malware38 articles
Russian Hacker Extradited Over Excel Macro Campaign That Hit 80,000 Freelance Platform Users
A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited from Cyprus and charged in the US for orchestrating a malware campaign in 2016–2017 that used around 255 fake accounts on a freelance platform to send malicious Excel attachments to approximately 80,000 users. The attachments tricked recipients into running macros that installed two remote access tools — TVRAT and DarkVNC — giving attackers covert control of victims' computers and enabling theft of credentials and personal data. The case highlights the ongoing abuse of freelance and job-hunting platforms as attack vectors, a tactic also currently employed by state-sponsored groups such as North Korea's Lazarus and Russia's Sandworm.
TerminalFix: The ClickFix Variant That Hands Attackers Your Entire Network
is a new variant of ClickFix malware that tricks users into running malicious PowerShell commands via fake Cloudflare CAPTCHA pages on compromised websites. The attack uses a multi-stage process involving DLL sideloading, steganographic payload extraction, and Active Directory reconnaissance, ultimately deploying a Python-based reverse-tunnel backdoor that grants attackers persistent access to the victim's internal network. Microsoft warns the technique is particularly dangerous as it can be exploited to escalate privileges, steal data, and deploy ransomware, and recommends restricting PowerShell execution, monitoring for DLL sideloading, and training employees to recognise ClickFix-style attacks.
APT28 Is Back With a New Backdoor and the Same Old Tricks
Researchers at Recorded Future have attributed a series of cyberattacks targeting government and diplomatic organizations in Romania, Spain, and Türkiye (between late 2025 and early 2026) to Russian state-sponsored group APT28, based on strong code and technique overlaps with the group's previously known tooling. The campaigns deploy a newly identified backdoor called HOOKEDGE — a Windows batch script delivered via macro-enabled Word documents — which uses webhook.site services for command-and-control, payload retrieval, and data exfiltration to blend in with normal network traffic. HOOKEDGE has been continuously refined over the campaign period and is considered a direct successor to APT28's earlier HEADLACE backdoor, with high-value targets receiving a more aggressive second-stage implant offering operators greater interactive control.
QUICAgent Backdoor Targets Myanmar Government in Multi-Stage Espionage Campaign
is a China-linked cyber espionage campaign targeting Myanmar's government and IT sectors, using deceptive lures such as graduation ceremony invitations and holiday calendars to trick victims into executing malware. The multi-stage infection chain abuses legitimate Windows tools like `ftp.exe` to reconstruct and deploy a custom Go-based backdoor called **QUICAgent**, which communicates with its command-and-control server via the QUIC protocol and supports file transfer, command execution, and directory browsing. Separately, the China-linked Mustang Panda group has been observed deploying an updated version of the **COOLCLIENT** backdoor featuring a new kernel-mode driver that enhances stealth by hiding malicious processes and protecting related files from detection.
77 Firefox Add-ons Caught Running a Coordinated Crypto Wallet Heist
Forty malicious Firefox extensions have been discovered impersonating legitimate Web3 products like OKX and Rabby Wallet as part of a campaign called "Offside Wallet Theft Factory," believed to have been active since March 2026. The extensions steal cryptocurrency wallet secrets — including recovery phrases and private keys — using methods such as fake wallet pages, hidden malicious code, and exfiltration via Cloudflare Workers and Supabase. Some extensions initially appeared as innocent sports score or utility tools before being repurposed as wallet-stealing malware, with researchers noting that the low cost of repeatedly publishing disposable extensions makes the campaign highly scalable and persistent.
Poisoned Rust Packages Spent 90 Minutes Stealing Developer Credentials Before Anyone Noticed
Hackers injected malware into several popular Rust packages, including arrayref, internment, and append-only-vec, by compromising a developer's credentials and publishing poisoned versions that fetched second-stage malware capable of stealing browser data, cryptocurrency wallet information, and establishing persistent remote access. The malicious releases were live for under two hours before the Rust Security Response Team removed them, though arrayref's roughly 245 million lifetime downloads highlights the potential reach of such an attack. Developers have been advised to audit their Cargo lockfiles and local registry caches for the affected packages.
