Threats Tagged 'spyware'
View all threats tagged with 'spyware'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'spyware'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated mobile threat linked to Indonesian actors combines ransomware and spyware capabilities in a single attack vector. The malware is distributed via third-party file-sharing platforms through social engineering, targeting Android devices. It requests extensive permissions including device administrator, SMS, contacts, and accessibility access. The threat encrypts files using AES on Android 9 and earlier, appending .enc extensions, while stealing sensitive data including screen recordings, browser history, PINs, contacts, call logs, SMS messages, WhatsApp and Telegram chats. It establishes C2 communication via HTTPS and WebSockets using dynamic domain resolution through GitHub. Version 2 introduces UI hijacking, screen blocking, touch input interception, harassment features, and remote text-to-speech capabilities. The malware exfiltrates data through Firebase and Catbox services, enabling double-extortion through an interactive chat portal for ransom demands. Join the discussion | AlienVault OTX General | 09/09/2026, 20:59:12 UTC Added: 09/10/2026, 09:22:42 UTC |
ValleyRAT is a backdoor malware distributed disguised as legitimate Chinese adware called QN Wallpaper. It uses DLL sideloading to execute malicious code under a signed process. The malware includes capabilities such as keylogging, clipboard monitoring, screenshot capture, and module delivery. The campaign has impacted over 1,500 users mainly in China and India with over 100,000 detections in 2026. The Silver Fox threat group is attributed to this campaign. The malware disables Windows Defender, establishes persistence, and protects its processes by marking them critical to cause system crashes if terminated. Join the discussion | AlienVault OTX General | 08/31/2026, 11:11:49 UTC Added: 08/31/2026, 15:38:07 UTC |
A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries. Join the discussion | AlienVault OTX General | 08/20/2026, 11:45:48 UTC Added: 08/20/2026, 23:22:26 UTC |
A fraudulent version of the widely-used PC cleaning utility CCleaner is being distributed through a convincing imitation website to deploy GhostDesk, a malicious Chrome extension functioning as spyware. The attack begins when users download the fake application from a lookalike site, which then launches a multi-stage infection using CScript to modify Chrome's Security Extension and install malicious components. Once active, GhostDesk performs extensive surveillance including credential theft, keylogging, screenshot capture, cookie harvesting, and cryptojacking. The extension establishes command-and-control communications via WebSocket connections and can execute arbitrary code within browser tabs. Similar fake versions of other popular software like 7-Zip and Adobe Acrobat have been identified using identical infection techniques. Join the discussion | AlienVault OTX General | 08/11/2026, 21:01:31 UTC Added: 08/12/2026, 06:41:18 UTC |
ModHeader, a popular Chrome developer extension with over 800,000 users, was flagged and removed by Google for containing hidden spyware. Version 7.0.18 included a covert SDK disguised as a date library (dayjs) that harvested visited domain names, encrypted them using AES-GCM, and was configured to upload the data daily to api.stanfordstudies.com. Although the collection remained dormant due to an empty allowlist, the complete exfiltration infrastructure was present and operational. Additionally, the extension displayed active adware behavior, opening affiliate tabs on every update including on enterprise-managed machines. The malicious code shipped with official Chrome Web Store signatures, affecting both Chrome and Edge users. Forensic analysis revealed the extension locally stored 178MB of sensitive HTTP headers from all browsing activity, though no data was successfully exfiltrated from analyzed systems. Join the discussion | AlienVault OTX General | 07/14/2026, 08:04:43 UTC Added: 07/14/2026, 10:02:33 UTC |
A sophisticated phishing campaign leverages evolved ClickFix techniques to bypass modern endpoint security through victim-assisted execution. Targets receive emails with urgent OneDrive document lures containing malicious ZIP attachments. The attack uses LNK shortcuts that redirect victims to landing pages, silently injecting PowerShell commands into their clipboard. Through social engineering, victims are tricked into manually executing commands via Win+R, circumventing traditional security filters. The campaign employs DNS TXT records for payload staging, avoiding HTTP detection. The threat infrastructure hosts multiple malicious components including obfuscated scripts, fake MSI installers masquerading as legitimate software like ConnectWise, and ISO images with spyware for persistent access. This represents a shift toward long-game tactics focused on establishing full post-compromise environmental control. Join the discussion | AlienVault OTX General | 06/23/2026, 12:11:53 UTC Added: 06/23/2026, 19:09:14 UTC |
WhatsApp successfully identified and disrupted spear phishing attempts linked to NSO Group, a spyware firm blacklisted by the US government. The company is requesting the court to hold NSO in contempt for violating a permanent injunction that prohibited them from targeting WhatsApp and its users. The attacks involved social engineering attempts to trick users into clicking malicious links, as well as creating test accounts and groups on the platform. WhatsApp emphasizes that spyware represents a national security threat and is supporting the Spyware Accountability Initiative through significant contributions. The company continues to protect users through end-to-end encryption and encourages reporting suspicious activity while maintaining updated applications and devices. Join the discussion | AlienVault OTX General | 06/09/2026, 07:07:35 UTC Added: 06/09/2026, 08:45:32 UTC |
A Reddit post on the r/Malware subreddit references a new malware threat described as a VMware antidetect ransomware, spyware, and trojan. The post links to an external site (antidetect.cloud) and includes a warning not to download the software. There is minimal technical detail or discussion available, and no confirmed exploits in the wild have been reported. No affected software versions or patch information is provided. The threat is assessed as medium severity based on the nature of the malware types mentioned. Join the discussion | Reddit Malware | 06/03/2026, 13:06:32 UTC Added: 06/03/2026, 13:18:28 UTC |
A targeted campaign has been identified distributing a trojanized version of the Red Alert rocket warning Android app to Israeli users via SMS messages impersonating official Home Front Command communications. The malicious app retains full rocket alert functionality while running malicious code in the background. It bypasses Android security checks through certificate spoofing and runtime manipulation. Once installed, the malware collects sensitive data including SMS messages, contacts, location data, device accounts, and installed applications. The stolen data is transmitted to a remote command-and-control server. This campaign exploits user trust in emergency services during periods of geopolitical tension, combining social engineering with mobile espionage for maximum impact. Join the discussion | AlienVault OTX General | 03/06/2026, 15:21:48 UTC Added: 03/09/2026, 10:21:50 UTC |
The U. S. Treasury has lifted sanctions on three individuals linked to Intellexa and Predator spyware, a development that may influence the regulatory and threat landscape surrounding these spyware tools. Intellexa and Predator spyware have been associated with surveillance and cyber espionage activities, often targeting activists, journalists, and political opponents. Although no new technical vulnerabilities or exploits are reported in this announcement, the removal of sanctions could affect the availability and distribution of these spyware tools. European organizations should be aware of potential shifts in spyware deployment or vendor operations resulting from this policy change. The threat does not involve direct exploitation or vulnerabilities but relates to geopolitical and regulatory factors impacting spyware proliferation. Mitigation should focus on enhanced detection capabilities for spyware behaviors and monitoring of communications for signs of Predator or Intellexa spyware activity. Countries with significant use of surveillance technology or high-profile political targets, such as France, Germany, Italy, Spain, and the UK, may be more affected. Given the indirect nature of the threat and absence of new exploits, the suggested severity is medium. Join the discussion | Reddit InfoSec News | 12/31/2025, 09:05:40 UTC Added: 12/31/2025, 09:13:50 UTC |
Showing 1 to 10 of 53 results