§Topic · Malware
Malware
New malware families, loaders, trojans, backdoors, rootkits, and the infection chains security teams are tracking.
All dispatches
Loading
§Topic · Malware
New malware families, loaders, trojans, backdoors, rootkits, and the infection chains security teams are tracking.
All dispatchesCampaign published nearly 800 malicious npm packages delivering a cross-platform RAT and infostealer for Windows, macOS and Linux.
ChainDrop npm worm compromised 400+ packages, impacting components with combined monthly installs exceeding two billion.
QuickFox supply-chain compromise trojanized Windows installer to deliver FDMTP backdoor in deployments since at least August 2025.
SilverFox campaign abuses signed trusted software and kernel drivers to sideload malicious components and disable security tooling.
Researchers disclosed factory-installed backdoor in Zbtlink routers enabling unauthenticated root shells and persistent beaconing.
Flying Eagle mobile RAT-as-a-service enables multiple groups to build Android infostealers that drain victims' banking credentials.
Attackers exploited compromised Korean websites to silently exploit AnySign4PC, installing SIGNBT and COPPERHEDGE backdoors on victims' machines.
APT42 leverages AI-assisted reconnaissance and the resilient TAMECAT malware to target senior government and defense personnel.
HollowGraph malware uses compromised Microsoft 365 calendars as covert two-way dead-drop C2 channels leveraging Graph API.
Dolphin X infostealer uses AI profiling to rank infected users, prioritizing high-value targets for exfiltration and fraud.
Brazilian banking Trojan campaign actively spreading in Portugal, exploiting language commonality to target local businesses and consumers.
JadeProx China-linked cluster uses TriBack Loader to target government, healthcare, and education organizations in Asia and Latin America.
Microsoft reports a surge in ACR Stealer attacks exfiltrating browser credentials, tokens, and sensitive documents from customers.
NadMesh botnet scans Shodan for exposed AI services, harvesting cloud keys and Kubernetes tokens to hijack model-serving infrastructure.
UAC-0145 (Sandworm sub-cluster) uses ClickFix CAPTCHAs to trick Ukrainian targets into installing data-stealing malware.
Russian actor UAT-11795 trojanized WebEx and Zoom installers to deploy Starland RAT, stealing credentials and crypto.
Four @asyncapi npm packages were compromised to distribute a multi-stage botnet loader with credential-stealing payloads.
Get these articles delivered to your inbox.
Subscribe free