-
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload ins…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kaspersky says OkoBot targets crypto users through fake software, stealing wallet files, seed phrases and passwords while recording activity inside wallet apps.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The China-linked Daxin backdoor has resurfaced in an active intrusion targeting a Taiwan-based subsidiary of a multinational high-tech manufacturer, exposing the enduring reach of an espionage operation first publicly detailed in 2022. Daxin’s return i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly documented malware framework dubbed OkoBot is targeting cryptocurrency users with a multi-stage intrusion chain designed to capture Ledger and Trezor recovery phrases, browser credentials, wallet files, keystrokes, screenshots, and application …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A previously undocumented Rust-based remote access trojan, dubbed LabubaRAT, which masquerades as legitimate NVIDIA software to establish persistent access on Windows systems. The malware was identified by the company’s Adversary Pursuit Group (APG) an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
11 malicious NuGet packages masquerading as game cheats, automation bots, and management “panels” that deploy a Windows payload called pepesoft.exe. The packages were published as .NET command-line tools, enabling users to install them through the dotn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A threat campaign discovered in mid-July 2026 abused the compromised Artlist subdomain new-blog. artlist[.]io to distribute a Remote Access Trojan through a fake CAPTCHA prompt. The operation combined stolen WordPress credentials, blockchain-based Ethe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Adaptive, AI-driven malware could challenge a foundational assumption in enterprise defense: that a malicious program’s exploitation logic remains fixed after deployment. New research on adaptive computer worms argues that a self-replicating agent pair…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dr.Web details Siggen Windows backdoor that uses Steam for C2, steals credentials and crypto data and infects Visual Studio projects to spread among developers.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft details GigaWiper, a destructive Windows backdoor that can wipe disks, encrypt files and give attackers remote access to compromised systems globally.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


