-
Russian state-linked threat actor BlueDelta has launched a renewed espionage campaign against defense manufacturing, government, and diplomatic organizations in Romania, Spain, and Türkiye using a lightweight Windows backdoor dubbed HOOKEDGE. The activ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework called GoCaracal. Arctic Wolf Labs uncovered the framework while investigating a targeted intrusion in …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The loader disguises executable shellcode as sequences of ordinary English words, helping malware evade sta…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector bodies and defense-industry organizations. The shift is notable because Core Werewolf, previou…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Open VSX has removed three extension identifiers from its malicious-extension list after the legitimate projects they impersonated began reclaiming their names. The move restores publishing access for the affected maintainers but highlights a supply-ch…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SynkLoader, a newly identified modular malware framework that combines Python, C#, C++, PowerShell, and memory-resident payloads to evade endpoint detection. Delivered through Microsoft Teams phishing, the operation uses a convincing fake Windows lock …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AmnesiaStealer, a multi-stage macOS infostealer written in Rust that moves beyond conventional credential theft by giving attackers covert, interactive control over a victim’s authenticated Chromium browser sessions. The malware is being distributed th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing bank-payment lure with a fileless execution chain …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


