Malware

Stories 119
Sources 252
Updated 2026.07.25
Steam forum posts use ClickFix tricks to infect gamers with XMRig cryptomining malware
Attackers are posting fake troubleshooting replies on Steam discussion forums that trick gamers into infecting their own Windows PCs with cryptocurrency-mining malware. The campaign uses ClickFix social engineering, telling users to open PowerShell as an administrator and run a command that installs XMRig from msfconfig[.]icu, adds Microsoft Defender exclusions, creates a scheduled task named "XMRig-[computer name]," and persists as C:\Windows\Background\system.exe. — Steam users and home PC owners can be compromised just by following what looks like a helpful forum fix, leading to slowed systems, higher power use, and weakened defenses. People should avoid running PowerShell commands from forum posts, and anyone who did should check for XMRig processes, scheduled tasks, Defender exclusions, and the C:\Windows\Background\system.exe file.
Sources: Steam forum ClickFix attacks infect gamers with XMRig cryptominers
SourTrade malvertising campaign uses fake Solana, Luno, and TradingView sites to assemble malware inside victims’ browsers
A large online ad scam is sending retail traders and cryptocurrency users to fake Solana, Luno, and TradingView pages that build malware directly inside the victim’s browser before download. Confiant says the SourTrade campaign has run since late 2024 across 25 languages in 12 countries, mainly in Asia Pacific and Latin America, using JavaScript, SharedWorker, and Service Worker features to assemble a unique malicious executable in memory from a clean Bun binary and remote components so no finished file crosses the network. — People looking for trading or crypto software through ads or sponsored search results could end up downloading malware that steals passwords, wallet data, and other sensitive information. Users should avoid ad-linked downloads and get software only from official vendor sites, while defenders should watch for this same-origin browser download technique and fake finance-brand pages.
Sources: Malicious sites use JavaScript to build malware in browser memory, Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Researchers say Hermes AI agent was used during a suspected breach of Thailand's Ministry of Finance
Researchers say attackers targeted and likely breached multiple systems at Thailand's Ministry of Finance, then used the open-source Hermes AI agent in unattended mode to automate parts of the intrusion. Hunt.io found exposed attacker directories containing 585 files, including stolen credentials, web shells, custom scripts, and logs showing Hermes was used for privilege-escalation checks, service enumeration, filesystem traversal, and Linux post-exploitation; the ministry had not confirmed the breach at publication. — This matters because it is a real-world example of AI being used to speed up hands-on intrusion work inside a government network, which could lower the skill and time needed for follow-on attacks. Government defenders and anyone running exposed admin tools should review logs for web-shell activity, credential misuse, and suspicious enumeration, and treat exposed attacker artifacts as indicators of compromise.
Sources: Hermes AI agent used to automate attack on Thai Finance Ministry
Dolphin X Windows stealer and remote-access trojan targets 300+ apps and uses an AI profiler to rank victims
Researchers say a new Windows malware service called Dolphin X is being sold to criminals to steal passwords, enterprise secrets, and cryptocurrency from infected users. Varonis says the stealer and remote-access trojan (RAT) claims support for more than 300 applications and theft of browser credentials, SSH keys, cloud tokens, .env files, DevOps secrets, and crypto wallets, plus an 'AI Profiler' that scores victims by app use, browsing history, and installed software so operators can prioritize the most profitable targets. The seller also advertises loader, hidden virtual desktop control, and distributed denial-of-service capabilities. — This could increase the damage from commodity malware by helping criminals quickly identify which infected people or employees are worth deeper follow-on attacks. Organizations should treat stealer infections as high risk, watch for credential and token theft on Windows endpoints, and rotate exposed passwords, keys, and cloud secrets if compromise is suspected.
Sources: Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits, New Dolphin X malware uses AI to rank high-value targets, In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Fake Claude desktop app in Bing ads delivers SectopRAT malware through Anthropic-hosted page
Attackers used sponsored Bing search results and a fake Claude desktop app to infect organizations with remote-access and info-stealing malware. Huntress says the campaign, dubbed FakeAgent, compromised at least 29 organizations on July 21-22, 2026. The lure used a malicious Claude Artifact hosted on a legitimate Claude.ai domain, then delivered a fake ClaudeDesktop.exe that sideloaded a malicious libcef.dll to install SectopRAT, also known as ArechClient2, and set persistence via a scheduled task created by DockerDesktop.exe. — People searching for trusted software can be infected even when the lure appears on a real vendor domain. Organizations should block or scrutinize sponsored search results, hunt for SectopRAT indicators, and remind users to verify downloads through known-good vendor paths.
