Malware

Other conventional threat types

Showing 21–40 of 44 threats, newest first

spear-phishingloaderbackdoorgo-malwarerust-malwarelaw-firm-targetingLNK-abuse

A newly documented Go-based loader called HollowFrame is being used to deploy a Rust-based backdoor tracked as Matryoshka in targeted spear-phishing attacks, with at least one confirmed intrusion against a law firm. The infection begins with a phishing email linking to an encrypted archive containing a malicious Windows LNK file that triggers a multi-stage execution chain leading to backdoor deployment.

Updated Aug 1, 2026

macOSmalvertisingNorth KoreaDPRKContagious Interviewcrypto-theftsocial-engineeringfake-updateagent-relevant

North Korea-linked threat actors are running a malvertising campaign that redirects macOS users to fake full-screen software update pages as part of the ongoing Contagious Interview operation. The fake update lure delivers malware designed to steal cryptocurrency and credentials from infected hosts.

Updated Jul 31, 2026

botnetmirai-variantddoslinuxtelnet-bruteforceiotpersistence

Tengu is a newly identified Mirai-derived Linux botnet that abuses hardware watchdog timers to force device reboots when its main process is killed, allowing persistence mechanisms to relaunch it. It spreads via Telnet credential brute-forcing and supports 25 DDoS attack methods, posing a risk to internet-facing Linux and IoT devices with weak credentials.

Updated Jul 29, 2026

iotbotnetddosblockchain-c2resilient-infrastructuredecentralized-dnscncertxlab

Dysphoria, an IoT botnet lineage tracked by CNCERT and XLab, has upgraded its command-and-control architecture to use blockchain-based naming services and peer-to-peer relays across infected devices, making it significantly more resilient to takedown efforts. This evolution follows a March 2026 law enforcement disruption of related JackSkid infrastructure, indicating the operators are actively hardening their C2 model against future enforcement action.

Updated Jul 28, 2026

botnetddosiot-malwaretraffic-relaylarge-scale-compromise

Dysphoria is a newly identified DDoS botnet that has compromised approximately 200,000 devices globally. The malware is being used both for distributed denial of service attacks and as a traffic relay/proxy network, indicating a dual-purpose criminal infrastructure. Its rapid scale suggests exploitation of weak credentials or unpatched vulnerabilities in widely deployed internet-facing devices.

Updated Jul 28, 2026

malvertisingwindowsfake-cryptosocial-engineeringevasionbun-runtimetrading-platforms

SourTrade is a malvertising campaign active since late 2024 that impersonates trusted brands like TradingView, Solana, and Luno to lure retail traders and crypto investors. It uniquely constructs its malicious Windows executable client-side, in the victim's browser, using a legitimate Bun JavaScript runtime as its base, avoiding detection by never serving a single complete malicious binary from a static URL.

Updated Jul 26, 2026

malvertisingfileless-malwarecryptocurrencybrowser-based-attacksocial-engineeringin-memory-executionagent-relevant

A large-scale malvertising campaign is directing users to fake Solana, Luno, and TradingView websites that use malicious JavaScript to assemble malware directly in browser memory, evading disk-based detection. The campaign targets users seeking cryptocurrency and trading tools, likely aiming to steal credentials, wallet keys, or session tokens.

Updated Jul 26, 2026

clickfixcryptominingxmrigsocial-engineeringsteamgamingfake-fixclipboard-hijack

Threat actors are posting fake troubleshooting guides on Steam discussion forums that use the ClickFix social engineering technique to trick gamers into executing malicious commands via the Windows Run dialog. These commands ultimately deploy XMRig cryptominers on victim machines, hijacking system resources for cryptocurrency mining.

Updated Jul 26, 2026

RATremote-access-trojanAI-powered-malwarevictim-profilingcredential-theftagent-relevant

Dolphin X is a newly identified remote access trojan that incorporates an AI-driven profiling feature to automatically score and rank infected hosts by potential value, allowing operators to prioritize high-value victims for follow-on exploitation. This automation reduces the manual triage effort typically required by threat actors managing large botnets of compromised machines.

Updated Jul 24, 2026

north-korealazaruscontagious-interviewottercookiesteganographyfake-job-lurecredential-theftcrypto-theftagent-relevant

North Korean threat actors behind the Contagious Interview campaign are using fake coding tests and job postings to lure developers into running malicious projects. The payloads are hidden via steganography in SVG flag images, ultimately deploying a four-stage OtterCookie-aligned malware chain that steals browser credentials, crypto wallets, and files.

