§Topic · Malware
Malware
New malware families, loaders, trojans, backdoors, rootkits, and the infection chains security teams are tracking.
All dispatches
Loading
§Topic · Malware
New malware families, loaders, trojans, backdoors, rootkits, and the infection chains security teams are tracking.
All dispatchesMultiple Chrome and Edge extensions delivered malware modules that steal crypto wallets, browser data, and inject ClickFix social engineering.
ToxNetV2 Linux botnet uses NVIDIA AI to propose shell and SSH attack commands, accelerating operator decision-making.
SANS roundup: UK power plant outage, car proxy-malware botnet, and N-able Passportal/Keycloak vulnerability fixes.
Researchers link novel car head unit malware to BadBox botnet, expanding vehicle infection surface for mass abuse.
Trojanized npm packages install RedC2 4.0 Linux backdoor with AI-assisted command-and-control capabilities.
Supply-chain compromise of Android car head unit updater spreads malware to build ad-fraud and proxy botnet on vehicles.
ToxicPanda Android malware abuses VPN permissions to block Google Play and expand remote command control across apps.
CISA ordered immediate patching of TrueConf Server vulnerabilities that are being actively abused to deploy malware.
Malicious Rust crate releases introduced build-time payloads, affecting widely used packages and prompting removals.
Evooo1Bot Mirai-based botnet infects routers and IoT edge devices, converting them into persistent SOCKS5 proxy/traffic relay nodes.
New macOS infostealer steals keychain and browser data via ClickFix and supports remote interactive browser control.
Lazarus exploits AFD.sys zero-day (CVE-2026-68820) to deploy FudModule rootkit for stealthy kernel persistence.
A Mirai variant adds encrypted C2 communications and a credential 'sniffer' to improve stealth and persistence for botnets.
Critical VMware vCenter flaw (CVE-2026-59310) is being actively exploited to deploy reverse SSH persistence backdoors.
Malware running in a signed Windows session can quietly use Windows Hello for Business keys to authenticate to Entra ID and persist.
Threat actors exploited unpatched TrueConf servers to replace client installers with trojanized backdoors for remote access.
Get these articles delivered to your inbox.
Subscribe free