Skip to main content

Threats Tagged 'malware'

View all threats tagged with 'malware'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: malware

Threats Tagged 'malware'

Click on any threat for detailed analysis and mitigation recommendations

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.

Join the discussion

A malicious NPM package named indexed-btree, impersonating the legitimate sorted-btree package, was discovered to contain hidden malware in its JavaScript prototype method. This supply chain attack accumulated over 2 million weekly downloads by creating a credible GitHub repository and avoiding typical detection methods. The malware collects system information, communicates with a hardcoded Slack channel and Telegram chat, and uses a blockchain smart contract for command-and-control. Multiple related malicious packages have also been identified and removed after millions of downloads. The campaign is ongoing and represents a sophisticated threat to organizations using the NPM ecosystem.

Join the discussion

CLOSEDQUORUM is a Windows malware implant that autonomously performs command and control (C2) by delegating decision-making to a panel of commercial large language models (LLMs). It operates without human intervention or a traditional attacker-operated C2 server, using AI to select and execute actions such as credential and crypto wallet theft. The malware queries up to four LLM providers sequentially, aggregates their decisions by voting, and acts on the majority decision. This represents a novel shift in offensive cyber operations by displacing human effort from the attack phase to the AI system. The public build contains placeholder API keys, so full end-to-end execution was not observed. There is no confirmation of in-the-wild deployment, but the developer is linked to criminal forums.

Join the discussion

CAIRN is a research toolkit developed by Cisco Talos for hunting, classifying, and tracking AI-integrated malware by analyzing metadata artifacts left by attackers. It identifies malware that operationalizes or exploits AI systems by extracting cognitive artifacts such as prompt templates, API endpoints, and evasion strings without requiring binary execution. CAIRN uses acquisition filters, relationship graphing, YARA rules, and semantic discovery to detect and attribute AI-enabled malware families. This metadata-first approach enables scalable and fast detection of emerging threats that integrate AI functionality.

Join the discussion

A widespread campaign impersonates LastPass and at least 40 other companies to distribute a kernel-level malware called Rapuncel via fake installers hosted on GitHub. The malware disables 145 security products by loading a malicious kernel driver and steals sensitive information including passwords, cryptocurrency wallets, and tokens from multiple applications. The campaign uses SEO manipulation and dynamic redirect chains to lure victims. Rapuncel installs as a persistent Windows service, continuously killing security tools and stealing data until the kernel driver is physically removed.

Join the discussion

RatHat is an Android trojan that uses generative AI to automate real-time device navigation and control, enhancing its adaptability and evasion capabilities. It steals credentials, mimics banking apps, intercepts SMS, and gains administrator-level permissions. The malware persists by reinstalling itself if removed and uses advanced keylogging techniques, including hardware-level monitoring of user input. It communicates with a command-and-control server via a secure reverse tunnel and abuses Android debugging tools for system-level access. RatHat is distributed through smishing and malvertising and appears linked to a Chinese threat actor.

Join the discussion

Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

Join the discussion

A malware campaign involving the npm package 'indexed-btree' demonstrates how attackers evade traditional supply chain defenses by embedding malicious code in the package's runtime behavior instead of installation scripts. This technique allows the malware to bypass install-time security checks and execute malicious actions during normal package usage.

Join the discussion

A malware campaign uses fake GitHub repositories impersonating LastPass Authenticator and other software brands to distribute the Rapuncel infostealer. The campaign delivers a Microsoft-signed kernel driver that disables 145 antivirus and EDR products, allowing the infostealer to harvest credentials, cryptocurrency wallet data, session tokens, and sensitive documents. The driver bypasses common protections by operating in kernel mode and is currently not blocked by Microsoft. The malware persists via a Windows service, re-killing security tools on reboot.

Join the discussion

This security news roundup highlights multiple cybersecurity developments including a critical SAP vulnerability (CVE-2026-44756) allowing unauthenticated memory corruption, a WordPress plugin file-upload flaw enabling mass webshell uploads, and a zero-click Plugin4Shell vulnerability affecting AI coding assistants that permits silent malicious plugin updates. Additionally, it covers the sentencing of a ransomware developer, new malware linked to bug bounty hunting, and other notable cybercrime and defense updates.

Join the discussion

Showing 1 to 10 of 590 results

Filters:Tag: malware
Page 1 of 59
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses