Threats Tagged 'trojan'
View all threats tagged with 'trojan'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'trojan'
Click on any threat for detailed analysis and mitigation recommendations
A security researcher gained unauthorized access to a server involved in distributing a modular malware campaign targeting Brazilian users. The malware includes a Trojan with keylogging, desktop capture, shellcode injection, a cryptominer, and a Tor-based command and control infrastructure. The infection chain uses multiple payload layers designed to maintain persistence even if one stage is disrupted. The researcher published a detailed report describing the infection chain and malware components. Join the discussion | Reddit Malware | 08/19/2026, 19:44:43 UTC Added: 08/19/2026, 20:37:03 UTC |
This content is a walkthrough and educational lab setup for hunting the Zeus Banking Trojan using tools like Suricata, Splunk, Volatility, and YARA. It details a hands-on malware analysis and detection engineering pipeline involving a Windows victim VM with Sysmon and an Ubuntu VM running Splunk Enterprise and Suricata IDS. The write-up is intended for defensive security study and SOC portfolio development. Join the discussion | Reddit BlueTeam | 07/18/2026, 12:29:31 UTC Added: 07/18/2026, 15:45:04 UTC |
Rokarolla is a new Android banking Trojan targeting 217 banking and cryptocurrency apps. It spreads via malicious websites masquerading as popular apps like TikTok and Chrome, initially installing a dropper disguised as Google Play Protect. Once installed and granted Accessibility Services, it can simulate user actions, inject overlays, intercept credentials, block calls, read and send SMS, disable Google Play Protect, and silently capture screen content. The malware dynamically downloads fake login pages to steal credentials and can operate even when the device is locked. It also replaces copied cryptocurrency wallet addresses with attacker-controlled ones and suppresses audio and notifications to avoid user detection. Rokarolla uses resilient command-and-control infrastructure and employs stealth techniques to maintain persistence and evade detection. No software flaw is exploited, so no patch is available; mitigation relies on user caution and security products detecting the malware. Join the discussion | Reddit Cybersecurity | 06/17/2026, 12:25:50 UTC Added: 06/17/2026, 12:45:06 UTC |
A user reported finding a trojan named "Servicehost.exe" on their PC, detected by Malwarebytes and identified via VirusTotal. The user is concerned that this malware may have recorded or leaked private calls. The report is based on a Reddit post linking to VirusTotal scan results, but no detailed technical or vendor advisory information is available. There is no confirmation of active exploitation or specific capabilities beyond the user's concern and VirusTotal detections. Join the discussion | Reddit Cybersecurity | 06/04/2026, 07:56:45 UTC Added: 06/04/2026, 08:03:24 UTC |
A Reddit post on the r/Malware subreddit references a new malware threat described as a VMware antidetect ransomware, spyware, and trojan. The post links to an external site (antidetect.cloud) and includes a warning not to download the software. There is minimal technical detail or discussion available, and no confirmed exploits in the wild have been reported. No affected software versions or patch information is provided. The threat is assessed as medium severity based on the nature of the malware types mentioned. Join the discussion | Reddit Malware | 06/03/2026, 13:06:32 UTC Added: 06/03/2026, 13:18:28 UTC |
This threat is a scam and likely malware or trojan disguised as a 'Path Of Exile 2 builder' distributed via a Reddit post. The malware reportedly hijacks user sessions on Discord, YouTube, and Facebook, attempting to send direct messages on Discord using IP proxies. The malicious payload is contained within a zip file with an executable, which if run, infects the system. There is no official patch or vendor advisory available. The threat is currently not known to be exploited in the wild beyond the Reddit report. Join the discussion | Reddit Malware | 06/02/2026, 12:53:16 UTC Added: 06/02/2026, 13:03:26 UTC |
A malicious SMS spoofing campaign is spreading a fake version of Israel's 'Red Alert' emergency app amid ongoing conflict. The trojanized Android app, disguised as a trusted warning platform, can steal SMS, contacts, and location data while appearing legitimate. The campaign exploits public fear during crises to deploy mobile spyware. The malware uses sophisticated techniques to bypass security checks, including package manager hooking and dynamic payload loading. It mirrors the official app's interface but requests high-risk permissions. The malware continuously tracks GPS coordinates and exfiltrates data to attacker-controlled infrastructure, posing severe strategic and physical security risks. This campaign erodes trust in emergency response systems and could potentially be used for targeted attacks or to optimize missile targeting. Join the discussion | AlienVault OTX General | 03/03/2026, 15:42:04 UTC Added: 03/03/2026, 17:02:26 UTC |
A new Android trojan, named NFCShare, has been discovered targeting Deutsche Bank customers through a phishing campaign. The malware, disguised as a banking app update, prompts users to perform a fake card verification process. It exploits NFC technology to steal card data and PINs, which are then exfiltrated to a remote WebSocket endpoint. The trojan's distribution, user flow, and technical analysis are detailed, including its NFC reading capabilities and string obfuscation techniques. The malware shows links to Chinese-linked tooling and similarities to other NFC-based threats. IOCs include hashes, package details, and network indicators. Join the discussion | AlienVault OTX General | 01/30/2026, 08:18:00 UTC Added: 01/30/2026, 08:43:08 UTC |
This detailed analysis uncovers a trojanized WinRAR installer used in a malware campaign distributing the Winzipper backdoor. The multi-layered unpacking and dynamic analysis reveal how the malware hides behind a legitimate installer to evade detection and establish persistence, with clear IOCs and mitigation advice provided. Join the discussion | Community Curated | 01/11/2026, 16:05:18 UTC Added: 01/11/2026, 16:05:18 UTC |
Hackers have been observed abusing the popular monitoring tool Nezha by repurposing it as a stealth trojan to evade detection. This malware misuse involves leveraging legitimate software functionalities to conduct covert operations on compromised systems. Although no known exploits are currently active in the wild, the threat poses a medium severity risk due to its stealth capabilities and potential for unauthorized access. European organizations using Nezha or similar monitoring tools should be vigilant for unusual activity that may indicate misuse. The threat primarily impacts confidentiality and integrity by enabling attackers to maintain persistence and exfiltrate data covertly. Mitigation requires enhanced monitoring of Nezha deployments, strict access controls, and anomaly detection tailored to identify misuse of legitimate tools. Countries with significant technology sectors and high adoption of open-source monitoring solutions, such as Germany, France, and the UK, are more likely to be affected. Given the stealth nature and potential impact without requiring user interaction, the suggested severity is medium. Defenders should prioritize detection of abnormal Nezha behavior and restrict its deployment to trusted environments only. Join the discussion | Reddit InfoSec News | 12/22/2025, 12:58:01 UTC Added: 12/22/2025, 13:03:25 UTC |
Showing 1 to 10 of 41 results