Malware

Infostealers, loaders, backdoors, and the frameworks behind them. Each profile carries indicators of compromise and the industries most exposed.

Other conventional threat types

Showing 1–20 of 44 threats, newest first

infostealerinitial-access-brokerwindowspython-malwareunderground-marketplaceagent-relevant

BraZetsu is a Python-based Windows malware framework used by Initial Access Brokers (IABs) to commoditize compromised hosts on underground marketplaces. Rather than acting as a standard infostealer, it functions as a comprehensive toolkit that profiles, categorizes, and packages victim systems for resale to other threat actors, including ransomware operators.

Updated Sep 4, 2026

malvertisingfake-installerdefender-evasionwindows-update-abuseinitial-accesschina-targetedagent-relevant

A malware campaign is using bogus software-download websites that impersonate legitimate vendors to trick users into downloading trojanized installers. Once executed, the malware disables Windows Update and weakens Microsoft Defender to maintain persistence and evade detection, with impact concentrated among China-based operations of multinational organizations and Chinese-speaking users.

Updated Sep 3, 2026

backdoorValleyRATSilver Foxadwarecode-signing-abuseantivirus-evasionRATChina

The Silver Fox threat actor is distributing the ValleyRAT backdoor concealed within a digitally signed Chinese desktop-wallpaper application called QN Wallpaper. By running under a trusted, signed process that users commonly whitelist in antivirus exclusions, the malware evades detection and establishes persistent remote access on infected hosts.

Updated Sep 1, 2026

clickfixsocial-engineeringpowershellreverse-tunnelfake-captchainitial-accessagent-relevant

Microsoft has identified a new ClickFix variant called TerminalFix that uses fake Cloudflare CAPTCHA verification prompts on compromised websites to trick users into copy-pasting and executing malicious PowerShell commands in Windows Terminal. The attack establishes reverse tunnels for persistent remote access, enabling attackers to bypass network perimeter defenses.

Updated Sep 1, 2026

clickfixsocial-engineeringpowershellwindows-terminalreverse-tunnelbackdoorfake-captchainitial-accessagent-relevant

Microsoft disclosed a new ClickFix-style social engineering campaign, dubbed TerminalFix, that uses fraudulent Cloudflare CAPTCHA pages to trick users into executing malicious commands in Windows Terminal or PowerShell instead of the traditional Run dialog. Successful execution deploys a reverse-tunnel backdoor granting attackers persistent remote access to the compromised host. This shift to terminal-based execution increases the likelihood that victims run more complex, capability-rich payloads compared to earlier ClickFix variants.

Updated Aug 31, 2026

infostealersession-hijackingcredential-theftAI-account-abuseagent-relevantLLM-abusetoken-theft

Anthropic has warned that infostealer malware infecting user PCs is exfiltrating active Claude session tokens, allowing attackers to hijack accounts and consume victims' paid usage. This represents a growing trend of infostealers specifically targeting AI service credentials and session cookies rather than just traditional banking or email accounts.

Updated Aug 31, 2026

malwaregamingseo-poisoningsocial-engineeringcredential-theftmalvertising

Threat actors are distributing the Weedhack malware family through fake Minecraft client websites that closely mimic legitimate gaming projects, using SEO poisoning to drive traffic. McAfee Labs has blocked over 6,300 access attempts to these malicious sites, indicating an active and sustained campaign targeting gamers, particularly those seeking cheat clients or modified game builds.

Updated Aug 25, 2026

androidbanking-trojanmobile-malwarevpn-abuseremote-access-trojantoxicpanda

ToxicPanda, an Android banking trojan, has expanded its capabilities to target 349 applications and now supports 167 remote commands. The malware abuses Android VPN permissions to block access to Google Play, likely to prevent security updates or app removal, while enabling device takeover and financial fraud.

Updated Aug 24, 2026

androidiotautomotivead-fraudproxy-botnetsupply-chainfirmwaredownloader

Kaspersky discovered a malware family targeting Android-based vehicle head unit firmware developed by DoFun, which propagates via built-in firmware updaters. The malware deploys a multi-stage downloader used to conduct ad fraud and enlist infected devices into a proxy botnet.

Updated Aug 22, 2026

botnetmirai-variantlinux-malwarerouter-compromisesocks5-proxyiot-security

Evooo1Bot is a newly identified Mirai-based modular Linux botnet targeting internet-facing gateway devices and routers. Once compromised, infected devices are converted into SOCKS5 traffic relay nodes, likely to support proxy-for-hire services or to anonymize other malicious traffic.

