Topic: malware analysis

  • REMnux v8: AI-Powered Malware Analysis for Linux

    REMnux v8: AI-Powered Malware Analysis for Linux

    REMnux v8 is a major rebuild of the malware analysis Linux distribution, migrating to Ubuntu 24.04 and introducing a new, flexible Cast-based installer for easier deployment. The release's most significant feature is the REMnux MCP server, which connects AI agents directly to over 200 analysis to...

    Read More »
  • ClickFix malware now targets macOS to steal crypto

    ClickFix malware now targets macOS to steal crypto

    A new ClickFix malware campaign targets macOS users with a Go-based payload that steals cryptocurrency, passwords, and sensitive system data via social engineering tricks that prompt victims to run malicious commands in Terminal. The attack uses a Bash script to profile the system, download a tai...

    Read More »
  • Sharpen Trojan Detection with Behavioral Signals

    Sharpen Trojan Detection with Behavioral Signals

    A recent study on malware detection for Windows-based IoT gateways demonstrates that the most valuable insight is not the TrDNN deep learning model, but its feature selection methodology, which reduces hundreds of sandbox attributes to a focused set of 33. The final 33 features serve as a Trojan ...

    Read More »
  • Cisco FMC Flaw Exploited Before Patch (CVE-2026-20131)

    Cisco FMC Flaw Exploited Before Patch (CVE-2026-20131)

    The Interlock ransomware gang exploited a critical zero-day vulnerability (CVE-2026-20131) in Cisco's Secure Firewall Management Center for over a month before a patch was released, using it for arbitrary code execution and privilege escalation. Amazon's threat intelligence, using a honeypot, unc...

    Read More »
  • Malware Contains Bugs That Defenders Can Exploit

    Malware Contains Bugs That Defenders Can Exploit

    Static analysis tools applied to 658 leaked malware samples revealed attackers' code is consistently riddled with severe flaws like buffer overflows, memory leaks, and use-after-free vulnerabilities. These embedded weaknesses allow cybersecurity defenders to actively exploit them, for example by ...

    Read More »
  • Beware: Fake 7-Zip Site Pushes Malware-Laden Installer

    Beware: Fake 7-Zip Site Pushes Malware-Laden Installer

    A fraudulent website impersonating the official 7-Zip software distributes a trojanized installer that secretly enrolls the victim's computer into a residential proxy network for malicious traffic routing. The malware, which mimics the legitimate site's appearance, deploys hidden components, modi...

    Read More »
  • 500 npm Packages Infected by Shai-Hulud Malware Leaking Secrets

    500 npm Packages Infected by Shai-Hulud Malware Leaking Secrets

    Over 500 npm packages, including popular tools like Zapier and Postman, have been compromised by the Shai-Hulud malware, which steals developer secrets and uploads them to rapidly multiplying GitHub repositories. The attack uses trojanized versions of legitimate packages to inject malicious scrip...

    Read More »
  • Android Tablet Backdoor & Dell Zero-Day: Critical Week in Review

    Android Tablet Backdoor & Dell Zero-Day: Critical Week in Review

    A critical firmware backdoor in Android tablets and a long-running espionage campaign exploiting a Dell zero-day highlight persistent supply chain security challenges and the stealthy nature of modern cyber adversaries. The role of the CISO is evolving to manage AI-augmented teams, while threats ...

    Read More »
  • $900K XSS Bounty, HybridPetya Attack, & Burger King Censorship

    $900K XSS Bounty, HybridPetya Attack, & Burger King Censorship

    Restaurant Brands International issued a DMCA takedown against researchers who exposed data vulnerabilities, despite the issues being patched after private reporting. Google distributed $1.6 million in rewards at a cloud-focused bug bounty event, contributing to a total of $2.5 million in cloud-r...

    Read More »
  • CISA releases Thorium: Open-source malware & forensic analysis tool

    CISA releases Thorium: Open-source malware & forensic analysis tool

    CISA launched Thorium, an open-source platform for malware analysis and forensic investigations, developed with Sandia National Labs to automate cyberattack investigations efficiently. Thorium processes 1,700+ jobs per second and 10M+ files hourly, integrating commercial and custom tools for thre...

