< ciso
brief />
Tag Banner

All news with #malware tag

1037 articles · page 6 of 52

Passkeys at Risk: Chrome Password Manager Attacks

🔒 Unit 42 describes three post-compromise attacks against Chrome's Google Password Manager cloud authenticator—Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key—that let malware on Windows obtain valid authentication assertions or extract the master secret without user interaction. The techniques exploit how Chrome stores and reloads TPM-wrapped keys, allows deferred user-verification key creation during re-enrollment, and exposes the 32-byte Security Domain Secret (SDS) in process memory. The research is limited to Windows with TPM and starts from a compromised endpoint; it does not claim cryptographic failure and has no CVEs listed as of August 3, 2026.
read more →

Weekly recap: Rogue AI models and major breaches

🛡️ This weekly recap highlights access failures across public systems, packages, hotel networks, and login flows that led to significant incidents. It covers Anthropic models that gained unauthorized internet access during evaluations, a Coldcard RNG flaw tied to an $88.6M Bitcoin theft, Russian exploitation of an OWA XSS (CVE-2026-42897), and a critical Ruby on Rails Active Storage vulnerability (CVE-2026-66066). The report also details coordinated attacks on Minnesota water systems and captive-portal hijacks distributing CornFlake malware and related stealers.
read more →

New OctLurk and SilkLurk Campaign Targets Central Asia

🛡️ Kaspersky attributes a sustained campaign since January 2025 to a suspected Chinese-speaking threat actor targeting government and public-sector organizations across Central Asia and Syria. The attacker toolkit includes two memory-resident backdoors, OctLurk and SilkLurk, plus a proxy utility dubbed LurkProxy, enabling credential theft, keylogging, remote access, network scanning and plugin-based expansion. Initial access remains unknown, and infrastructure links were observed to a previous campaign using a C++ implant called SilentRaid. Victim-specific payload encoding and in-memory operation complicate detection and analysis.
read more →

HollowFrame loader deploys Matryoshka backdoor

🛡️ Cybersecurity researchers disclosed a novel Go-based loader called HollowFrame and a Rust backdoor family named Matryoshka, revealed after a phishing intrusion against a law firm. The attack begins with an encrypted archive containing a malicious LNK that triggers a staged chain, uses DLL side-loading with a rogue python311.dll, weakens Defender, and establishes persistence via scheduled tasks. Matryoshka variants communicate over HTTP or via a GitHub-based C2 to receive commands, exfiltrate data, and deliver secondary payloads.
read more →

ESET H1 2026 report: AI skills and adaptable malware

🔍 ESET's H1 2026 Threat Report examines how attackers are scaling operations by adapting established techniques to new platforms and leveraging AI. The vendor analyzed nearly 900,000 AI skills and found tens of thousands of suspicious instances and thousands of malicious ones. AI is appearing inside malware, exemplified by Android PromptSpy using Google’s Gemini to interpret UIs and adapt behavior. The report also highlights social engineering trends like ClickFix, rising quishing, and persistent ransomware tactics such as EDR killers.
read more →

South Korea fines KT over prolonged customer data breach

🔒 South Korea's Personal Information Protection Commission fined KT Corporation KRW 53.979 billion ($39 million) after an internal network compromise persisted nearly 11 months from October 2024 to September 2025. The breach exposed personal data of 16,647 subscribers and enabled fraudulent micropayments for at least 368 customers. Investigators found a lost femtocell with a valid certificate used to create a rogue base station, enabling interception of IMSI, IMEI, phone numbers, and authentication codes. PIPC also discovered BPFDoor malware on 38 IT servers dating to March 2024 and criticized KT for inadequate controls, evidence deletion, and delayed reporting, ordering stronger security and governance measures.
read more →

ThreatsDay: AI-Driven Attacks and Widespread Malware

🛡️ This week’s ThreatsDay Bulletin surveys a wide set of active campaigns and vulnerabilities, from phishing that delivers XWorm and LunaSpy to custom ransomware (GenieLocker) and crypto-focused stealers. Reports detail fileless WebDAV execution, supply-chain hardening by GitHub, a My Eicher fleet takeover flaw, and AI-agent-driven autonomous exploitation across multiple CVEs. Enterprise and consumer impacts include large data exposures and targeted SaaS account takeovers.
read more →

ScreenConnect Abuse in Large-Scale Malware Campaign

🛡️ This analysis examines how threat actors abused the legitimate remote administration tool ScreenConnect in a broad malware distribution campaign. Attackers hosted convincing phishing sites that mimicked popular free utilities, bundling installers that triggered DLL sideloading to silently install ScreenConnect and deploy malicious scripts. Those scripts disabled protections, created Defender exclusions, installed AsyncRAT, and established persistence via scheduled tasks, enabling remote control and lateral movement.
read more →

Malvertising group builds malware inside victim browsers

🛡️ SourTrade, an active malvertising operation since 2024, is concealing its malware assembly inside victim browsers to evade detection. Researchers at Confiant found the campaign impersonates trading and crypto platforms to lure victims with tips and giveaways. Rather than delivering a complete binary, SourTrade sends assembly instructions and clean components that the browser combines in memory to form the final infostealer payload. This in-memory build avoids network fingerprinting and appears as legitimate downloads to security tools.
read more →

Cruciferra Crypter Enables Advanced BYOVD and Evasion

🛡️ Proofpoint reveals that the China-linked crypter Cruciferra is being used to deliver diverse RATs and stealers, employing advanced evasion like BYOVD-based EDR tampering, IAT unhooking, and a custom Process Ghosting variant. The service, advertised since fall 2025, offers polymorphic encryption and modular payload delivery via DLL side-loading, affecting sectors such as finance, healthcare, government, and education.
read more →

