-
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In la…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A supply-chain campaign targeting OpenClaw has shown how threat actors can turn autonomous AI agents into persuasive malware-delivery intermediaries. Rather than relying only on exploit code, attackers poisoned the ClawHub skill registry with seemingly…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control (C2) domains without depending on conventional attacker-owned servers. The approach turns a public…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researc…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed Windows malware. The campaign used a fake Web3 recruitment process to deploy a three-payload s…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm install event to spread through developer environments. The self-propagating npm worm, also tracked…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