    Read More »
  • Microsoft's RIFT: Open-Source Tool for Rust Malware Analysis

    Microsoft's RIFT: Open-Source Tool for Rust Malware Analysis

    Microsoft released RIFT, an open-source tool for analyzing Rust-based malware, addressing challenges posed by Rust's compilation methods and large binary sizes. RIFT uses three integrated components (static analyzer, signature generator, and IDA plugin) with FLIRT and binary diffing to efficientl...

    Read More »
  • Stealthy Mistic Backdoor Tied to Ransomware Broker KongTuke

    Stealthy Mistic Backdoor Tied to Ransomware Broker KongTuke

    A new backdoor malware called Mistic, linked to ransomware broker KongTuke, is being used in financially motivated attacks targeting insurance, education, IT, and professional services sectors. Mistic acts as a stealthy remote access tool using advanced evasion techniques like encrypted communica...

    Read More »
  • Putting NICE Guidelines into Practice: Training Insights

    Putting NICE Guidelines into Practice: Training Insights

    SMBs can effectively train employees against cyber threats by focusing on a streamlined, scenario-based program derived from the NICE Framework, targeting the most common attacks like phishing, malware, and web-based threats. The training integrates technical skills with legal knowledge through r...

    Read More »
  • COLDCARD audit phishing attack installs remote access tool

    COLDCARD audit phishing attack installs remote access tool

    Phishing emails impersonating COLDCARD exploit fears of a reported $88.6 million Bitcoin theft and hardware vulnerability, directing victims to a fake compliance site (coldcardcompliance.com) that lures them into downloading a malicious file. The downloaded batch file installs ConnectWise ScreenC...

    Read More »
  • Expert Help Needed for SHA1 Analysis (650915975bfc36ee)

    Expert Help Needed for SHA1 Analysis (650915975bfc36ee)

    A network administrator is seeking help to identify an unknown ransomware variant after Trend Micro Apex One flagged a breach, with ID Ransomware unable to identify the threat from the ransom note. The ransomware selectively encrypts files in outer folders (like user documents) while leaving deep...

    Read More »
  • Microsoft Teams Phishing Attack Spreads A0Backdoor Malware

    Microsoft Teams Phishing Attack Spreads A0Backdoor Malware

    A sophisticated phishing campaign targets financial and healthcare employees by using Microsoft Teams to impersonate IT support, tricking users into granting remote access via Quick Assist to install malware. The attack deploys a novel backdoor called A0Backdoor through signed MSI installers that...

    Read More »
  • Russia's Sandworm Blamed for Polish Power Grid Wiper Attack

    Russia's Sandworm Blamed for Polish Power Grid Wiper Attack

    A Russian state-sponsored hacking group, Sandworm, is attributed with a cyberattack on Poland's energy grid in late 2025 using destructive DynoWiper malware, though it did not cause a power outage. The attack's timing is seen as symbolic, coinciding with the 10-year anniversary of Sandworm's 2015...

    Read More »
  • Urgent Samsung Patch Stops Spyware Exploit

    Urgent Samsung Patch Stops Spyware Exploit

    Samsung has released a critical security update for a vulnerability (CVE-2025-21042) in its image processing library, which was actively exploited to install the LANDFALL spyware on mobile devices. The spyware uses a zero-click infection method via manipulated image files, allowing it to infect d...

    Read More »
  • Adform ad script hacked to steal cryptocurrency

    Adform ad script hacked to steal cryptocurrency

    Adform, a major European adtech provider, suffered a supply-chain attack that injected crypto-stealing code into its tracking script, which swapped copied or displayed cryptocurrency wallet addresses on websites using its platform to redirect funds to attackers. Security researcher Kevin Beaumont...

    Read More »
  • AI-Powered Slopoly Malware Drives Interlock Ransomware Attack

    AI-Powered Slopoly Malware Drives Interlock Ransomware Attack

    Threat actors are now using generative AI to create custom malware, as evidenced by the AI-assisted "Slopoly" backdoor deployed in an Interlock ransomware attack, which features uncharacteristically clear code. The attack chain began with a **ClickFix social engineering ruse** and used the Slop...

    Read More »