Topic: information stealer

  • PureLogs infostealer targets global credentials

    PureLogs infostealer targets global credentials

    A sophisticated phishing campaign uses cat photos to hide the PureLogs infostealer, with attackers employing steganography to conceal encrypted payloads within PNG images. The attack chain begins with an invoice-themed phishing email containing a TXZ archive, which uses JavaScript and PowerShell ...

    Read More »
  • Malware hidden in backdoored Telnyx PyPI package

    Malware hidden in backdoored Telnyx PyPI package

    A malicious version of the Telnyx SDK Python package was uploaded to PyPI on March 27, 2026, by the threat actor TeamPCP, who backdoored the legitimate code. The attack originated from stolen credentials obtained in a prior breach of the LiteLLM project, which were used to compromise the Telnyx P...

    Read More »
  • Criminals Sell RAT Malware as Legitimate RMM Tool

    Criminals Sell RAT Malware as Legitimate RMM Tool

    A cybercrime operation sells a malicious remote access trojan disguised as a legitimate remote management tool, using a fraudulent Extended Validation certificate to bypass security detection. The service, marketed via an AI-generated website, is sold for a monthly fee and distributed through phi...

    Read More »
  • DanaBot Malware Returns to Target Windows After 6-Month Hiatus

    DanaBot Malware Returns to Target Windows After 6-Month Hiatus

    DanaBot malware has re-emerged with a new version (v669) after a six-month hiatus, now utilizing Tor-based infrastructure and cryptocurrency addresses for stolen funds. Originally a banking trojan distributed as malware-as-a-service, it evolved into a modular threat targeting credentials and cryp...

    Read More »
  • Inside the PureRAT Attack: From Info Stealer to Full Control

    Inside the PureRAT Attack: From Info Stealer to Full Control

    A sophisticated cyberattack begins with phishing emails using sideloading techniques to deploy malware, escalating from credential theft to deploying the full-featured PureRAT remote access trojan for complete system control. The campaign employs multiple layers of obfuscation, including custom c...

    Read More »
  • Stealth Malware Campaign Infects Thousands via DNS TXT Abuse

    Stealth Malware Campaign Infects Thousands via DNS TXT Abuse

    The Detour Dog malware campaign has infected over 30,000 websites, using DNS TXT records for server-side attacks that remain hidden from most users, selectively targeting specific visitors for redirection or malware downloads. This attack operates by having compromised servers send DNS queries wi...

    Read More »