Updated Aug 16, 2026

browser-extensionchrome-web-storevpn-proxy-abusetraffic-interceptionrussian-speaking-userssupply-chaincredential-exposure

A coordinated campaign involving 737 free VPN and proxy Chrome extensions, published across at least 40 developer accounts, has been found intercepting browser traffic and routing it through attacker-controlled proxy infrastructure. The campaign primarily targets Russian-speaking users attempting to bypass service blocks, with 274 extensions identified as impersonating 66 legitimate brands, and has amassed over 75,000 installs.

Updated Aug 13, 2026

androidmobile-malwarenfc-relayratbanking-trojancredit-card-fraudfraud

A newly identified Android malware campaign pairs a novel NFC relay tool called WindRelay with the established SpyNote RAT to capture and relay victims' live credit card data to attackers in real time. The combo also facilitates taking out fraudulent loans using stolen victim information, indicating a financially motivated criminal operation targeting mobile banking users.

Updated Aug 13, 2026

botnetddosandroidiothttp2mirai-variant

Kimwolf v7, an evolution of the AISURU Android/IoT botnet, was discovered by Palo Alto Networks Unit 42 in February 2026 with enhanced HTTP/2-based DDoS capabilities designed to blend malicious traffic with legitimate browsing patterns. The improvements increase operational resilience and evasion, making detection and mitigation more difficult for defenders relying on traditional traffic-signature analysis.

Updated Aug 12, 2026

banking-malwareBECclipboard-hijackingcryptocurrency-theftbrowser-manipulationemail-compromisefinancial-fraud

Gen's H1 2026 Threat Report details two distinct financially-motivated attack chains: one leveraging compromised legitimate business email accounts combined with browser manipulation to deliver banking malware, and another using clipboard hijacking malware to silently redirect cryptocurrency payments to attacker-controlled wallets. Both campaigns rely on abusing trust in legitimate channels (real inboxes, clipboard contents) rather than novel exploits, making detection via traditional signature-based tools more difficult.

Updated Aug 9, 2026

clickfixmacosinfostealercrypto-theftsocial-engineeringcredential-theftagent-relevant

A ClickFix-style social engineering campaign is delivering a Go-based macOS infostealer capable of draining cryptocurrency wallets, harvesting browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The infection chain uses a shell script that profiles the victim's CPU architecture before fetching an architecture-specific malware payload, indicating deliberate targeting and evasion.

Updated Aug 8, 2026

macOSinfostealerClickFixcrypto-theftsocial-engineeringcredential-theftagent-relevant

A ClickFix-style social engineering campaign is distributing a Go-based infostealer targeting macOS users, designed to exfiltrate cryptocurrency wallets, browser-saved passwords, Apple Keychain contents, and cached credentials. The attack relies on tricking victims into manually executing malicious commands via fake verification or error prompts, bypassing typical download-based security controls.

Updated Aug 7, 2026

ClickFixmacOSsocial-engineeringfingerprintingevasionmalware-lureinitial-access

A large-scale ClickFix campaign spanning over 250 front-end domains uses server-side browser fingerprinting to selectively serve fake software download lures to macOS users while hiding malicious content from crawlers and sandboxes. Microsoft Threat Intelligence has been tracking this infrastructure for weeks, noting the increased sophistication of its evasion techniques targeting Mac users specifically.

Updated Aug 6, 2026

ClickFixloader-as-a-servicesteganographyCountLoaderDeviceManagerRATRussian-threat-actorsocial-engineeringcross-platformcredential-theftagent-relevant

DOUBLECUP is a newly identified Russian loader-as-a-service that leverages ClickFix-style social engineering to trick victims into executing malicious commands, hiding payload code inside PNG images stored in browser caches. The service delivers CountLoader to both Windows and macOS victims and a new Windows-targeted remote access trojan called DeviceManager, expanding the threat actor's toolkit for initial access and persistent remote control.

Updated Aug 4, 2026

passkeyscredential-theftwindowsgoogle-password-managerpost-exploitationaccount-takeoveragent-relevant

Security researchers disclosed three attack techniques, collectively dubbed 'Pass-ta-key,' that allow malware already present on a compromised Windows device to abuse Google Password Manager's synced passkey feature. The attacks enable adversaries to bypass user verification, hijack accounts protected by passkeys, and extract passkey private keys, undermining a core assumption that passkeys are phishing-resistant and device-bound.

Updated Aug 4, 2026

ad-fraudbotnetresidential-proxyiot-securityandroidclick-fraudsupply-chain

Researchers at Bitsight identified an operation dubbed Fuyao in which cheap Android TV boxes ship with pre-installed apps that spoof device identifiers to impersonate Samsung, Huawei, Xiaomi, or Vivo smartphones, enabling large-scale ad fraud. The same devices are also weaponized to covertly route third-party traffic through owners' home broadband connections, effectively turning them into residential proxy nodes. The operation has been attributed to Zhejiang Fengwo IoT Technology Co., Ltd., a China-based manufacturer.

Updated Aug 1, 2026