Sources: Fake Claude app promoted by Bing ads pushes SectopRAT malware
Ukraine says UAC-0099 is abusing Notepad++ plugin loading to install LunchPoke and BurnyBear malware
Ukraine’s cyber defenders say a threat group linked to earlier Sandworm initial-access activity is disguising malware as a Notepad++ plugin to infect organizations in Ukraine. CERT-UA says UAC-0099 delivers a VBS script disguised as a PDF, which fetches a ZIP containing legitimate Notepad++ 8.8.3 plus a malicious NppExport.dll that installs LunchPoke persistence, then extracts BurnyBear and the MatchBoil V2 loader. CERT-UA also referenced disputed Notepad++ issue CVE-2025-56383 and urged updates to Notepad++ 8.9.7, 7-Zip 26.02, and WinRAR 7.23. — This is a stealthy malware delivery technique that hides inside normal application behavior, making it relevant to defenders and users in Ukraine now. Organizations should review Notepad++ plugin use, hunt for the named files and scheduled tasks, and update the listed software promptly.
Sources: Hackers abuse Notepad++ plugins to stealthily install malware
Chaos ransomware uses new msaRAT malware that hides command traffic inside Chrome and Edge
Cisco Talos says the Chaos ransomware group is deploying a new Rust-based backdoor called msaRAT that hides its command traffic by sending it through Google Chrome or Microsoft Edge instead of connecting directly to attacker servers. The malware is loaded in memory from an MSI installer posing as a Windows update, then uses the Chrome DevTools Protocol to control a headless browser, reach a Cloudflare Workers endpoint, and relay encrypted WebRTC traffic through Twilio TURN servers to obscure the attackers’ infrastructure. — This gives attackers a stealthier way to stay in networks and evade security tools because the malware blends into normal browser traffic. Organizations should hunt for the reported indicators, watch for suspicious headless browser activity and remote debugging use, and harden defenses against the email, voice-phishing, and fake IT/software-update lures used to start these intrusions.
Sources: New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
North Korea’s Kimsuky breached South Korean groupware vendors and used them to reach customer networks
North Korean hackers broke into South Korean collaborative-work software vendors and then used that access to target the vendors’ customers. ENKI WhiteHat said the 2025 to early-2026 campaign hit at least two unnamed groupware suppliers: one was compromised via a remote-code-execution flaw in an internet-exposed mail server, and another via social engineering of an employee. The attackers deployed Gomir and new malware variants, moved laterally, stole customer server information, tampered with login pages to harvest credentials, and then compromised at least one SaaS customer server. — This is a supply-chain style espionage campaign: organizations can be exposed through trusted software providers even if they were not the initial target. South Korean firms using affected collaboration or SaaS platforms should urgently review vendor access, check for credential theft, enforce multi-factor authentication, and hunt for Gomir and related persistence on servers and employee accounts.
Sources: New Kimsuky campaign compromised South Korean software vendors
FakeGit campaign uses 7,600 GitHub repositories and AI tool listings to spread SmartLoader and StealC malware
Attackers set up thousands of fake GitHub repositories to trick developers and AI coding tools into downloading malware. Island says the 'FakeGit' campaign used about 7,600 repositories, including more than 1,400 posing as AI tools, skills, agents, and MCP servers, with README files pointing to ZIP downloads that actually launched SmartLoader, which then used a Polygon smart contract to find command-and-control infrastructure and fetched later stages from GitHub to install the StealC information stealer. — Developers and organizations using GitHub projects or AI agent recommendations are at risk of downloading malware that steals credentials and other sensitive data. Teams should verify repositories and publishers, restrict approved AI tool catalogs, and avoid running downloaded installers or 'releases' from untrusted GitHub projects.
Sources: FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
Attackers exploit critical WordPress Core wp2shell flaws CVE-2026-63030 and CVE-2026-60137 to install webshells
Hackers are actively breaking into vulnerable WordPress sites and planting backdoors that let them keep control of the server. The 'wp2shell' chain affects WordPress Core and abuses the REST API batch-processing feature to achieve unauthenticated remote code execution using CVE-2026-63030 and CVE-2026-60137. WordPress patched the issue in versions 7.0.2, 6.9.5, and 6.8.6, and researchers observed malicious plugins, rogue admin accounts, and PHP webshells being deployed. — WordPress powers a large share of the public web, so active exploitation creates immediate risk for website owners, businesses, and users of compromised sites. Organizations running WordPress should update immediately, review plugins and admin accounts, and check for webshells or unusual REST API activity.
