Malware Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
The ShinyHunters extortion group hacked and defaced the Clop (Cl0p) ransomware operation's data leak site by exploiting an unauthenticated file upload vulnerability in Grav CMS. They replaced the site content with their own messages and ASCII art, claiming to have stolen server data including source code, Grav CMS plugins, system logs, and private keys for Clop's Tor onion service. ShinyHunters threatened to extort Clop, demanding payment within 72 hours. This attack appears to be part of an ongoing feud between the two cybercrime groups, with ShinyHunters retaliating against threats made by Clop representatives. The incident raises questions about a potential shift in ransomware group dynamics toward direct attacks on rival groups. No independent verification of the full extent of data theft has been confirmed. Join the discussion | Reddit Cybersecurity | 09/21/2026, 16:55:52 UTC Added: 09/21/2026, 17:01:29 UTC |
A widespread campaign impersonates LastPass and at least 40 other companies to distribute a kernel-level malware called Rapuncel via fake installers hosted on GitHub. The malware disables 145 security products by loading a malicious kernel driver and steals sensitive information including passwords, cryptocurrency wallets, and tokens from multiple applications. The campaign uses SEO manipulation and dynamic redirect chains to lure victims. Rapuncel installs as a persistent Windows service, continuously killing security tools and stealing data until the kernel driver is physically removed. Join the discussion | SecurityWeek | 09/21/2026, 15:46:58 UTC Added: 09/21/2026, 16:01:39 UTC |
RatHat is an Android trojan that uses generative AI to automate real-time device navigation and control, enhancing its adaptability and evasion capabilities. It steals credentials, mimics banking apps, intercepts SMS, and gains administrator-level permissions. The malware persists by reinstalling itself if removed and uses advanced keylogging techniques, including hardware-level monitoring of user input. It communicates with a command-and-control server via a secure reverse tunnel and abuses Android debugging tools for system-level access. RatHat is distributed through smishing and malvertising and appears linked to a Chinese threat actor. Join the discussion | SecurityWeek | 09/21/2026, 12:51:41 UTC Added: 09/21/2026, 13:01:39 UTC |
In April 2026, a manufacturing organization in the Middle East suffered a ransomware attack where threat actors with domain admin privileges weaponized Active Directory Group Policy Objects to achieve domain-wide impact without deploying ransomware binaries on Windows endpoints. The attackers created malicious GPOs linked at the domain root, delivering ransom notes, hijacking wallpapers and lock screens, enforcing logon banners, and disabling local administrator accounts across all domain-joined workstations. No file encryption occurred on Windows systems; instead, the operation focused on encryptionless extortion through operational disruption and data exfiltration. Initial access was gained via compromised VPN credentials. The attack remained dormant for one day between GPO creation and detonation, evading file-based detection entirely by abusing trusted AD infrastructure. Join the discussion | AlienVault OTX General | 09/21/2026, 11:54:10 UTC Added: 09/21/2026, 15:31:54 UTC |
ThreatFox IOCs for 2026-09-21 Join the discussion | ThreatFox MISP Feed | 09/21/2026, 00:00:00 UTC Added: 09/22/2026, 00:31:25 UTC |
A malware campaign involving the npm package 'indexed-btree' demonstrates how attackers evade traditional supply chain defenses by embedding malicious code in the package's runtime behavior instead of installation scripts. This technique allows the malware to bypass install-time security checks and execute malicious actions during normal package usage. Join the discussion | Bleeping Computer | 09/20/2026, 14:11:21 UTC Added: 09/20/2026, 14:16:38 UTC |
ThreatFox IOCs for 2026-09-20 Join the discussion | ThreatFox MISP Feed | 09/20/2026, 00:00:00 UTC Added: 09/21/2026, 00:31:25 UTC |
BragJack is a proof-of-concept attack that hijacks AI assistants in multiple browsers including Chrome, Edge, Opera Neon, and AI platforms like Perplexity Comet and Claude via a single malicious browser extension. It uses a technique called Prompt Forcing to manipulate AI agents. The attack has earned significant bug bounty rewards and resulted in two CVEs. No specific affected software versions or patch information is provided. HighMalware Join the discussion | Bleeping Computer | 09/19/2026, 14:56:31 UTC Added: 09/19/2026, 15:01:40 UTC |
In 2026, the DPRK-sponsored Lazarus subgroup TraderTraitor continued campaigns targeting cryptocurrency entities, including a high-profile attack on LayerZero resulting in $292 million theft from KelpDAO. Following this disclosure, an additional victim was identified: a smaller IT services provider in India with no cryptocurrency connections. The compromise involved a DevOps engineer targeted through fake job interview lures containing weaponized Terraform coding projects. Malicious GitHub repositories used typosquatted provider domains to deliver macOS backdoors FLATROOF and ROOFDECK when victims executed terraform init. The backdoors enabled reconnaissance, credential theft, and cloud environment escalation. One day after LayerZero's public disclosure, attackers deployed an updated stripped version of ROOFDECK and removed earlier implants. Activity continued until June 2026, suggesting the threat actor ultimately abandoned the intrusion after determining insufficient value from the smaller target. Join the discussion | AlienVault OTX General | 09/19/2026, 08:44:15 UTC Added: 09/21/2026, 08:46:37 UTC |
ThreatFox IOCs for 2026-09-19 Join the discussion | ThreatFox MISP Feed | 09/19/2026, 00:00:00 UTC Added: 09/20/2026, 00:31:25 UTC |
Showing 1 to 10 of 3748 results