< ciso
brief />
Tag Banner

All news with #malware tag

1036 articles · page 5 of 52

New macOS infostealer hijacks browsers for remote control

🛡️ Jamf Threat Labs uncovered a multi-stage macOS infostealer named AmnesiaStealer that uses a fake GitHub download page to trick victims into running a Terminal command which installs malware. The Rust-based loader retrieves a password-protected ZIP, deploys a universal Mach-O payload and collects passwords, Keychain items, browser data and other sensitive files. A distinct stream_module converts the victim’s Chromium browser into a remotely controlled session via WebSocket, allowing attackers to export cookies and perform browsing actions.
read more →

Infostealers Harvest 1.7 Billion Credentials in H1 2026

🔍 Flashpoint reports 7.4 million devices infected by infostealer malware in H1 2026, marking a 27% increase from the previous half-year. The company recorded 1.7 billion harvested credentials, with Vidar, StealC and Lumma as the top variants, and highlighted a shift to automated credential-processing ecosystems. The report also details rising vulnerability disclosures and growing underground AI-driven threats.
read more →

AmnesiaStealer targets macOS Chromium sessions

🛡️ Researchers disclosed a new Rust-based macOS infostealer, AmnesiaStealer, delivered via a fake GitHub “Download for macOS” page that tricks users into pasting a Base64 command into Terminal. The multi-stage dropper retrieves a password-protected ZIP and executes a Rust payload that harvests Keychain items, browser data, Apple Notes, Telegram, and files, while using the captured system password for privileged access. A second-stage remote_stream module enables operator-driven browser control over Chromium-family browsers via the Chrome DevTools Protocol to steal live sessions and evade detection.
read more →

WindRelay NFC Android Relay Malware Emerges

🔒 WindRelay is a new Android NFC relay malware deployed alongside the SpyNote RAT to enable contactless payment fraud. First observed in August 2025, it captures live card data via NFC and streams it in real time to fraudsters. Attackers use personalized social engineering and remote access to sideload the NFC reader covertly, turning the victim's phone into a payment proxy. The scheme pairs a victim-side reader with an attacker-side emulator and a shared C2 channel to relay EMV commands and enable card-present cashouts.
read more →

Fake CCleaner installer enables Chrome credential theft

🛡️ Researchers discovered a multi-stage Windows malware campaign that uses a fake CCleaner download to install a malicious Chrome extension called GhostDesk. The payload abuses Chrome to capture credentials, cookies, keystrokes, screenshots, and to inject arbitrary JavaScript into active tabs. Variants impersonating 7-Zip and Adobe Acrobat share the same C2 infrastructure and delivery mechanism. Malwarebytes recommends verifying download sources and using up-to-date anti-malware protections.
read more →

Chrome reduces Android notification abuse by billions

🔔 Google reports that Chrome's anti-abuse systems blocked over 7 billion unwanted Android notifications per day in Q1 2026. The company says notification abuse has become a vector for scams, malware, phishing, and fraudulent payment requests, prompting a layered "Swiss cheese" defense model. Chrome now auto-revokes notification permissions from inactive or repeatedly abusive sites and allows users to review and restore access via Safety Hub. The browser also limits message rates for disruptive sites and adjusted permission prompts to be less intrusive on Android.
read more →

Rise of polyglot file attacks and defenses

🛡️ Files created with the polyglot technique are increasingly used in cyberattacks to evade filters and confuse investigators. Attackers craft files that can be interpreted as multiple formats (for example, PNG or ZIP) so different applications or scanners see different contents. Real-world campaigns have used EXE/ZIP, PDF/DOC, MSI/JAR, DLL/HTML and multi-archive polyglots to deploy malware like PhantomPyramid, StrRAT, Ratty and IcedID. Defenses rely on consistent security hygiene and targeted testing of detection tools.
read more →

Real emails and clipper attacks hijacked payments

🛡️ Gen Threat Labs examined two H1 2026 campaigns where attackers used legitimately compromised accounts and local system manipulation to intercept payments. The first campaign abused corporate mailboxes to deliver JavaScript droppers that progressed through PowerShell and shellcode to modify proxy and browser settings for banking fraud. The second used a Rust-based clipboard clipper that replaced copied crypto addresses and read C2 pointers from Binance Smart Chain smart-contract data.
read more →

Common dangerous file extensions used in email attacks

🛡️ Cybercriminals frequently disguise malicious files as benign documents or archives to trick recipients into executing malware. Kaspersky researchers analyzed malicious email blasts from early 2026 to identify the 15 most abused extensions — from .exe, .dll and .scr to script, web, archive, and Office formats. The report explains how double extensions, hidden extensions, macros, embedded scripts, and password-protected archives are used to evade detection and deliver payloads. It emphasizes keeping software patched, disabling unnecessary macros and scripts, and using advanced security solutions to detect disguised threats.
read more →

ClickFix macOS infostealer targets crypto and credentials

🛡️ A Go-based malware delivered via a ClickFix campaign targets macOS users to steal cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. Researchers at Huntress found the attack uses a Bash profiler and Mach-O payload tailored to the victim’s CPU, persists by faking errors with osascript, and removes quarantine flags to bypass Gatekeeper. The malware can intercept and divert crypto transactions and selectively drain a percentage of funds.
read more →