Sources: Critical wp2shell WordPress flaws exploited to install webshells
ClickLock Stealer targets macOS users with fake Cloudflare checks to steal passwords and cryptocurrency
A newly reported macOS malware campaign is tricking users into infecting their own Macs and then stealing passwords, browser data, and cryptocurrency wallet information. Group-IB says ClickLock Stealer has targeted at least 100 users in 33 countries since late May 2026, likely via ClickFix-style fake Cloudflare verification pages that tell victims to paste a bash command into Terminal. The malware kills visible processes and NotificationCenter to suppress warnings, uses fake password prompts to capture credentials, steals Keychain and browser secrets, and exfiltrates data to a Telegram bot. — Mac users are affected even without a software exploit because the attack relies on social engineering and abuse of built-in tools. Organizations should warn users not to paste commands from websites into Terminal, review macOS detections and process-killing behavior, and treat exposed passwords, wallet secrets, and browser data as compromised.
Sources: ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing, New ClickLock macOS malware traps users into revealing login password
OkoBot malware framework uses ClickFix and fake GitHub software repos to steal credentials and cryptocurrency seed phrases
A malware framework called OkoBot is being used to steal passwords, browser cookies, cryptocurrency wallet files, and wallet recovery phrases from victims worldwide. Kaspersky says the campaign evolved from the TookPS activity seen since March 2025 and now uses multi-stage delivery through ClickFix social-engineering lures and trojanized GitHub repositories, including fake software offerings. More than 20 payloads are involved, including modules that inject into Chrome, Trezor Suite, Ledger Wallet, and Ledger Live, install malicious extensions, log keystrokes, and record activity in crypto wallets and password managers. — This can directly lead to drained crypto wallets and stolen accounts, and recovery may be impossible if seed phrases are captured. Organizations and users should avoid running code from untrusted GitHub repositories, treat ClickFix-style prompts as hostile, and hunt for the published indicators of compromise.
Sources: New OkoBot framework deploys 20 payloads to steal data, crypto
ClickFix campaign targets macOS users with Atomic macOS Stealer through silent DMG mounting
A new scam-style malware campaign is tricking Mac users into pasting a Terminal command that silently installs a password and crypto-stealing program. Palo Alto Networks says the ClickFix attack uses a fake CAPTCHA to get victims to run a command that downloads a malicious DMG disk image, mounts it with macOS hdiutil without showing it in Finder, and launches Atomic macOS Stealer (AMOS). The malware steals browser credentials, cookies, Keychain data, Telegram and Discord data, documents, and cryptocurrency wallet information, and can replace Ledger Live and Trezor Suite with trojanized versions. — This can lead directly to stolen passwords, drained crypto wallets, and account takeover for Mac users who follow the fake verification prompt. Users should never paste commands into Terminal from websites, and organizations should warn users about ClickFix lures and watch for AMOS-related activity.
Sources: New macOS ClickFix attack silently mounts DMGs to push infostealer, C'mon, just copy this text string and paste it into your macOS Terminal – it'll fix your computer, honest
CERT-UA says Russia’s Sandworm is using fake CAPTCHA prompts to trick Ukrainians into running PowerShell malware
Ukraine’s cyber agency says Russian military hackers are using fake CAPTCHA checks on compromised websites to trick Ukrainian targets into infecting their own Windows PCs. CERT-UA said Sandworm has increasingly used the ClickFix social-engineering technique in June and July 2026, directing victims to paste PowerShell commands that install malware including GhettoVibe, ScoutCurl, FluidLeech, and LoadLoop; the agency also said the group continues related Android lures and Signal-based social engineering. — This is an active intrusion method aimed at Ukrainian users, including government and military-linked targets, and it can lead to persistent compromise and follow-on destructive attacks. Organizations and individuals in Ukraine should treat CAPTCHA pages asking them to paste commands as malicious, block PowerShell abuse where possible, and warn staff about Signal and fake security-tool lures.
Sources: Sandworm hackers have a CAPTCHA trick for Ukrainians
Russian threat actor UAT-11795 uses trojanized Zoom, Webex, and other software installers to deploy Starland RAT
A Russian cybercrime group is spreading fake installers for popular software such as Zoom, Webex, MobaXterm, DBeaver, and FaceIT to infect Windows users with a new backdoor called Starland RAT. Cisco Talos says UAT-11795 has run the campaign since at least June 2025, mainly against U.S. users, using an HTA file and a trojanized NSIS installer to load Starland, persist via Registry and scheduled tasks, and in some cases deliver CastleStealer and Remcos. The malware steals browser and cryptocurrency-wallet data, gathers Active Directory information, and uses a fallback command-and-control method via a Polygon smart contract. — People and organizations can be compromised simply by installing what looks like legitimate remote-work or developer software, leading to stolen passwords, wallet theft, and deeper network access. Defenders should hunt for Talos indicators of compromise, restrict software downloads to verified vendor sources, and warn users against running pasted commands or unofficial installers.