Updated Jul 19, 2026

infostealercredential-theftagent-relevantbrowser-securitydata-exfiltration

Microsoft has identified a significant surge in attacks deploying ACR Stealer, an information-stealing malware targeting enterprise customers. The malware harvests browser-stored passwords, authentication tokens, and sensitive documents, posing a serious risk to organizational credential security and downstream account compromise.

Updated Jul 19, 2026

macosinfostealercredential-theftsocial-engineeringagent-relevant

ClickLock is a newly identified macOS information-stealing malware that forcibly terminates all visible user processes to coerce victims into entering their system login password. Once captured, this password can be used to unlock keychains, decrypt stored credentials, and gain deeper system access. The technique represents an evolution in macOS malware social engineering, exploiting user trust in system prompts.

Updated Jul 17, 2026

iotbotnetllm-generated-malwareai-assisted-malwarelinuxmirai-variant

TuxBot v3 Evolution is a newly disclosed IoT botnet framework whose codebase shows evidence of being partially generated using an LLM, including a leftover safety disclaimer the developer failed to strip out. The botnet targets vulnerable IoT devices for likely DDoS and further propagation purposes, illustrating growing use of generative AI tools in lowering the barrier to malware development.

Updated Jul 16, 2026

macosinfostealergatekeeper-bypassnotarization-abusenative-c++credential-theftagent-relevant

CrashStealer is a newly identified macOS information stealer written in native C++ that uses a notarized dropper to bypass Gatekeeper security checks. Unlike typical macOS stealers built with AppleScript or Objective-C wrappers, its native implementation and local password validation suggest a more sophisticated, evasion-focused development approach. The malware is designed to harvest sensitive data from compromised systems, including credentials and stored secrets.

Updated Jul 14, 2026

macOSinfostealercredential-theftkeychaincrypto-walletagent-relevant

CrashStealer is a newly identified macOS information-stealing malware that disguises itself as Apple's legitimate crash-reporting utility to gain user trust and system access. Once executed, it harvests saved credentials, macOS Keychain data, and cryptocurrency wallet files, exfiltrating them to attacker-controlled infrastructure. Its impersonation of a trusted system tool makes it likely to evade casual user scrutiny and some endpoint defenses.

Updated Jul 14, 2026

RATChina-nexusRustgRPCC2SEO-poisoningcounterfeit-installersSilver-Fox

The China-linked threat actor Silver Fox has been attributed a new Rust-based remote access trojan called MODBEACON, which uses gRPC streaming to encrypt and obfuscate its command-and-control traffic. Despite appearing as an opportunistic, low-sophistication campaign relying on SEO poisoning and trojanized installers for distribution, researchers assess the group demonstrates notable organizational and technical maturity.

Updated Jul 13, 2026

androidmobile-malwareadbwireless-adbshell-accessprivilege-escalationmobile-security

A new variant of the RedHook Android malware exploits the Android Wireless Debugging (Wireless ADB) feature to obtain shell-level access on infected devices without requiring a wired connection to a computer. This removes a key barrier that previously limited ADB-based attacks, making device compromise more autonomous and scalable. The technique poses a significant risk to Android users and enterprises relying on mobile devices for authentication and access.

Updated Jul 13, 2026

wiperdestructive-malwarefake-ransomwarespywarewindowsbackdoormicrosoft-research

Microsoft has identified GigaWiper, a modular Windows backdoor that combines three legacy destructive tools into a single operator-controlled framework. The malware offers command-selectable payloads including full disk wiping, Windows drive overwriting, and fake ransomware that encrypts files without retaining decryption keys, making recovery impossible even if a ransom is paid.

Updated Jul 10, 2026

residential-proxyfake-installertrojanized-softwaremalvertisingdns-abuseagent-relevant

A threat actor dubbed Lurking Lizard has been running a residential proxy business since at least August 2022 using more than 230 lookalike domains that distribute trojanized software installers, including fake 7-Zip installers. Victims who download these fake installers unknowingly turn their devices into residential proxy exit nodes, which are then resold for anonymized traffic routing, potentially including malicious or fraudulent activity.

Updated Jul 9, 2026

androidbanking-trojanmaastelegrammobile-malwarecredential-theftotp-interceptionoblivion-variant

RedWing is a newly identified Android malware-as-a-service operation, rented out via Telegram for roughly $300/month, that allows low-skill attackers to take full control of victim devices, steal banking credentials, and intercept one-time passcodes (OTPs). Discovered by Zimperium's zLabs, it is believed to be a new variant of the Oblivion malware family, lowering the barrier of entry for widespread mobile banking fraud.

Updated Jul 8, 2026