Articles tagged "Malware"

Found 827 articles

The 'TerminalFix' campaign has emerged as a serious cyber threat targeting enterprise networks. This attack employs a ClickFix-style approach, characterized by a complex, multistage process that includes creating reverse tunnels to infiltrate victim organizations. The use of PowerShell in these attacks allows cybercriminals to execute commands and scripts remotely, making it easier for them to manipulate systems without detection. Companies with vulnerable defenses should be particularly cautious, as these tactics can lead to significant data breaches or system compromises. The sophistication of the attack underscores the need for robust security measures and ongoing vigilance in cybersecurity practices.

Read Original

Recent cybersecurity incidents highlight various vulnerabilities and threats that users and organizations need to be aware of. A router was discovered to be configured to listen for sensitive information right out of the box, potentially compromising user data. Additionally, attackers used a fake check to trick a user into installing malicious software, leading to unauthorized access to traffic and passwords. Old vulnerabilities were exploited in new ways, forming complex attack chains. Even AI systems are not immune, as one agent strayed from its intended task. Alongside this, fake applications and weak security defaults continue to pose risks, emphasizing the need for heightened vigilance in cybersecurity practices.

Read Original

A cybersecurity group has reported that a threat actor known as Silver Fox is distributing a backdoor malware called ValleyRAT by disguising it as a legitimate signed adware application. This adware, specifically a desktop wallpaper tool named QN Wallpaper, is being added to users' antivirus exclusions, allowing the malware to operate undetected. The tactic of embedding malware within trusted applications poses a significant risk to users, as they may unknowingly grant access to their systems. Kaspersky, a Russian cybersecurity vendor, identified this method, which raises concerns about the security of software that users might consider harmless. This incident serves as a reminder for users to be cautious about what they exclude from their antivirus protections.

Read Original

Anthropic has issued a warning to users of its AI assistant, Claude, regarding a new infostealer malware threat. This malware compromises users' computers, stealing active login sessions for Claude and allowing attackers to access these accounts and consume their usage. The situation poses a significant risk as it could lead to unauthorized access and potential data breaches for affected users. The company emphasizes the importance of securing personal devices to prevent such attacks. Users are advised to check for malware on their systems and take appropriate security measures to protect their accounts.

Read Original
Actively Exploited

The latest Security Affairs Malware newsletter reports on a campaign named Operation QUICSILVER, which is attributed to a Chinese-linked actor targeting diplomats in Myanmar. This operation involves the use of a Go backdoor that is delivered via VHD files. In addition, the newsletter discusses the emergence of FTP banners as a new method for delivering remote access Trojans (RATs). The report also touches on the evolving landscape of AI-enabled malware, highlighting changes from brand abuse to more sophisticated attacks. These developments indicate a growing trend in cyber threats that exploit both social engineering and advanced technology, affecting diplomatic communications and potentially compromising sensitive information.

Read Original

Researchers have identified 19 browser extensions—18 for Google Chrome and one for Microsoft Edge—that contain malicious code designed to steal cryptocurrency wallet secrets and drain funds. These extensions were published in the last six months and share similar coding techniques, suggesting they may be part of a coordinated attack. Users of these browsers who have downloaded these extensions are at risk of losing their cryptocurrency assets. This discovery highlights the need for users to scrutinize extensions before installation and for browser vendors to enhance their review processes to prevent such malicious software from being available in their stores.

Read Original

A new campaign is targeting individuals and organizations in Cambodia using a remote access trojan (RAT) known as Spark RAT. The attackers are employing various lure themes, including government notices, public health information, and real estate content, to entice a wide range of potential victims. Notably, the campaign exploits a vulnerable OPSWAT driver, which allows the malware to disable security tools, making it easier for attackers to infiltrate systems undetected. This situation is concerning as it not only threatens personal and organizational data security but also raises alarms about the potential for broader impacts on national security and public safety. Users in Cambodia should be particularly vigilant and ensure their security measures are up to date.

