fake ransomware with unrecoverable keys, and multi-pass secure wiping. Researchers observed standalone wipers and larger backdoor binaries, and advise enabling tamper protection, cloud-delivered antivirus, EDR in block mode, and blocking known C2 infrastructure.
read more →

New MODBEACON Rust RAT Uses gRPC Streaming

🛡️ QiAnXin attributes a new Rust-based remote access trojan named MODBEACON to the China-linked Silver Fox cluster. The memory-resident implant uses a modular, plugin-based architecture and leverages gRPC tunnel streaming with transport borrowed from open-source proxy tools (Xray/V2Ray) for its C2 channel. Distributors push the malware via counterfeit installers promoted through SEO poisoning and host C2 infrastructure on Amazon and Cloudflare CDNs.
read more →

Injective SDK npm package used to steal wallet keys

🔒 Security researchers discovered that the @injectivelabs/sdk-ts npm package (v1.20.21) was published with malicious code to capture cryptocurrency wallet private keys and mnemonic seed phrases. The compromise stemmed from a hijacked GitHub contributor account with suspicious commits appearing on June 8; the legitimate owner quickly reverted changes and released a clean 1.20.23. The malware activated when wallet-generation or import functions were called and exfiltrated secrets via HTTP POST to a public Injective Labs endpoint, and the tainted package had hundreds of dependent packages and thousands of downloads.
read more →

GodDamn ransomware uses signed PoisonX kernel driver

🛡️ GodDamn is a newly observed ransomware family that employs a signed PoisonX kernel driver and a Symantec‑masquerading user‑mode tool to disable endpoint protections. First spotted on May 21, 2026, Broadcom's Threat Hunter Team attributes the lineage to the Hyadina developer and links it to earlier Beast and Monster variants. Attacks used AnyDesk, PsExec, credential harvesters and lateral movement to compromise multiple hosts before deploying the encryptor.
read more →

Rise of Malicious AI Agents Threatens Organizations

🤖 ESET analysis shows cybercriminals increasingly use AI agents and chatbots to autonomously plan and execute attacks. Researchers reviewed 900,000 AI skills in public repositories and found tens of thousands of suspicious and thousands of malicious toolsets, expanding the attack surface. These agentic tools can exfiltrate data, execute malware, override instructions, and be repurposed from legitimate utilities into harmful capabilities. ESET urges organizations to enforce policies and caution users about downloading free tools from untrusted sources.
read more →

China-linked APT expands relay network and malware

🔍 Cisco Talos reports a China-nexus APT tracked as UAT-7810 has expanded a network of hijacked routers and devices called Operational Relay Boxes (ORBs) to hide other attackers' traffic. The group maintained a long-running LapDogs relay infrastructure and exploited unpatched Ruckus and ASUS router vulnerabilities to recruit devices. Researchers uncovered an upgraded backdoor, LONGLEASH, plus two new tools, DOGLEASH and JARLEASH, with evidence suggesting Chinese-speaking operators. Talos says the group's servers and malware remain active.
read more →

RedWing malware: Android bank-fraud service rental

🛡️ RedWing is a commercially rented Android malware operation sold via Telegram that enables low-skill criminals to take over victims' phones and harvest banking credentials and one-time codes. Zimperium's zLabs links it to an earlier rent-a-malware family and says a Telegram bot builds custom malicious apps on demand. Infection begins with phishing to a fake app-store page that persuades users to sideload and authorize intrusive permissions like Accessibility and default SMS handling. Once installed, RedWing can present overlays, read SMS OTPs, forward calls, stream the screen, record input, and exfiltrate files and location.
read more →

Gentlemen ransomware tests identity and recovery controls

🔍 The Gentlemen ransomware highlights challenges for CISOs in stopping attackers after an initial foothold. Researchers report the malware self-propagates using legitimate Windows management tools while attempting to disable security and recovery systems. Picus Security notes the encryptor, written in Go and obfuscated with Garble, leverages multiple lateral-movement methods and targets backups, EDR, and virtualization services to hinder recovery.
read more →

Monday Recap: Proxy Botnets, Browser Ransomware

⚡ Google and partners disrupted the NetNut residential proxy network (aka Popa), which abused smart home devices and preinstalled SDKs to route malicious traffic through an estimated 2 million devices. Other incidents this week include fake PoC repos delivering the ChocoPoC RAT via a dependency, a 19-year-old alleged Scattered Spider suspect extradited to the U.S., and a Brazilian Ousaban banking trojan targeting Spain and Portugal. Check Point flagged AI-generated browser ransomware leveraging the File System Access API, illustrating AI can autonomously devise working attack techniques.
read more →

New Java-based QuimaRAT MaaS Targets All Platforms

🛡️ Cybersecurity researchers have identified QuimaRAT, a modular Java-based remote access trojan offered as malware-as-a-service that targets Windows, Linux, and macOS. The kit includes a builder, loader, dropper, and the RAT itself, with subscription tiers from $150 to $1,200. QuimaRAT uses encrypted plugins, native libraries via JNA, and multiple persistence and delivery techniques to evade protections and maintain robust C2 connectivity.
read more →

North Korean campaign publishes malicious packages

🛡️ Researchers observed North Korea–linked actors behind the Contagious Interview campaign publish 108 unique malicious packages and extensions across npm, Packagist, Go, and Chrome under an operation dubbed PolinRider. The releases include obfuscated JavaScript loaders that append code to common project config files and leverage VS Code task auto-run behavior to execute payloads. Attackers appear to acquire or retain registry and maintainer access via repository compromises, domain takeovers, or malicious dependencies. The campaign has been active since at least 2023 and continues to deliver RATs and stealers through multi-stage blockchain-backed payload delivery.
read more →

Avalon modular malware framework and CrownX ransomware

🛡️ Cybersecurity researchers uncovered a modular malware framework dubbed Avalon that uses a multi-stage phishing chain to bypass traditional defenses and deploy a ransomware component called CrownX. The campaign begins with a spoofed legal-document email pointing victims to a password-protected Proton Drive archive containing an ISO image. Interaction with a malicious Windows Shortcut inside the mounted image triggers an MSBuild-led loader that disables ETW, fetches additional payloads, and ultimately launches Avalon. The framework includes credential harvesting, crypto-wallet theft, lateral movement, data exfiltration, recovery disruption, anti-forensics, and disk tampering capabilities.
read more →

Armored Likho targets governments and utilities

🛡️ Kaspersky attributes a newly documented threat actor, Armored Likho, to espionage and financially motivated campaigns against government agencies and the electric power sector in Russia, Brazil, and Kazakhstan. The group's toolkit includes obfuscated Python stealers (BusySnake), modular RATs, Go2Tunnel for reverse SSH, and droppers delivered via spear-phishing or weaponized LNK files exploiting CVE-2025-9491. The malware emphasizes persistence, credential theft, and dynamic module delivery tailored to victims.
read more →