Malware & threats
101 stories

Malicious npm Package Poses as Twilio Bug-Bounty Probe
Researchers discovered a malicious npm package that mimics a Twilio security tool to steal developer credentials and environment data.

Microsoft Takes Down EvilTokens Device-Code Phishing Service
Microsoft and international partners took down the EvilTokens phishing-as-a-service platform that leveraged AI to facilitate large-scale business email compromise.

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code
A malicious npm package named indexed-btree hid its execution logic within runtime code to bypass new npm security restrictions.

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat group SideCopy is using ReverseRAT in spear-phishing campaigns targeting Indian academic institutions.

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus
Attackers are distributing a fake LastPass Authenticator installer on GitHub that uses a malicious, Microsoft-signed kernel driver to disable security software and deploy a password stealer.

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
North Korean threat actors have compromised 30,000 devices and stolen over $10 million in a long-running fake job recruitment campaign.

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Researchers discovered a new PowerShell-based malware campaign called TASK#STOMP that uses native Windows tools to harvest sensitive data and establish redundant persistence.

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are using ClickFix lures and Polygon smart contracts to deliver a new RAT called ChainScript.

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories
The threat group Transparent Tribe is using new Rust-based malware and private GitHub repositories for C2 in attacks against government and defense targets.

Scammers use 80s photo trend to blackmail Bengaluru man
A Bengaluru man was blackmailed after installing a fake photo editing app that gave scammers access to his device.

Abandoned CDN Domain Re-Registration Risks Website Security
Expired domains previously used by content delivery networks are being re-registered by attackers to serve malicious code to websites that still link to them.

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Researchers discovered 13 malicious npm packages distributing a new stealer called WeaselBiscuit that targets Chrome extension storage.

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven Stealer
A threat actor created the PhantomRaven information stealer using LLMs to facilitate fraudulent bug bounty submissions.

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
A new Android malware called RatHat utilizes AI and ADB abuse to maintain persistent device access even after uninstallation.

Iranian Hacktivists Linked to Heavygram Telegram Surveillance Backdoor
Researchers link the Iran-affiliated Handala Hack group to HEAVYGRAM, a Telegram-based backdoor used to target dissidents and steal passwords.

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The threat actor FamousSparrow is targeting Latin American government entities using a newly discovered backdoor called SparroWocky.
Professor of Tumkur University cheated of Rs 1.32 lakh
A professor at Tumkur University was defrauded of 1.32 lakh rupees after clicking a malicious APK file.

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan uses a tool called Vwork to create Android work profiles to evade security checks on infected devices.

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Threat actors are abusing the Google Play Early Access program to distribute deceptive applications for ad revenue and fraudulent schemes.

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
UNC3569 exploited a vulnerability in the Sogou Input Method to deploy the GRAYRABBIT backdoor.

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
A swarm of OpenAI agents used junk RubyGems packages to achieve remote code execution on RubyDoc servers and scrape public data.

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic disrupted a Russian state-sponsored actor using AI-assisted workflows to automate malware evasion and deployment.

JADEPUFFER group targets AI infrastructure using new ENCFORGE ransomware strain
A threat actor known as JADEPUFFER deployed a new Go-based ransomware strain called ENCFORGE targeting AI model files and infrastructure after exploiting a remote code execution vulnerability in Langflow.

BambooToken Malware Uses MQTT to Control Windows and Linux Systems
The BambooToken malware uses the MQTT protocol for command-and-control communication to target organizations in Asia and South America.

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Intelligence agencies from the U.S., U.K., and the Netherlands issued a joint advisory regarding Iranian state-sponsored malware targeting dissidents and journalists.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials
A Brazilian banking malware operation named KREMLIN uses malicious browser extensions to steal credentials and session tokens from Chrome and Edge users.

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The N0va phishing kit is targeting North American and European organizations by abusing legitimate authentication flows and trusted business platforms.

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
An attacker hijacked an AI coding-assistant session to deploy the Shai-Hulud worm across approximately 100 internal software repositories.

Shai-Hulud's Reach Just Grew to 469 Credential Locations
The Shai-Hulud infostealer worm has expanded its credential scanning capabilities across 469 locations in developer and CI/CD environments.

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool
Threat actors are using the legitimate Node.js runtime to execute malicious scripts and deploy backdoors in targeted cyber attacks.