Nearly 2,000 Hacked WordPress Sites Are Powering a Surprisingly Sophisticated Criminal Operation
A large-scale cybercrime operation called **StopAndProtect** has compromised nearly 2,000 outdated WordPress websites, using them as infrastructure to distribute malware, issue attacker commands, and store stolen data from victims. The campaign begins with fake ClickFix CAPTCHA prompts that trick users into running malicious PowerShell commands, deploying a toolkit that includes ransomware, a credential stealer, a screen locker, a worm, and a chat utility for communicating with victims. As of late July 2026, over 6,000 unique IP addresses have been compromised, with researchers urging users to be wary of unexpected CAPTCHA prompts that instruct them to run commands outside the browser.
Malware Can Hijack Passkey-Protected Accounts Through Google Password Manager Without Touching Your Screen
Researchers at Unit 42 have identified three attack techniques against Google Password Manager's passkey implementation in Chrome on Windows, which could allow malware already running on a victim's device to silently sign into passkey-protected accounts without any user interaction. The attacks exploit weaknesses in how Chrome stores device keys, handles device re-enrollment, and manages the 32-byte Security Domain Secret used to decrypt synced passkeys — rather than breaking the underlying cryptography. No CVEs have been assigned, the full remediation status is unclear, and it remains unknown whether actions like changing a Google Password Manager PIN would invalidate a secret an attacker has already obtained.
SVR Operatives Are Turning Hotel Wi-Fi Into Malware Traps
Russian SVR operatives (Storm-2945/Midnight Blizzard) are compromising public Wi-Fi captive portal networks at hotels and conference centres to deliver sophisticated malware, in a campaign Microsoft calls "CaptiveCrunch." By manipulating DNS and HTTP traffic to position themselves as adversary-in-the-middle, attackers use ClickFix-style fake prompts — disguised as OS updates or driver repairs — to trick users into installing malware, including a full-featured Windows RAT called CornFlake and an in-memory credential-stealing tool called ChocoShell. The campaign also incorporates device code phishing to hijack victims' Microsoft 365 accounts, with Microsoft advising users to avoid public Wi-Fi where possible and organisations to disable device code authentication flows to limit exposure.
New Backdoors OctLurk and SilkLurk Linked to Chinese-Speaking Hackers Hitting Central Asian Governments
A suspected Chinese-speaking threat actor has been conducting cyberattacks against government and public sector organisations across Central Asia and Syria since January 2025, targeting sectors including healthcare, law enforcement, and foreign affairs ministries. The campaign deploys two newly identified backdoors — OctLurk and SilkLurk — alongside a network proxying tool called LurkProxy, enabling capabilities such as credential theft, keylogging, remote access, and data exfiltration. Both backdoors operate primarily in memory and use victim-specific encoding tied to machine details, making detection and reverse engineering significantly more difficult.
ShareFile Shutdown Orders, Citrix Bleed 2 Ransomware, and AI Coding Assistants You Can't Trust
This weekly cybersecurity recap highlights a recurring theme: attackers are exploiting the same ordinary vulnerabilities faster than defenders can patch them, using the same AI-powered tools now available to security teams. Key incidents include Progress urging ShareFile customers to shut down Storage Zone Controllers due to an unspecified external threat, active exploitation of Citrix Bleed 2 to deploy DragonForce ransomware, a compromised Jscrambler npm package stealing developer credentials, and a new attack technique called HalluSquatting that tricks AI coding assistants into installing malicious code. The recap also covers a broad range of trending CVEs, new malware families, and emerging threat groups, underscoring that the gap between patch availability and active exploitation continues to narrow.
Daxin Is Back, and It Brought a Friend: Meet Stupig, the Pre-Login Backdoor Nobody Saw Coming
A China-linked advanced malware called Daxin has resurfaced at a Taiwan manufacturing firm in 2026, over four years after it was first publicly documented, alongside a newly discovered backdoor called Stupig that hides within the Windows logon process to execute commands with SYSTEM privileges before any user signs in. Both tools carry 2013 compilation timestamps, raising the possibility the intrusion went undetected for up to 13 years. Separately, a suspected China-linked actor has also been observed using AI tools, including Anthropic's Claude Code and DeepSeek, to automate cyberattacks against government and financial targets across multiple countries.