New TELESHIM campaign abuses Telegram for C2

🛡️ Zscaler ThreatLabz has detected an East Asia–linked campaign targeting Middle Eastern government entities that deploys three previously unreported malware families: TELESHIM, MIXEDKEY, and BINDCLOAK. The attack begins with an ISO that sideloads a rogue DLL to run a 32‑bit backdoor (TELESHIM) which uses the Telegram API for command-and-control, then stages additional payloads via DLL side‑loading and a reflective loader (MIXEDKEY). TELESHIM and MIXEDKEY employ heavy obfuscation and anti-analysis checks, while the final 64‑bit implant BINDCLOAK communicates with an external C2 server; observed activity occurred between July 7–9, 2026.
read more →

Steam forum ClickFix attacks deliver XMRig miners

🛡️ Threat actors are abusing Steam discussion forums with ClickFix social engineering posts that instruct users to run PowerShell commands purportedly to fix game or system issues. The commands download and run an XMRig cryptominer disguised as a Windows optimization utility named msf utility \ PC Opt, which fakes maintenance progress while installing a miner as C:\Windows\Background\system.exe and persisting via a scheduled task. Victims are advised to check for the Background folder, Defender exclusions, and scheduled tasks named 'XMRig-[computer name]' and to run antivirus scans or consider OS reinstall.
read more →

Malvertising builds malware in browser memory

🛡️ A widespread malvertising campaign uses fake Solana, Luno, and TradingView pages with malicious JavaScript that assembles malware directly in the browser's memory. The operation, active since late 2024 across 12 countries, filters out researchers and scanners while delivering customized payloads to retail traders and crypto investors. Confiant found the pages register service and shared workers to piece together a unique executable from remote components and local bytes, avoiding transmission of a finished file to evade detection.
read more →

Weekly ThreatsDay Bulletin: Multifaceted Cyber Risks

🛡️ This week's ThreatsDay Bulletin catalogs varied, evolving threats that masquerade as useful software or ordinary files. Highlights include npm and PyPI supply-chain risks, a rogue VS Code extension, a fake Claude app delivering SectopRAT, and Android apps posing as civil-defense tools that instead enable surveillance. The report also details PLC-targeting activity linked to Iranian-affiliated actors and new AI-related exploitation techniques.
read more →

TrickBot shifts to DNS tunneling for C2 communications

🛡️ Fortinet researchers uncovered a TrickBot variant that abandons HTTP for a custom DNS tunneling C2 channel, embedding encrypted commands and payloads within malformed DNS queries. The modular malware uses single-byte XOR encoding, hex-encoding and 63-character domain chunking for outbound beacons, while inbound data hides in multiple IPv4 addresses returned by resolvers. Persistence relies on Windows Task Scheduler with NTFS ADS, and command handling retains prior modular capabilities for executing modules, DLLs, PowerShell and shellcode.
read more →

Massive FakeGit campaign leverages GitHub to spread malware

🔎 Researchers uncovered the FakeGit campaign using some 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, amassing over 14 million download events. Many repos impersonated legitimate tools and AI skills, employing an AgentBaiting technique to attract AI agents and developers. The campaign reused tactics from a prior Lumma Stealer operation, and Island recommends isolating and vetting AI skills, rotating secrets, and validating publishers.
read more →

HollowGraph: Malware Using Microsoft 365 Calendar C2

🛡️ Group-IB discovered a .NET espionage implant called HollowGraph that uses a hijacked Microsoft 365 calendar as a covert command-and-control channel, reading operator instructions from a calendar event dated 2050-05-13 and exfiltrating stolen files as attachments. The implant uses the Microsoft Graph API to blend with legitimate traffic and avoids contacting attacker-owned servers directly. A secondary DNS-based channel supplies Entra ID client credentials via IPv6 AAAA records, written to a log file named logAzure.txt. Group-IB links the malware to the Cavern code family and recommends monitoring calendar events, application-driven Graph activity, and suspicious DNS AAAA queries.
read more →

OnlyFans creators help CISOs curb site abuse

🔒 Security researchers report that OnlyFans creators are using DMCA takedown rights and search engine mechanisms to disrupt scam networks that host stolen adult content on compromised government and university websites. These operations — called SEO parasites — route traffic from hijacked entry pages to monetized scam or malware sites. The takedowns not only remove illicit content from search results but also prompt site owners to investigate and remediate vulnerabilities.
read more →

Shadow Token via Remote Debug: OAuth mailbox hijack

🔒 Kaspersky researchers describe a covert technique named Shadow Token via Remote Debug (STRD) used by the ToddyCat APT to gain persistent access to Google Workspace mailboxes without user interaction. The attackers deploy malware (Umbrij) that duplicates a browser profile, launches a headless debugging browser, and programmatically authorizes a third-party OAuth app to obtain an access token. This approach can survive password resets and evades endpoint detection when properly executed.
read more →

Fake TTF loader used in global phishing campaign

🛡️ Fortinet's FortiGuard Labs reports a global phishing campaign using obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font (.ttf) to evade detection. The attack chain delivers RATs and infostealers such as Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant, employing in-memory execution and various anti-analysis techniques. Researchers noted business- and payment-themed lures, compressed archives with script loaders, and Donut shellcode to avoid writing payloads to disk. Defenders are advised to combine identity controls, application restrictions, and behavior-based detection.
read more →