Topic: malware persistence
-
Microsoft Teams vishing leads to Chaos ransomware attacks
Cybercriminals posing as IT support staff over Microsoft Teams calls have targeted North American businesses, with 95% of attacks hitting Canadian (50%) and U.S. (45%) entities across services, manufacturing, energy, and construction sectors. The scheme uses external Teams accounts and IT-themed ...
Read More » -
Cisco Unified CM vulnerability exploited to deploy webshells
Threat actors are actively exploiting an SSRF vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager to deploy webshells and establish remote code execution capabilities. The flaw allows unauthenticated attackers to execute arbitrary commands and maintain persistent access for lat...
Read More » -
Microsoft uncovers stealthy backdoor targeting crypto wallets
Microsoft discovered "Crypto Clipper," a new self-propagating malware that spreads via USB drives and steals cryptocurrency credentials by monitoring clipboard activity for wallet addresses and seed phrases. The malware captures screenshots of stolen data and exfiltrates it through Tor using a SO...
Read More » -
Hola Browser for Windows hijacked to install cryptominer
The Windows version of Hola Browser was compromised in a supply chain attack, inserting an unauthorized executable that acts as a Monero cryptocurrency miner. The miner, identified as 'me.exe', adds a Windows Defender exclusion, copies itself as 'HolaMonitorService.exe', and activates when the co...
Read More » -
NoVoice Malware Infects 2.3M Android Downloads
The "NoVoice" malware infected over 50 apps on the Google Play Store, which were downloaded more than 2.3 million times, hiding in utilities, games, and photo apps to steal data and install other software. Google states devices with security updates since "May 2021" are protected, and its G...
Read More » -
Malware hidden in backdoored Telnyx PyPI package
A malicious version of the Telnyx SDK Python package was uploaded to PyPI on March 27, 2026, by the threat actor TeamPCP, who backdoored the legitimate code. The attack originated from stolen credentials obtained in a prior breach of the LiteLLM project, which were used to compromise the Telnyx P...
Read More » -
AI-Powered Slopoly Malware Drives Interlock Ransomware Attack
Threat actors are now using generative AI to create custom malware, as evidenced by the AI-assisted "Slopoly" backdoor deployed in an Interlock ransomware attack, which features uncharacteristically clear code. The attack chain began with a **ClickFix social engineering ruse** and used the Slop...
Read More » -
The Rise of Thinking Malware
ESET researchers discovered PromptSpy, the first known Android malware that integrates a generative AI model (Google's Gemini) into its core execution to analyze a device's screen and generate adaptive navigation instructions. The malware's primary AI-driven function is to maintain persistence by...
Read More » -
First Android Malware Using Generative AI Discovered
A novel Android malware called "PromptSpy" is the first to use generative AI, specifically Google's Gemini, to automate on-screen navigation and lock itself in the recent apps list, making it hard to remove and increasing its adaptability across devices. The malware deploys a remote-control VNC...
Read More » -
Chinese Mustang Panda Hackers Use CoolClient Backdoor to Spread Infostealers
Mustang Panda has deployed an updated CoolClient backdoor with enhanced capabilities to steal browser credentials and clipboard data, targeting government entities across Asia and beyond. The malware uses new distribution methods, compromising legitimate software for initial access, and introduce...
Read More » -
Ukraine's Military Targeted in Deceptive Charity Malware Attack
A Russian-aligned threat group (Void Blizzard/Laundry Bear) targeted Ukrainian military personnel in late 2025/early 2026 using a fake charity scheme to deploy the PluggyApe backdoor malware. The attack used personalized messages on encrypted apps to trick victims into downloading malicious files...
Read More » -
ClayRat Spyware Evolves with New Android Threats
The ClayRat Android spyware has evolved with significantly expanded surveillance and remote-control capabilities, including advanced keylogging and screen recording, posing a major threat to personal and corporate security. It abuses Android's Accessibility Services and SMS permissions to seize n...
Read More » -
APT37 Hackers Use Google Find Hub to Wipe Android Data
North Korean hackers are using Google's Find Hub service to remotely wipe Android devices and track locations, primarily targeting South Koreans through KakaoTalk messages and linked to known threat groups like APT37 and Kimsuky. The attack begins with spear-phishing messages impersonating author...
Read More » -
Google: AI-Powered Malware Is Now in Active Use
Google has identified new AI-driven malware families like PromptFlux and PromptSteal that use large language models to dynamically generate malicious scripts, enabling them to evade detection and operate more flexibly. These malware variants employ AI for various malicious purposes, including sel...
Read More » -
Malicious Solidity VSCode Extension Backdoors Developers
SleepyDuck malware disguised as a Solidity extension in the Open VSX registry has been downloaded over 53,000 times, targeting developers using AI-driven IDEs like Cursor and Windsurf. It uses an Ethereum smart contract for command-and-control, ensuring persistence by retrieving instructions from...
Read More » -
Microsoft: SesameOp Malware Exploits OpenAI API in Attacks
Microsoft discovered the SesameOp backdoor, which exploits the OpenAI Assistants API as a covert command-and-control channel to maintain persistent access in compromised systems. The malware evades detection by using legitimate cloud services for communication, blending malicious traffic with nor...
Read More » -
Chrome Zero-Day Used to Spread LeetAgent Spyware
A zero-day vulnerability in Google Chrome (CVE-2025-2783) was exploited via phishing in Operation ForumTroll, allowing attackers to escape Chrome's sandbox and deploy spyware developed by Memento Labs. The attack delivered LeetAgent spyware, which executed commands, stole files, and communicated ...
Read More » -
Beware: Spyware Poses as Signal and ToTok Messaging Apps
Cybersecurity experts discovered two spyware operations, ProSpy and ToSpy, which impersonate updates for Signal and ToTok to target Android users, particularly in the UAE, through fake websites. These malicious apps steal sensitive data like contacts, messages, and files by tricking users into gr...
Read More » -
Stop Malware Persistence: A Wazuh Defense Guide
Malware persistence allows attackers to maintain long-term access to compromised systems by using techniques like scheduled tasks, boot scripts, and system process modifications. Successful persistence leads to severe consequences, including extended undetected operations, data exfiltration, and ...
Read More » -
Beware: Noodlophile Infostealer Masks as Fake Legal Notices
A global cyber campaign uses fake legal notices via spear-phishing emails to distribute the Noodlophile infostealer, impersonating law firms to create urgency and steal sensitive data. The malware employs sophisticated techniques like DLL side-loading and disguised malicious files to bypass secur...
Read More »