Meet Dolphin X: The Infostealer With an AI Profiler That Tells Crooks Which Victims Are Worth Robbing First
Varonis Threat Labs has discovered a new Windows malware called Dolphin X, sold on cybercrime forums, which targets over 300 applications and can steal credentials, cryptocurrency wallets, SSH keys, and cloud tokens. Its most notable feature is an AI Profiler that analyses victims' app usage, browsing history, and installed software to rank them by likely profitability, helping criminals prioritise their attacks — something researchers say has never been seen before in malware. Sold through a tiered subscription model starting at around $80 per month, the malware lowers the technical barrier for cybercriminals and includes advanced detection-evasion capabilities, prompting security experts to advise defenders to focus on behavioural threat detection rather than file signatures.
7,600 Fake GitHub Repos Are Hunting Developers and AI Agents Alike
A cybersecurity campaign called **FakeGit** has created nearly 7,600 malicious GitHub repositories — over 800 of which impersonate AI tools or Model Context Protocol (MCP) servers — to distribute **SmartLoader malware**, which then deploys the **StealC** information stealer on victims' systems. The campaign uses copied projects, fake developer profiles, and deceptive README files to trick users into downloading malicious ZIP files. A particularly alarming evolution called **AgentBaiting** allows AI agents (including Claude, Gemini, and ChatGPT) to independently discover and act on these fraudulent repositories without any human involvement, meaning the attack no longer requires a victim to click a link.
Misconfigured Server Blows Cover on AI-Assisted Phishing Operation Targeting Mexico
Rapid7 discovered an exposed malware delivery server containing over 1,000 files that revealed a mid-development phishing operation targeting Windows users in Mexico, using a WebDAV working-directory hijack (CVE-2025-33053) to deliver an infostealer disguised as a government ID document. The exposed toolkit showed strong evidence of AI-assisted development, with LLM-formatted documentation, test matrices, and emoji-heavy code suggesting the operator used an open-source AI coding agent to rapidly build, test, and scale the campaign. Over roughly five and a half days the panel logged over 77,000 requests, with Mexico accounting for the vast majority of traffic, and both identified campaign chains ultimately delivered the known .NET malware PureRAT.
TELEPUZ: The Modular Malware Using Telegram, Steam, and a Blockchain to Phone Home
TELEPUZ is a newly discovered modular malware written in C that has been spreading since late April 2026 through ClickFix-style social engineering attacks, which trick users into pasting and executing malicious commands. Once installed, it employs extensive evasion techniques — including anti-VM checks, AMSI/ETW disabling, and obfuscation — before establishing contact with its command-and-control server via WebSockets to steal data, log keystrokes, capture screenshots, and execute commands. The malware uses multiple fallback methods to locate its C2 server, including Telegram, Steam, DNS queries, and a Polygon blockchain smart contract, and is believed to be an early-stage malware-as-a-service (MaaS) offering based on its high build volume and rapid development pace.
GoSerpent Malware Has Been Quietly Raiding Southeast Asian Governments for Months
Cybersecurity researchers at Kaspersky have uncovered a previously undocumented malware called GoSerpent, which has been targeting government and diplomatic entities in Southeast Asia since late 2025 for espionage and long-term intelligence gathering. The malware connects to a command-and-control server to deploy secondary payloads capable of credential dumping, file collection, and data exfiltration, while also supporting SOCKS5 proxying to mask attackers' true IP addresses. The campaign shares similarities with the known threat actor TetrisPhantom, though definitive attribution remains uncertain, and a separate but related espionage operation by DoNot Team was also disclosed, targeting Bangladesh's military using spear-phishing emails.