Read Original

In June 2026, a new malware framework named GoCaracal was identified during an intrusion at a communications organization in Venezuela. Linked to the Dark Caracal group, this Go-based malware allows attackers to gain remote shell access and execute malicious payloads. It also has capabilities for stealing browser data, logging keystrokes, and controlling remote desktops. The use of Ethereum smart contracts to dynamically fetch replacement command-and-control (C2) addresses makes it particularly sophisticated and harder to track. This incident is concerning as it highlights the evolving tactics of cybercriminals and the potential risks to sensitive information within the communications sector.

Read Original

Nimbus Manticore, linked to the Tortoiseshell hacking group, has expanded its capabilities by deploying a new SSH-based tunneling tool and a C++ backdoor that resembles its existing malware known as TWOSTROKE. This development indicates a shift in tactics, allowing attackers to establish more secure communications with compromised systems. The increase in their malware arsenal raises concerns for organizations that may be targeted, as it suggests a growing sophistication in their operations. Companies need to be vigilant and enhance their defenses against potential intrusions, especially those using SSH protocols. The implications of this escalation could lead to more successful breaches and data exfiltration if not addressed promptly.

Read Original

Dark Caracal, a cyber espionage group, has introduced a new malware framework called GoCaracal. This modular tool enhances their ability to steal sensitive information and maintain persistent access to compromised systems. Researchers indicate that this new framework allows attackers to customize their approach, making it more challenging for victims to defend against these threats. The implications are significant, as organizations may face increased risks of data breaches and espionage, particularly if they are targeted by this group. Users and companies need to remain vigilant and implement strong security measures to protect their data from such sophisticated attacks.

Read Original

A group known for operating a click-fraud botnet is now targeting infotainment systems in vehicles, exploiting legitimate update mechanisms to spread malware. This new tactic allows attackers to hijack the update process, potentially infecting car head units with malicious software. The implications of this are concerning, as it could compromise the functionality of car systems and expose personal data of drivers and passengers. This type of attack not only puts individuals at risk but also raises questions about the security of automotive software updates. Users of affected vehicle infotainment systems should remain vigilant and consider how they manage software updates to protect against these threats.

Read Original

A recent analysis by Palo Alto Networks' Unit 42 examined 405 malware samples that are linked to artificial intelligence. The findings revealed that while AI can accelerate the development of malware, it does not necessarily improve its success rate. Out of the analyzed samples, only 12 managed to reach production endpoints, which indicates that most AI-generated malware struggles to effectively infiltrate systems. This study is significant as it suggests that while cybercriminals may adopt AI to create malware more quickly, the effectiveness of these tools remains limited. Companies and security teams should continue to focus on traditional defenses as the majority of AI-linked malware is not successfully deployed.

Read Original

Research by Group-IB has identified new infrastructure associated with the Tortoiseshell malware group, which now includes a backdoor and an SSH tunneling tool. This development indicates that attackers are expanding their toolkit, potentially increasing their ability to infiltrate and control compromised systems. The introduction of these tools can allow malicious actors to maintain persistent access and exfiltrate sensitive data without detection. Organizations should be aware of this evolving threat and take proactive measures to secure their environments against such intrusions. The findings highlight the ongoing risks associated with sophisticated cyber threats, particularly for businesses that rely on networked systems.

Read Original

Recent research has revealed that mobile banking trojans are becoming more dangerous. Approximately 66% of these malicious apps now have the ability to take full control of a victim's device, which includes features like remote access and ransomware capabilities. This development poses significant risks to users, as attackers can not only steal sensitive banking information but also lock devices and demand ransom for access. The rise in these capabilities indicates a shift in the tactics used by cybercriminals, making it essential for users to be vigilant about the apps they download and the permissions they grant. As these threats evolve, individuals and organizations must prioritize cybersecurity measures to protect against potential financial losses and data breaches.

Read Original

A new Windows backdoor known as SLEEPWALKER has been discovered by an independent malware researcher. This backdoor remains inactive until it receives a specifically crafted network packet, at which point it executes commands written in a unique 23-instruction language. The malicious software is an unsigned 64-bit dynamic-link library (DLL) totaling nearly 60,000 bytes, designed for side-loading. This means that it could potentially be used to infiltrate systems quietly and execute commands without detection. The implications are serious, as it poses a risk to Windows users who may unknowingly execute this backdoor, allowing attackers to take control of affected machines.

Read Original
Page 1 of 56Next