Sources: Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Spirals ransomware breached a South Asian IT services firm and encrypted its network in under 24 hours
A newly identified ransomware actor called Spirals broke into a South Asian IT services company and went from initial access to data theft and encryption in less than a day. Symantec says the attackers entered through an internet-exposed Microsoft IIS server, uploaded an ASP.NET web shell, enabled Remote Desktop, dumped credentials from the SAM and LSASS, moved laterally with Windows Management Instrumentation (WMI) and PsExec, and used revsocks, Chisel, and Cloudflare Tunnel for persistence. The Rust-based ransomware used intermittent encryption to speed up locking files and dropped a ransom note named RECOVERY_SECTION.log. — This is a fast-moving ransomware playbook that can leave defenders very little time to respond once attackers get in. Organizations with exposed IIS servers should urgently review exposure, hunt for the listed tools and indicators, and verify that endpoint protection, backups, and lateral-movement controls are working.
Sources: New Spirals ransomware encrypts victim network in under 24 hours
Threat actor used Google Gemini CLI to help run a botnet targeting a dental clinic and OpenDental systems
Researchers say a Russian-speaking threat actor used Google’s Gemini CLI as a hands-on assistant to run a small botnet and target a dental clinic’s systems. Trend Micro says the actor used more than 200 Gemini CLI sessions to migrate command-and-control infrastructure, manage eight infected systems, generate infection links, and pursue access to an OpenDental database; the malware used lightweight PowerShell agents, a Python HTTP server, scheduled tasks, WMI event persistence, and registry changes. — This matters because it shows an off-the-shelf AI coding tool being used to speed up real intrusions against a healthcare setting, lowering the skill and time needed to operate malware. Dental and healthcare organizations should review endpoint and PowerShell activity, check for unauthorized persistence, investigate access to OpenDental systems, and harden controls around remote administration and credential exposure.
Sources: Google Gemini CLI abused as a hacking agent, malware botnet operator
AsyncAPI npm supply-chain attack trojanized widely used packages through compromised GitHub Actions workflows
Attackers published malicious versions of several AsyncAPI npm packages, putting developers and systems that installed them at risk of remote access malware and secret theft. Reports say the attacker compromised two AsyncAPI GitHub repositories on July 14 and abused misconfigured GitHub Actions release workflows plus npm trusted publishing to ship trojanized versions of @asyncapi/generator 3.3.1, @asyncapi/generator-helpers 1.1.1, @asyncapi/generator-components 0.7.1, and @asyncapi/specs 6.11.2-alpha.1 and 6.11.2 during a roughly four-hour window. — This matters because a trusted developer dependency with about 2.25 million weekly downloads was used to deliver malware that can provide shell access and steal credentials, tokens, wallets, and CI/CD secrets. Organizations using these packages should identify and remove the bad versions, regenerate lock files, kill related processes, and rotate exposed credentials immediately.
Sources: ​ ​AsyncAPI npm packages infected with credential-stealing malware
Bitdefender shows Windows bind links can hide malware from EDR tools on Microsoft systems
Bitdefender researchers showed that a legitimate Windows feature called bind links can be abused to make malware appear harmless or invisible to some endpoint security tools on Microsoft systems. The techniques use bindflt.sys path redirection to create conflicting filesystem views, including 'file-binding' to swap trusted DLL loads such as amsi.dll and 'process-binding' to make security tools inspect an innocent file path while a different attacker-controlled file runs; Microsoft reportedly rated the issue low severity because it requires administrator access. — Organizations using Windows should treat bind-link abuse as a practical post-compromise stealth technique, especially where attackers may already have admin rights. Defenders should review EDR visibility around bind links, hunt for unusual bindflt.sys activity and trusted-path DLL or executable redirection, and harden privilege controls.
Sources: Windows Bind Link Attacks Can Hide Malware From EDR Tools
Fake GitHub pages impersonating Arctic Wolf and other software vendors are spreading BoryptGrab stealer malware
Attackers created fake GitHub pages that impersonate Arctic Wolf and many other software brands to trick people into downloading malware. Arctic Wolf says one bogus repository used an 'Official Page' link to deliver a ZIP file containing a trojanized installer, 'Arctic-Wolf-3.9.7.exe,' which side-loaded a fake libcurl.dll to decrypt and launch BoryptGrab Stealer, an information-stealing malware family. The company says it found nearly 300 similar repositories using search-engine bait and branding from vendors including Malwarebytes, Bitdefender, and 360 Total Security. — This is a broad social-engineering and malware campaign that can hit employees and consumers who trust GitHub pages and software downloads that look official. Organizations should warn users, block known indicators, and tell staff to download tools only from verified vendor sites or trusted repositories.