ACR Stealer Is Raiding Enterprise Networks and All It Needs Is for Someone to Press Enter
ACR Stealer, an infostealer active since 2024, is being distributed through ClickFix lures that trick users into pasting malicious commands into Windows' Run dialog, requiring no vulnerability or exploit to succeed. Once executed, the malware uses two delivery chains — one file-based and one nearly entirely in-memory — to steal browser passwords, session tokens, and Microsoft 365 documents, with techniques including payload concealment inside JPEG pixels and blockchain-based command-and-control infrastructure. Defenders are advised to block the paste-and-run vector via Group Policy, apply application control rules, revoke (not just rotate) compromised tokens, and hunt for indicators such as rundll32.exe making unexplained network connections or scheduled tasks disguised as software updates.
Brazilian Gov Websites Hijacked to Deliver Malware in Active Banking Campaign
A cyberattack campaign called PhantomEnigma has compromised more than 20 Brazilian government websites, turning them into malware delivery channels targeting banks and public agencies. The operation uses fake police-themed documents sent via authenticated emails and trusted `.gov.br` domains to deceive victims into installing a modular backdoor capable of stealing credentials, establishing persistence, and delivering additional payloads. The campaign's abuse of legitimate government infrastructure and rotating command-and-control domains makes it particularly difficult to detect using conventional security tools, with behavioral analysis recommended as a more reliable defence.
OkoBot Malware Serves Fake Recovery Pages Inside Real Ledger and Trezor Apps
OkoBot is a Windows malware framework active since April 2025 that targets hardware wallet users through a module called SeedHunter, which injects fake recovery phrase prompts directly into legitimate Ledger and Trezor desktop applications rather than replacing them. The malware is delivered via ClickFix lures or trojanized software on GitHub, establishing persistent access through reverse SSH tunnels, patched RDP components, and a scheduled task called "Apple Sync," before deploying over 20 surveillance and theft modules. Kaspersky's research identified hundreds of victims across 25+ countries, but attribution remains unclear beyond soft indicators suggesting Russian-speaking threat actors.
North Korean Hackers Are Quietly Poisoning Open Source Repositories
North Korean hackers are conducting a supply chain campaign called PolinRider, active since December 2025, targeting open source developers across NPM, Packagist, Go modules, and Chrome extensions. The attackers compromise maintainer accounts to inject obfuscated JavaScript loaders into legitimate repositories, which deliver the DEV#POPPER RAT and OmniStealer malware, with 162 malicious artifacts identified across 108 packages so far. Security firm Socket warns that any developers who installed affected packages should treat their environment as potentially compromised and conduct remediation from a clean machine, as credentials for package registries, cloud services, and CI/CD pipelines may have been exposed.
Iran's MOIS-Linked Hackers Deploy Modular C2 Framework Against Israeli Targets
An Iranian hacking group called Cavern Manticore, linked to Iran's Ministry of Intelligence and Security, has been targeting Israeli IT providers and government organisations using a newly discovered modular command-and-control framework called Cavern. The framework exploits SysAid's software update feature to deploy a trojanised DLL, enabling capabilities such as file theft, database access, Active Directory reconnaissance, network scanning, and tunnelling, while using multiple .NET compilation formats to deliberately complicate reverse engineering and forensic analysis. The group has also been observed moving laterally through trusted IT supply chain relationships and abusing remote monitoring tools, with related Iranian threat actors simultaneously conducting broader reconnaissance and data exfiltration campaigns across the Middle East.
PamStealer: The macOS Malware That Actually Did Its Homework
Researchers at Jamf have discovered a novel macOS malware called PamStealer, which disguises itself as the Maccy clipboard manager and uses a two-stage infection chain — an AppleScript-based first stage and a Rust-written second stage — to stealthily steal credentials. It stands out by using macOS's built-in Pluggable Authentication Modules (PAM) interface to validate stolen passwords locally, avoiding the detectable system calls used by most comparable malware. The malware also employs additional evasion tactics such as impersonating legitimate macOS components, delaying suspicious prompts by up to 40 minutes, and bypassing macOS quarantine restrictions, illustrating the growing sophistication of Mac-targeted infostealers.
