The article discusses a new component of the Astaroth spambot, which has been observed in recent attacks. This spambot is primarily used to distribute malware and steal sensitive information from victims. Researchers indicate that the latest version has enhanced capabilities, allowing it to evade detection more effectively than its predecessors. Astaroth targets a range of users, particularly those in sectors that handle confidential data, making it a significant threat. Its ongoing evolution raises concerns for cybersecurity professionals as they work to protect their networks from such sophisticated attacks.
Articles tagged "Malware"
Found 827 articles
Two beta versions of npm packages from the @joyfill namespace have been compromised to include a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4. When these packages are imported into a Node.js environment, they execute an implant that runs encrypted malicious code. This incident poses a significant risk to developers who might unknowingly use these compromised packages in their projects. Users are advised to avoid these specific versions and monitor for any unusual activity in their systems.
SCM feed for Latest
A recent report from Cyber Insider reveals that a malicious map on the Steam Workshop for the game MECCHA CHAMELEON has been used to deliver malware to players. This exploit takes advantage of a vulnerability in the game's mod-loading system, allowing attackers to inject harmful software onto users' computers. Players who downloaded the infected map are at risk of having their personal information compromised or their systems damaged. This incident serves as a reminder for gamers to be cautious about the mods they install and to ensure their systems are protected against potential threats. Users should regularly update their security software and avoid downloading content from untrusted sources.
Researchers have discovered the Dysphoria botnet, which has compromised around 200,000 devices globally. This botnet is particularly notable because it uses Ethereum and Solana blockchain domains to obscure its command and control (C2) infrastructure, making it harder to track and shut down. The botnet is an evolution of previous malware known as jackskid and fbot. The collaboration between QiAnXin XLab and China’s CNCERT to reveal this threat underscores the ongoing challenges in combating sophisticated cybercriminal operations. The use of blockchain technology for such malicious purposes raises concerns about the security of connected devices and the methods attackers are using to evade detection.
Hackread – Cybersecurity News, Data Breaches, AI and More
PhantomEnigma is a cybercriminal group that has been using compromised Brazilian government websites and legitimate email channels to distribute malware. Their primary targets are financial institutions, particularly banks, which they aim to infiltrate while avoiding detection by security systems. This method of attack allows them to maintain persistent access to their victims' networks. The use of trusted government sites adds a layer of credibility that makes it easier for them to trick users into downloading malicious software. As these tactics evolve, organizations need to be vigilant about the security of their online interactions and the integrity of the websites they visit.
Security Affairs
Researchers at Proofpoint have identified a new crypter-as-a-service called Cruciferra, which is being used by cybercriminals to facilitate malware attacks. This service allows hackers to bypass antivirus protections and has been linked to a series of campaigns that target Indian taxpayers, tax professionals, and corporate finance teams. The income-tax-themed lures are being delivered through this shared infrastructure, indicating a collaborative approach among various unrelated criminal groups. This development raises concerns about the growing sophistication of malware delivery methods and the potential for increased financial fraud, especially in regions where tax-related scams are prevalent. Organizations and individuals need to be vigilant against these types of attacks and ensure their cybersecurity measures are up to date.
Kaspersky researchers have identified a new malware campaign attributed to a group known as Mirage Kitten, which primarily targets the Middle East and Africa. This campaign involves several previously undocumented tools, including the NightLedger backdoor and tunneling tools called ArcBridge and BridgeHead. These malicious tools can facilitate unauthorized access and data exfiltration from compromised systems. The emergence of this malware is concerning as it highlights the ongoing cyber threats facing organizations in these regions, emphasizing the need for heightened security measures. Companies should remain vigilant and implement robust defenses to protect against potential breaches.
According to a report from Bleeping Computer, cybercriminals are taking advantage of the Steam discussion forums to distribute cryptominers using a method known as ClickFix. This social engineering tactic tricks users into downloading malicious software that can hijack their computer's resources for cryptocurrency mining. Steam users are particularly vulnerable as they engage in discussions and share links within the forums. The implications of this attack are significant, as it not only affects individual users by slowing down their systems and increasing electricity costs but also raises concerns about the overall security of online gaming platforms. Users are advised to be cautious about clicking on links shared in forums and to ensure their security software is up to date.