Sources: Security Bulletin: GitHub Impersonation Deploys Information Stealer, Nearly 300 GitHub repos pose as legit software to push malware
TrendAI says Russian-speaking scammer used jailbroken Gemini to target QAnon and MAGA users with wallet theft and WordPress credential attacks
A Russian-speaking threat actor allegedly used a jailbroken Google Gemini account to run a months-long scam and theft campaign aimed at QAnon and MAGA communities, stealing WordPress admin credentials and draining at least one victim's cryptocurrency wallets. TrendAI says the operation ran from September 2025 to May 2026 through a Telegram channel with about 17,000 subscribers, used 73 likely stolen Gemini API keys, pushed a fake StellarMonster wallet app that actually installed the GoToResolve remote access tool, and captured victims' seed phrases through a bogus wallet-import screen. — This matters because it blends political-community targeting, AI-assisted social engineering, malware, and direct crypto theft in a way ordinary users can fall for and defenders may miss. Users should avoid wallet apps and recovery prompts promoted in Telegram channels, while organizations should investigate exposed WordPress credentials and watch for abuse of stolen API keys.
Sources: A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets, 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
Compromised Jscrambler npm packages pushed credential-stealing malware in supply-chain attack
Several Jscrambler npm package versions were maliciously updated to install credential-stealing malware on Windows, macOS, and Linux systems used by developers and cloud operators. Jscrambler said an attacker used stolen or otherwise compromised npm publishing credentials starting July 11, 2026 to publish poisoned versions 8.16, 8.17, 8.18, and 8.20 of the main package; the first clean version is 8.22. Related packages were also affected through dependency chains, including Jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and Jscrambler-metro-plugin 9.0.2, with 1,479 downloads recorded before deprecation. — Anyone who installed the affected packages may have had passwords, tokens, cloud credentials, crypto-wallet data, and other secrets stolen. Organizations using these packages should remove the affected versions immediately, scan impacted machines, and rotate credentials and API keys without delay.
Sources: Multiple Jscrambler Packages Impacted by Supply Chain Attack
Microsoft details GigaWiper backdoor that can spy on systems, encrypt files, and wipe Windows disks
Microsoft says a threat actor has used a destructive Windows backdoor called GigaWiper for more than eight months to maintain access and sabotage infected systems. First seen in October 2025, the Go-based malware combines older wiping components with backdoor functions, supports command-and-control through RabbitMQ and Redis, and can run PowerShell, upload files, take screenshots, record screens, trigger a Blue Screen of Death, encrypt files in both reversible and destructive modes, and wipe disks at the physical-drive level. — This is not just another infostealer or ransomware sample: it gives attackers a single tool for stealthy access and for crippling machines on demand. Defenders should hunt for the malware’s persistence and command-and-control activity, especially RabbitMQ, Redis, MinIO Client, and destructive commands, because the impact can range from spying to irreversible data loss.
Sources: GigaWiper Combines Multiple Malware for System-Level Sabotage, Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
Compromised Injective SDK package on npm stole cryptocurrency wallet seed phrases and private keys
A malicious version of Injective Labs' JavaScript SDK was published to npm after attackers compromised a contributor account, putting developers and downstream crypto apps at risk of wallet theft. The poisoned release was @injectivelabs/sdk-ts version 1.20.21, and 17 related packages were pinned to it. The malware triggered when wallet-generation or wallet-import functions were used, then exfiltrated mnemonic seed phrases and private keys via HTTP requests disguised as legitimate traffic. Injective later published clean version 1.20.23. — Developers who installed or used the affected package may have exposed wallet secrets that let attackers drain funds, so this is urgent for cryptocurrency projects and users tied to those wallets. Affected teams should audit dependencies, rotate environment secrets, and move funds to new wallets if any seed phrase or private key may have been handled by the malicious version.
