2026-08-27 11:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 11:25 UTC
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat
P0
2026-08-27 09:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-27 10:15 UTC
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control
P0
2026-08-27 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are targeting the AI attack surface to deliver malware and steal data. See how trusted AI tools are being exploited today.
P0
2026-08-26 21:33 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-08-26 21:50 UTC
GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.
P0
2026-08-26 17:33 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-08-26 18:50 UTC
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections.
P0
2026-08-26 15:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka
P0
2026-08-26 07:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&
P0
2026-08-26 06:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB Threat Intelligence performed enrichment and APT hunting based on recent public data about the Tortoiseshell APT group, leading to the discovery of new samples sharing similarities with known Tortoiseshell malware and additional operational infrastructure.
P0
2026-08-25 11:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
P0
2026-08-25 11:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-25 12:45 UTC
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development
P0
2026-08-25 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Sara McBroom · indexed 2026-08-25 10:20 UTC
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.
P0
2026-08-25 07:15 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-25 07:25 UTC
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control […]
P0
2026-08-24 20:51 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-24 21:15 UTC
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
P0
2026-08-24 17:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 23:15 UTC
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,
P0
2026-08-24 17:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-24 18:10 UTC
A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the […]
P0
2026-08-24 15:02 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-24 15:50 UTC
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
P15
2026-08-24 14:34 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-08-24 15:05 UTC
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
P0
2026-08-24 12:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 14:05 UTC
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
P15
2026-08-24 12:15 UTC
Security Journalism
The Record · indexed 2026-08-24 12:30 UTC
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet.
P0
2026-08-24 11:51 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 12:10 UTC
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate
P0
2026-08-24 08:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 08:45 UTC
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open
P0
2026-08-24 07:23 UTC
Community
SANS Internet Storm Center · indexed 2026-08-24 07:35 UTC
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn't use real steganography:
P0
2026-08-23 17:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-23 18:20 UTC
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]
P15
2026-08-23 14:23 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-23 14:25 UTC
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
P0
2026-08-23 08:29 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-23 09:20 UTC
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries Malware Hijacks Android Car Head Units […]
P0
2026-08-22 14:14 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-22 14:30 UTC
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
P0
2026-08-22 08:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-22 09:15 UTC
Malware is abusing car infotainment updates to install proxy software, turning Android head units into nodes for the BADBOX network. Kaspersky researchers found something in June 2026 that made them stop and look twice: an Android app with no interface at all, installed like any ordinary app but making zero effort to disguise itself as […]
P0
2026-08-21 18:53 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 20:30 UTC
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary, marks it executable, and launches it as a detached background process," TrendAI, Trend Micro's
P0
2026-08-21 18:01 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-21 18:05 UTC
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
P0
2026-08-21 15:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-21 16:40 UTC
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of
P0