VEIL#DROP: How Attackers Are Hiding Malware Inside Google's Blogger
The VEIL#DROP attack chain uses a disguised JavaScript file to trigger a multi-stage malware infection, leveraging Google's Blogger platform to host payloads and bypass reputation-based security defences. The infection employs advanced evasion techniques including dynamic URL generation, runtime script mutation, fileless in-memory execution, and abuse of trusted Microsoft-signed binaries (Living-off-the-Land) to avoid detection. The ultimate goal is to deploy PureLogs Stealer, a .NET-based malware-as-a-service infostealer capable of harvesting sensitive data and potentially enabling deeper network compromise.
North Korean Hackers Hijack 108 Packages Across npm, Go and Chrome in Sprawling PolinRider Campaign
North Korean threat actors linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist, Go, and Google Chrome as part of an ongoing operation called PolinRider, which has compromised nearly 2,000 public GitHub repositories. The attackers use obfuscated JavaScript payloads, fake font files, and VS Code task files to deliver malware including BeaverTail, DEV#POPPER RAT, and OmniStealer, while rewriting Git history to make malicious changes appear legitimate and harder to detect. Developers are advised to treat any affected environments as fully compromised, rotate secrets, rebuild from clean lockfiles, and audit repositories for suspicious modifications to configuration files.
ToddyCat's Umbrij Malware Quietly Hijacks Gmail via OAuth Abuse
The ToddyCat APT group has developed a new malware called Umbrij that exploits OAuth 2.0 and the Google API to covertly access victims' Gmail accounts. The tool works by launching a Chromium-based browser in headless mode, hijacking an active Gmail session via remote debugging, and using Puppeteer to automate the OAuth authorization process — ultimately obtaining an access token granting full access to Gmail, Drive, Contacts, and other Google services. Organizations are advised to check for unauthorized OAuth app connections, particularly those named "Google Workspace Migration/Sync for Microsoft Outlook," and revoke any suspicious access tokens.
Avalon Malware Framework Bundles Ransomware, Credential Theft and AI-Assisted Development Into One Nasty Package
Cybersecurity researchers have uncovered a modular malware framework called **Avalon**, distributed via phishing emails, which combines credential theft, lateral movement, remote access, and ransomware (internally named CrownX) into a single toolkit. The framework employs sophisticated evasion techniques targeting major security vendors and shows signs of AI-assisted development, highlighting how AI is lowering the barrier to entry for malware creation. These findings coincide with other emerging AI-driven threats, including a fully autonomous LLM-powered ransomware attack and a novel malware that uses a public LLM API to translate plain-language attacker instructions into shell commands — requiring no coding knowledge whatsoever.
DeepSeek Wrote Browser Ransomware When Asked Nicely Enough
Cybersecurity firm Check Point Research discovered that DeepSeek generated a near-functional browser-based ransomware sample called "InfernoGrabber 9000," which exploits the Chrome File System Access API to encrypt local files without requiring any native software installation. Although the original sample was incomplete, researchers found that only minimal technical expertise was needed to make it fully operational, and they successfully built a working proof-of-concept using DeepSeek's latest model with slightly rephrased prompts. Check Point warns that this type of AI-assisted, browser-native attack is likely already being attempted by real threat actors, lowering the bar for cybercriminals significantly.
Ousaban Banking Trojan Is Hunting Iberian Bank Customers via Fake PDF Lures
Ousaban, a Brazilian banking trojan also known as Javali, is targeting Windows users in Spain and Portugal through phishing PDFs that trick victims into downloading malware hidden inside an image file using steganography. Once installed, it monitors banking activity, capturing keystrokes and screenshots, and gives attackers remote control to hijack live banking sessions at over two dozen Iberian banks. The campaign uses geofencing to restrict delivery to genuine targets in the two countries, and evades detection through a rotating daily command server address and a custom encryption scheme that has proved resilient for years.
AI Chatbots Are Sending Users Straight to Cryptojacking Malware
If you ask an AI chatbot to recommend a useful tool or service and it helpfully provides a link, you might want to think twice before clicking. Security researchers have identified a pattern where chatbot recommendations are directing users toward sites hosting cryptojacking malware, software designed to quietly hijack your hardware and mine cryptocurrency for someone else's benefit.