Attackers hide Java malware inside Oracle databases

🛡️ Huntress uncovered an intrusion where attackers exploited a SQL injection flaw to embed a Java-based post-exploitation toolkit, Khunt, inside an Oracle database using the platform’s embedded JVM. By uploading Java source via CREATE JAVA SOURCE, compiling it in-database and invoking it through SQL, the threat actors executed OS-level commands and maintained persistence while blending with legitimate database functionality. The campaign escalated to SYSTEM-level access on the Windows host, enabling credential dumping and offline extraction of password hashes. Huntress urges defenders to check for unexpected Java objects, compiled classes, and stored procedures as part of incident response.
read more →

Enterprise passkey risks from malware and weak processes

🔒 A Palo Alto Networks Unit 42 report details how malware on compromised endpoints can abuse onboarding, recovery and device-trust workflows to defeat passkey protections. The research outlines three attack categories—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that enable account takeover or mass extraction of synced passkeys. Experts emphasize these are post-compromise attacks that exploit implementation and procedural weaknesses rather than breaking the underlying cryptography. CISOs are advised to enforce user verification, prefer device-bound authenticators for sensitive accounts and tighten enrollment, recovery and sync policies.
read more →

NullReceiver: New EtherHiding Evolution Conceals C2 IP

🔍 OpenSourceMalware has identified a refined EtherHiding-style dead drop, dubbed NullReceiver, embedded in two trojanized npm packages, bianira-ui and fluid-type-ui. The technique encodes a C2 IP address directly in the recipient address bytes of an otherwise empty Ethereum transfer, allowing malware to decode the C2 from an attacker's wallet outbound transaction. The packages were published on July 28, 2026 and have been downloaded a few hundred times before removal from npm.
read more →

XCSSET v40 Targets macOS Developers via Xcode

🛡️ Researchers at Unit 42 have uncovered a resurgence of the XCSSET macOS malware, now in version 40, which infects developers by injecting downloader scripts into compromised Xcode projects and GitHub repositories. The campaign was observed in two waves in mid-April and early May and introduces two new modules: a Chrome hijacker and a Telegram trojanizer. The malware employs enhanced evasion techniques, aggressively disables macOS protections, and propagates across Xcode projects when developers build infected code.
read more →

Keyv-linked npm worm poisons hundreds of packages

🛡️ A credential-stealing npm worm first seen in keyv@6.0.0 spread beyond Keyv and Cacheable namespaces on August 4, 2026, impacting hundreds of packages. SafeDep verified 353 poisoned versions across 79 package names while other monitors reported larger, harder-to-validate totals. The malicious preinstall script harvested repository, registry, cloud and private-key material, installed a token-revocation watcher and used npm publish access to propagate. Additional execution paths via Claude Code and VS Code workspace hooks could trigger the payload when a user trusts a workspace or permits project configuration.
read more →

Malware Bypassing DNS: Direct-to-IP Threats Rise

🔎 Analysis of 4 million dynamic reports shows nearly half (45.32%) of malware with C2 activity connects directly to IP addresses, bypassing DNS. This behavior—seen in ransomware droppers, P2P botnets and IoT threats—evades DNS-based defenses. The article introduces zero trust IP (ZT-IP), a network-level enforcement model that permits only DNS-sanctioned outbound IP connections and validates its efficacy against real-world samples and traffic.
read more →

New Pass-ta-key attacks target Google synced passkeys

🔒 Security researchers from Palo Alto Networks' Unit 42 disclosed three related attacks, collectively dubbed "Pass-ta-key," that let malware on compromised Windows devices abuse Google Password Manager's synced passkeys in Chrome on TPM-equipped machines. The techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — exploit weaknesses in device trust, onboarding, recovery, and synced credential handling rather than breaking passkey cryptography. While the attacks require existing malware on the victim's device, they can bypass or subvert user verification and even extract the master key that encrypts synced passkeys, enabling account takeover and future key decryption. Unit 42 reported findings to Google and affected services; some issues, such as eBay's validation, have been fixed.
read more →

DOUBLECUP ClickFix service hides malware in cache

🔍 SOCRadar warns of a Russian loader-as-a-service called DOUBLECUP that uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, delivering CountLoader and a new DeviceManager RAT. The service, active since June 2026, provides infrastructure and a Go-based builder while customers host phishing pages that trick users into pasting commands. The technique forces browsers to cache steganographic images, then extracts and executes payloads via clipboard-driven commands.
read more →

Fake Xeno script launcher infects Roblox players

🛡️ Bitdefender identified malicious installers posing as the Xeno Executor Roblox utility that deliver a multi-stage Java-based loader and a final RAT/infostealer. The campaign, active since early this year and spiking in March, lures gamers via forums, Discord, and compromised accounts with archives mimicking legitimate Xeno installations. Once executed, the malware extracts a Java runtime, registers victims with a C2, and deploys payloads that steal browsers, wallets, and account tokens while enabling surveillance and remote control.
read more →

Passkeys at Risk: Chrome Password Manager Attacks

🔒 Unit 42 describes three post-compromise attacks against Chrome's Google Password Manager cloud authenticator—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that let malware on Windows obtain valid authentication assertions or extract the master secret without user interaction. The techniques exploit how Chrome stores and reloads TPM-wrapped keys, allows deferred user-verification key creation during re-enrollment, and exposes the 32-byte Security Domain Secret (SDS) in process memory. The research is limited to Windows with TPM and starts from a compromised endpoint; it does not claim cryptographic failure and has no CVEs listed as of August 3, 2026.
read more →