Topic: command and control

  • Hackers Hijack CPUID Downloads to Distribute STX RAT

    Hackers Hijack CPUID Downloads to Distribute STX RAT

    The official website of CPUID, a provider of popular system utilities like HWMonitor and CPU-Z, was compromised between April 9-10, 2026, redirecting users to malicious downloads in a watering hole attack. Attackers distributed trojanized software using a DLL sideloading technique, which deployed...

    Read More »
  • Android Malware on Google Play Infected 2.3M Devices

    Android Malware on Google Play Infected 2.3M Devices

    A sophisticated Android malware campaign called "NoVoice" infected millions of devices via over 50 apps on the Google Play Store, hiding its malicious payload within seemingly legitimate applications. The malware exploited old Android vulnerabilities to gain root access, established deep persis...

    Read More »
  • eScan AV Users Hit by Malicious Update Attack

    eScan AV Users Hit by Malicious Update Attack

    Unknown attackers compromised eScan's update server, weaponizing it to deploy a malicious downloader that disabled the antivirus and blocked future security updates. The breach, detected in January 2026, forced the vendor to take its global update system offline and required many users to manuall...

    Read More »
  • Rust crate arrayref poisoned by hackers to deliver infostealer malware

    Rust crate arrayref poisoned by hackers to deliver infostealer malware

    A supply-chain attack compromised the maintainer account of the popular Rust crate arrayref, injecting malware via a typosquatted dependency (proc-macro1) across three crates (arrayref, append-only-vec, internment) within a 23-minute window, affecting over 245 million lifetime downloads. The malw...

    Read More »
  • Microsoft Blames North Korea for Mastra AI Supply Chain Attack

    Microsoft Blames North Korea for Mastra AI Supply Chain Attack

    North Korean state-sponsored group Sapphire Sleet (also known as APT38 and BlueNoroff) conducted a sophisticated supply chain attack on the Mastra npm framework by compromising a maintainer account and injecting malicious code. The attack affected over 140 packages and delivered a cross-platform ...

    Read More »
  • Credential-stealing malware found in AsyncAPI npm packages

    Credential-stealing malware found in AsyncAPI npm packages

    Malicious AsyncAPI packages were uploaded to npm via a compromised GitHub Actions workflow, deploying a remote access trojan that steals credentials; the packages had over 2.25 million weekly downloads. The multi-stage malware, retrieved from IPFS and using a 92,000-line modular framework, commun...

    Read More »
  • Stealthy Fileless Malware Spreads RAT via Legitimate Tools

    Stealthy Fileless Malware Spreads RAT via Legitimate Tools

    A fileless malware campaign uses trusted tools like ScreenConnect and PowerShell to deploy a remote access Trojan, leaving minimal forensic traces and evading detection. The attack loads payloads directly into memory via reflection, employs a .NET launcher to establish persistence and disable sec...

    Read More »
  • Active Attacks Target Unpatched SolarWinds WHD Systems

    Active Attacks Target Unpatched SolarWinds WHD Systems

    Attackers are exploiting unpatched SolarWinds Web Help Desk systems to gain network access, using "living-off-the-land" techniques like legitimate remote access tools to avoid detection. Once inside, they deploy a weaponized version of the Velociraptor forensics tool for command-and-control, enab...

    Read More »
  • Fake Claude AI site infects Windows with new Beagle malware

    Fake Claude AI site infects Windows with new Beagle malware

    A fraudulent website at "claude-pro[.]com" impersonates the official Claude AI platform to distribute a malicious installer disguised as "Claude-Pro Relay," which installs a new Windows backdoor named Beagle. The attack chain uses a trojanized Claude installer to deploy DonutLoader, which then lo...

    Read More »
  • RedHook Android malware exploits Wireless ADB for shell access

    RedHook Android malware exploits Wireless ADB for shell access

    RedHook malware exploits Android Wireless Debugging by tricking users into granting Accessibility permissions, then autonomously enabling Developer Options and Wireless ADB to gain shell-level privileges without a physical computer connection. After securing shell access via the loopback interfac...