One Hacker Group Is Turning Software Supply Chains Into a Self-Replicating Nightmare
A cybercriminal group called TeamPCP has carried out an unprecedented wave of software supply chain attacks, hiding malware in hundreds of open source tools to breach companies including GitHub, OpenAI, and the European Commission's website. Their self-perpetuating strategy involves stealing developer credentials to compromise more tools, recently automated through a self-spreading worm called Mini Shai-Hulud, resulting in over 500 corrupted software packages across 20 attack waves in just a few months. Security experts warn that organisations should rotate authentication tokens regularly, avoid auto-updating open source tools, and vet new code before deployment, as the group shows no signs of slowing down.
Supply Chain Attack Hits Packagist: Eight PHP Packages Compromised via GitHub-Delivered Malware
Eight packages on Packagist, the primary dependency registry for PHP projects, were quietly backdoored in a supply chain attack that used GitHub infrastructure to serve Linux malware.
One Hacker Group Is Turning Software Supply Chain Attacks Into a Production Line
A cybercriminal group called TeamPCP has carried out an unprecedented wave of software supply chain attacks, embedding malware in over 500 open source tools to infiltrate hundreds of companies, including GitHub, Anthropic, and the European Commission's public website. The group exploits a self-perpetuating cycle — compromising developer tools to steal credentials, then using those credentials to poison more tools — and has recently automated attacks using a self-spreading worm called Mini Shai-Hulud. Security experts warn that organisations must practice better credential hygiene, carefully vet software updates, and avoid automatically installing the latest versions of open source packages to protect themselves.
FBI Director's Merch Site Is Serving Malware to macOS Users
FBI Director Kash Patel's merchandise website, BasedApparel.com, was found hosting a "ClickFix" malware attack that tricks macOS users into running a malicious command by disguising it as a Cloudflare human-verification process. Victims are prompted to copy what appears to be a simple verification code, but the clipboard actually receives a hidden obfuscated command that, when run in Terminal, executes a script designed to steal browser credentials and cryptocurrency wallet data. The attack likely resulted from hackers compromising the site, and the malicious payload was flagged by 27 antivirus engines as a Trojan/infostealer.
Megalodon Attack Poisons Thousands of GitHub Repos via CI/CD Hijacking
Someone has been systematically targeting GitHub repositories at scale.
Microsoft Dismantles Shady Code-Signing Operation Fuelling Ransomware Campaigns
Microsoft has taken down a malware-signing service that threat actors were using to get ransomware and other malicious software past Windows security defences. The operation targeted a cybercriminal outfit providing a kind of laundering service for malware, giving it legitimately signed certificates so it looked trustworthy to the operating system.
Another npm Account Hijacked, 314 Packages Poisoned in Under Half an Hour
A compromised npm account infected 314 JavaScript packages — including popular ones like size-sensor and echarts-for-react with millions of monthly downloads — with malware that steals credentials for cloud platforms, GitHub, and npm, and uses GitHub as a command-and-control backdoor. The attack, which unfolded in just 22 minutes, follows the same pattern as a similar incident three weeks ago and is part of an ongoing wave of npm supply chain attacks dubbed "Shai-Hulud." Developers who installed affected versions are advised to rotate all credentials, while npm owner GitHub has said little about the continuing series of incidents.
Reaper Malware Hits macOS: Steals Passwords, Drains Crypto Wallets, Then Quietly Moves In
A new macOS malware variant called Reaper, an updated version of the SHub stealer, targets users by spoofing trusted domains like Apple, Microsoft, and Google to steal passwords, cryptocurrency wallet credentials, and sensitive files. Unlike earlier versions, it bypasses Apple's Terminal entirely by using macOS Script Editor to execute its malicious payload, circumventing defences added in macOS Tahoe 26.4. The malware also establishes persistent backdoor access by disguising itself as a Google Software Update process, allowing attackers to remotely execute code on compromised machines every 60 seconds.