A widespread malvertising campaign is targeting users by creating fake websites for popular cryptocurrency platforms like Solana, Luno, and TradingView. Attackers are using malicious JavaScript to build malware directly in users' web browsers, which can compromise their systems without any direct downloads. This tactic not only endangers individual users but also poses a risk to the broader cryptocurrency ecosystem, potentially leading to financial losses and data breaches. Users visiting these counterfeit sites are particularly vulnerable, as the malware can operate without any additional user action. It's crucial for individuals to stay vigilant and ensure they are accessing legitimate websites, especially when dealing with sensitive financial information.
Latest news
A recent study by CDW reveals that 43% of companies have already faced cybersecurity attacks powered by artificial intelligence, particularly in the form of sophisticated phishing and malware threats. This shift in tactics indicates that cybercriminals are increasingly using AI to enhance their attacks, making them more effective and harder to detect. Despite the growing threat, the research raises concerns about whether enough organizations are adopting AI-driven defenses to counter these emerging risks. As companies grapple with these new challenges, they must prioritize integrating AI into their cybersecurity strategies to protect sensitive data and systems. The findings serve as a wake-up call for businesses to reassess their security measures and ensure they are equipped to handle AI-enhanced threats.
A new malvertising campaign called SourTrade is targeting unsuspecting users by mimicking well-known cryptocurrency and trading platforms. This campaign uses a unique method that allows it to embed information-stealing malware directly into the victims' web browsers. Once a user interacts with the fake sites, the malware can extract sensitive information, such as login credentials and financial data. This strategy poses a significant risk, especially to individuals involved in cryptocurrency trading, as it could lead to financial loss and identity theft. Users are advised to remain vigilant and verify the authenticity of websites they visit, particularly those related to financial transactions.
A cybercrime group linked to China has been using a sophisticated crypter service named Cruciferra to hide malware in attacks targeting Indian taxpayers, tax professionals, and corporate finance teams. Recent analysis from Proofpoint reveals that this service allows various cybercriminals to deliver different forms of remote access malware while evading detection. Cruciferra employs techniques such as Bring Your Own Vulnerable Driver (BYOVD) and process ghosting, which help the malware operate stealthily on victim systems. The implications of these tactics are significant, as they enable attackers to compromise sensitive financial data and potentially cause substantial financial harm to individuals and organizations. This development is a reminder for users and companies to remain vigilant against evolving cyber threats and to implement strong security measures.
Cybersecurity researchers have identified a series of cyberattacks targeting government agencies in the Middle East, linked to a threat group from East Asia. The attackers are using Telegram for command and control (C2) operations and have deployed new malware families named TELESHIM, MIXEDKEY, and BINDCLOAK. Zscaler ThreatLabz reported that these activities were detected earlier this month. The implications of these attacks are significant, as they exploit communication platforms for malicious purposes, potentially compromising sensitive government data and operations. Understanding these tactics is crucial for enhancing security measures in affected regions.
In September 2025, attackers compromised the credentials of an npm maintainer, allowing them to release malicious versions of popular packages including chalk and debug. These packages are widely used, collectively racking up over 2 billion downloads weekly. In response, GitHub announced that it would delay automatic version updates to allow time for malware detection before users receive updates. This incident underscores the risks associated with open-source package management, where speed can sometimes lead to vulnerabilities. Developers and teams relying on these packages need to be vigilant and ensure they review updates carefully to avoid introducing malicious code into their projects.
The Security Affairs Malware Newsletter discusses recent malware threats, including a backdoor introduced through compromised RubyGems like SleeperGem, Dendreo, and fastlane. These malicious packages can allow attackers to maintain persistent access to affected systems. Additionally, the report highlights the chaos caused by over 800 fake AI skills and MCP servers that delivered malware to unsuspecting users. The newsletter also mentions a ransomware variant called msaRAT that poses further risks. These developments are significant as they illustrate the evolving tactics used by cybercriminals, affecting developers and users who rely on these tools. Companies and users should remain vigilant and ensure their software sources are secure to prevent such incidents.