    Read More »
  • HR and Recruiters Hit by Year-Long Malware Attack

    HR and Recruiters Hit by Year-Long Malware Attack

    A long-running malware campaign is specifically targeting HR and recruitment professionals to steal sensitive organizational data using sophisticated, stealthy techniques. The attack begins with a deceptive resume-themed file that triggers a multi-stage infection, employing tactics like DLL sidel...

    Read More »
  • APT37 Breaches Air-Gapped Networks with New Malware

    APT37 Breaches Air-Gapped Networks with New Malware

    North Korean state-sponsored hackers (APT37) are using a novel toolkit called Ruby Jumper to breach sensitive air-gapped networks by exploiting removable USB drives as a covert bridge. The multi-stage infection begins with a malicious shortcut file and deploys a chain of tools, including the REST...

    Read More »
  • EDR Exploited for Stealthy Ransomware Attacks

    EDR Exploited for Stealthy Ransomware Attacks

    Attackers are exploiting trusted security tools like EDR software and Windows utilities to deploy malware with stealth and persistence, shifting from mass phishing to more sophisticated methods. A specific attack involved social engineering to execute malicious commands, sideloading a rogue DLL v...

    Read More »
  • Cisco FMC Flaw Exploited Before Patch (CVE-2026-20131)

    Cisco FMC Flaw Exploited Before Patch (CVE-2026-20131)

    The Interlock ransomware gang exploited a critical zero-day vulnerability (CVE-2026-20131) in Cisco's Secure Firewall Management Center for over a month before a patch was released, using it for arbitrary code execution and privilege escalation. Amazon's threat intelligence, using a honeypot, unc...

    Read More »
  • Sharpen Trojan Detection with Behavioral Signals

    Sharpen Trojan Detection with Behavioral Signals

    A recent study on malware detection for Windows-based IoT gateways demonstrates that the most valuable insight is not the TrDNN deep learning model, but its feature selection methodology, which reduces hundreds of sandbox attributes to a focused set of 33. The final 33 features serve as a Trojan ...

    Read More »
  • LeakNet Ransomware's Stealthy New Attack Methods Revealed

    LeakNet Ransomware's Stealthy New Attack Methods Revealed

    LeakNet ransomware uses a stealthy "bring your own runtime" attack, employing the legitimate Deno software to run malicious code directly in memory, which evades traditional detection by leaving minimal forensic evidence. The group initiates attacks with a social engineering technique called Clic...

    Read More »
  • Russian Hackers Hide Malware in CAPTCHA Tests

    Russian Hackers Hide Malware in CAPTCHA Tests

    Star Blizzard, a Russian state-sponsored hacking group, has escalated cyber-espionage by hiding malware like NoRobot, YesRobot, and MaybeRobot within fake CAPTCHA pages, using social engineering tactics to trick targets into executing harmful code. The group rapidly abandoned its previous LostKey...

    Read More »
  • Fake OpenAI Privacy Filter Tops Hugging Face, 244K Downloads

    Fake OpenAI Privacy Filter Tops Hugging Face, 244K Downloads

    A malicious repository impersonating OpenAI's Privacy Filter model reached #1 on Hugging Face's trending charts with 244,000 downloads in 18 hours, delivering a Rust-based information stealer to Windows users before being disabled. The attack used a multi-stage infection chain: a cloned repositor...

    Read More »
  • Dutch military invests millions in Intelic’s drone software

    Dutch military invests millions in Intelic’s drone software

    The Dutch Ministry of Defence is investing tens of millions of euros in startup Intelic for a three-year agreement. Intelic's technology allows drones from different manufacturers to be controlled through a single unified command platform. The investment reflects a key lesson from the war in Ukra...

    Read More »
  • AI-Powered Malware Targets Iranian Protesters

    AI-Powered Malware Targets Iranian Protesters

    A sophisticated cyber campaign named **RedKitten** is targeting individuals and organizations in Iran, particularly human rights and political dissent groups, using AI-generated content and emotionally manipulative lures to deploy spyware. The operation employs a malicious implant called **Sloppy...

    Read More »