Sources: Injective SDK on npm infected with cryptocurrency wallet stealer, Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
China- and India-linked hackers both breached Pakistan’s Balochistan Police and planted malware on its public complaint portal
Hackers linked to China and India spent more than two years inside Pakistani police networks, with Balochistan Police hit most heavily and its public complaint website used to expose visitors to fake software updates. SentinelOne says the intrusions ran from February 2024 to April 2026 and involved activity clusters using PlugX, ShadowPad, Cobalt Strike, and Remcos malware against servers tied to biometric databases, criminal case files, personnel records, and citizen-facing systems. — This is a significant government and privacy breach affecting police operations, sensitive biometric and personnel data, and potentially members of the public who used the complaint portal. Pakistani government defenders should investigate for the named malware families and review all systems connected to Balochistan Police’s public web services; users and staff should treat past update prompts from that portal as suspicious.
Sources: China, India-Linked Hackers Both Targeted Same Pakistani Police Force, China, India ran separate spying campaigns against same Pakistani police force
Researchers show HalluSquatting attack can make AI coding assistants fetch fake packages and run attacker commands
Researchers say attackers can abuse recurring AI hallucinations to make coding assistants download malicious repositories or packages and execute commands on a user’s machine. The 'HalluSquatting' technique pre-registers fake resource names that large language model tools such as Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI, and OpenClaw repeatedly invent during repo-cloning or skill-installation tasks, creating a scalable prompt-injection path to remote code execution and possible malware or botnet deployment. — Organizations using AI coding or automation assistants could be exposed even without a direct phishing message or malicious email. Teams should treat AI-suggested package and repository names as untrusted, restrict agent terminal actions, and add allowlists or review gates before assistants install software or run commands.
Sources: ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
Operation Muck and Load used more than 200 GitHub repositories and a malicious Go module to infect Windows systems
Attackers used a network of more than 200 GitHub repositories to trick developers and users into downloading malware on Windows. Socket says the campaign, dubbed Operation Muck and Load, used 222 lure repositories across 190 accounts and a fake Go module posing as a DNS scanning tool based on dnsub. The module secretly ran PowerShell to fetch a resolver from public dead drops including Pastebin, YouTube, Instagram, Telegram, Google Docs, and GitCode, then downloaded and launched payloads such as AsyncRAT, Quasar RAT, Vidar infostealer, spyware, trojan downloaders, and XMRig-related cryptominers. — This is a broad open-source supply-chain and malware delivery operation that can hit developers, enterprise users, and anyone who runs code from untrusted GitHub projects. Organizations should review use of Go packages and GitHub repositories tied to the campaign, block the listed dead-drop services where appropriate, and hunt for PowerShell-based payload delivery on Windows endpoints.
Sources: Network of 200 GitHub Repositories Used for Malware Infection
China-linked hackers exploit Roundcube flaws CVE-2024-42009 and CVE-2025-49113 to spy on U.S. and Canadian researchers
A suspected China-aligned hacking group has been breaking into vulnerable Roundcube webmail servers at U.S. and Canadian universities to steal logins and plant backdoors. Proofpoint says the campaign, tracked as UNK_MassTraction, has run since May and targets physics, engineering, astrophysics, particle-physics, and national-security-related research organizations. Attackers use emails that trigger Roundcube cross-site scripting flaw CVE-2024-42009 to load the IceCube stealer, then abuse deserialization flaw CVE-2025-49113 to try to install the SquareShell PHP web shell or the VShell backdoor. — Universities and research groups handling sensitive science and national-security work may have had email accounts and mail servers compromised. Organizations using Roundcube should patch immediately, review mail-server logs for exploitation, and reset credentials and session cookies for potentially affected users.
Sources: Hackers exploit Roundcube flaw to spy on academic researchers, Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Fake Paysafe, Skrill, and Neteller SDK packages on npm and PyPI stole developer credentials and API keys
Attackers uploaded fake software packages for Paysafe, Skrill, and Neteller to npm and PyPI, putting developers and any systems that ran them at risk of credential theft. Socket identified 17 malicious packages: 13 on npm with versions 1.0.0 through 1.0.3 and 4 on PyPI at version 1.0.0. The packages imitated legitimate payment software development kits, exposed expected APIs, returned fake success responses, and exfiltrated Paysafe API keys, AWS keys, GitHub tokens, npm tokens, passwords, and host metadata to attacker infrastructure on AWS. — Developers, payment integrations, and continuous integration systems may have had secrets stolen just by importing or running these packages. Organizations that installed them should remove the packages, audit dependency trees and build logs, and rotate exposed credentials immediately.
Sources: Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
China-aligned UAT-7810 expands router-based ORB network with LONGLEASH malware on Ruckus and ASUS devices
A China-aligned hacking group is expanding a covert relay network by breaking into internet-facing routers and loading new backdoor malware. Cisco Talos says UAT-7810 is using LONGLEASH, plus DOGLEASH, JARLEASH, and LEASHTEST, to grow an operational relay box (ORB) infrastructure that can proxy traffic for other China-linked actors. Initial access relies on n-day flaws in Ruckus routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS AiCloud routers (CVE-2025-2492). — Organizations and consumers with unpatched edge devices could have their routers turned into stealth infrastructure for espionage or follow-on attacks. Patch affected Ruckus and ASUS devices, check Talos indicators of compromise, and review exposed networking gear for web shells, tunneling, and unusual proxy behavior.
Sources: Chinese hackers develop LONGLEASH malware to expand ORB network, China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
Attackers exploit unpatched Langflow flaw CVE-2026-5027 to run code on exposed AI workflow servers
Attackers are exploiting a security hole in Langflow that can let outsiders take over internet-exposed servers without logging in. The flaw, CVE-2026-5027, is an unauthenticated remote-code-execution bug affecting Langflow, an open-source tool for building AI workflows; exploitation means attackers can send crafted requests to run their own commands on vulnerable systems, and the article says no patch is available yet. — Organizations using Langflow should treat this as urgent because an exposed server could be fully compromised with no valid account needed. If you run Langflow, restrict internet access, apply any vendor mitigations, monitor for compromise, and patch immediately once a fix is released.
Sources: Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE, Path traversal flaw in AI dev platform Langflow exploited in attacks, Hackers Exploit Langflow Vulnerability for Remote Code Execution (+4 more)
CAI cloud worm targets Docker, Kubernetes, Redis, etcd, Kubelet, and Ray to steal credentials and mine cryptocurrency
A newly reported malware framework called CAI is infecting cloud and developer infrastructure to steal secrets and run cryptocurrency miners. Hunt.io says the worm scans for exposed services including Docker, Kubernetes, Redis, etcd, Kubelet, and Ray, then deploys miners, credential stealers, and a Python backdoor while also killing rival malware from TeamPCP and PCPJack. Researchers observed the operator move from testing to active compromises between mid-June and early July 2026. — Organizations running internet-exposed cloud management and developer tools could have credentials stolen and systems hijacked for follow-on attacks or cryptomining. Defenders should check exposed Docker, Kubernetes, Redis, etcd, Kubelet, and Ray services, hunt for miners and unknown Python backdoors, rotate exposed secrets, and review cloud access controls now.
Sources: CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Iran-linked Cavern Manticore used compromised IT providers and a modular malware framework to target organizations in Israel
An Iran-linked hacking group used compromised IT service providers and a custom modular malware framework to break into organizations in Israel, especially government entities and technology suppliers. Check Point says Cavern Manticore, which it links to Iran’s Ministry of Intelligence and Security and possibly OilRig/Lyceum, abused SysAid’s software update feature to sideload a WinDirStat DLL and launch its .NET-based 'Cavern' agent, then pulled modules for file access, database and LDAP enumeration, SMB brute-force, tunneling, and lateral movement through remote monitoring tools. — This matters because the attackers did not just hit one victim directly; they moved through trusted IT providers to reach higher-value targets, which raises risk across connected organizations. Israeli organizations and service providers should review SysAid-related update paths, hunt for the Cavern agent and follow-on modules, and scrutinize remote management and remote desktop activity.
Sources: Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
Attackers use fake Microsoft Teams IT support calls to install EtherRAT on employee computers
Attackers are calling employees on Microsoft Teams while pretending to be corporate IT staff and tricking them into installing malware that gives remote control of their computers. According to Palo Alto Networks' Unit 42, the campaign starts with an 'Employee Survey' phishing email and PDF, then a Teams voice call from an external Microsoft 365 tenant, followed by abuse of Teams screen sharing and remote tools including HopToDesk and AnyDesk. The attackers then run a malicious MSI installer that fetches Node.js and launches EtherRAT, a cross-platform remote access trojan that can execute commands, steal data, persist, and use Ethereum smart contracts to locate command-and-control servers. — Organizations using Microsoft Teams are at risk of employees being talked into giving attackers direct access to their devices. Defenders should warn staff not to trust unsolicited Teams support calls, restrict external Teams communications and remote-control features where possible, and review logs for suspicious external tenants, remote tool installs, and the listed infrastructure.
Sources: Fake IT support calls on Microsoft Teams push EtherRAT malware, Fake IT bods on Microsoft Teams coax workers into installing malware
Veil#Drop malware campaign uses Blogspot-hosted payloads and PowerShell to install PureLog infostealer
Attackers are using compromised websites and Google’s Blogspot service to infect Windows users with a data-stealing malware called PureLog. Securonix says the 'Veil#Drop' framework starts with a fake document JavaScript file that launches PowerShell, pulls later stages from attacker-controlled Blogspot pages, and runs payloads in memory using obfuscation, reflective .NET loading, and trusted Microsoft-signed binaries to evade detection. PureLog steals browser credentials, cookies, session tokens, wallet data, and secrets from messaging, email, FTP, cloud, remote-access, and developer tools. — This is dangerous because one infected employee computer can hand over passwords, tokens, and other secrets that attackers can later use for ransomware, business email compromise, or deeper intrusions. Organizations should block or scrutinize script-based downloads, hunt for suspicious PowerShell and LOLBIN activity, and reset exposed credentials if an infostealer infection is suspected.
Sources: Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
Kaspersky says Armored Likho is targeting government and electric power organizations in Russia, Brazil, and Kazakhstan
A newly identified hacking group called Armored Likho has been targeting government and electric power organizations in multiple countries, while also running financially motivated attacks against individuals. Kaspersky says the actor uses spear-phishing emails with executable or shortcut (LNK) files to install malware including the Python-based BusySnake Stealer and Go2Tunnel, enabling credential theft, browser cookie and password extraction, Telegram session theft, screenshot capture, reverse SSH tunnels, and persistent remote access. — Government and energy organizations are high-value targets, and the campaign uses common email lures that can reach many users. Defenders should harden email filtering, block malicious LNK/executable attachments, monitor for GitHub-hosted payload retrieval and reverse SSH activity, and hunt for BusySnake, Go2Tunnel, and related persistence mechanisms.
Sources: Armored Likho APT Targeting Government, Electric Power Entities
North Korea-linked PolinRider campaign hijacks more than 100 open-source packages and repositories to backdoor developers
North Korean hackers are compromising legitimate open-source packages and code repositories to infect software developers with a backdoor and an information stealer. Socket says the PolinRider campaign has been active since December 2025 and has produced 162 malicious release artifacts across 108 packages spanning npm, Packagist, Go modules, and Chrome extensions. The attackers reportedly hijack maintainer accounts, rewrite Git history to hide tampering, and use obfuscated JavaScript loaders to fetch DEV#POPPER remote-access malware and OmniStealer via blockchain and public remote procedure call infrastructure. — This can put developer laptops, source code, cloud accounts, and continuous integration and delivery secrets at risk even when teams install what look like trusted updates. Organizations that installed affected package or extension versions should treat those systems as compromised, investigate from clean machines, and rotate exposed credentials.
Sources: North Korean Hackers Target Open Source Developers in Supply Chain Attacks
Automated ransomware attack exploited Langflow CVE-2025-3248 and Nacos CVE-2021-29441 to destroy server data
Researchers say an attacker used a large language model to automate a full ransomware and extortion attack against exposed servers, ending with encrypted and deleted data. Sysdig said the intrusion began by exploiting Langflow CVE-2025-3248, an unauthenticated remote-code-execution flaw, then moved to a production server running MySQL and Alibaba Nacos, abused Nacos CVE-2021-29441 and the product's default JWT signing key, added a backdoor admin, and encrypted 1,342 configuration records before dropping database schemas. — Organizations running internet-exposed Langflow or Nacos instances could face fast, destructive break-ins that do not reliably allow recovery even if a ransom is paid. Defenders should urgently patch or isolate exposed systems, rotate credentials, and check for cron-based persistence, rogue Nacos admins, and database tampering.
Sources: Smooth AI criminal drives 'first' end-to-end agentic ransomware attack, Agentic AI Used to Conduct Ransomware Attack via Langflow, JadePuffer ransomware used AI agent to automate entire attack
Researchers link Popa Android TV box botnet and residential proxy network to NetNut and Alarum Technologies
Researchers say a sprawling Android TV box botnet called Popa has been turning millions of consumer streaming devices into residential proxies that relay malicious traffic. KrebsOnSecurity, citing Qurium and earlier XLAB findings, says Popa is associated with the Vo1d malware ecosystem and has been used for advertising fraud, account-takeover activity, and mass data scraping; newly analyzed command-and-control domains including ninjatech[.]io are linked to NetNut, a proxy provider owned by Alarum Technologies. — People who bought unofficial streaming boxes may have unknowingly exposed their home internet connections and possibly local networks to abuse by third parties. Consumers should disconnect suspect devices, replace them with trusted hardware, and monitor accounts and network activity; defenders should block known Popa infrastructure and scrutinize traffic from Android-based set-top boxes and residential proxy sources.
Sources: ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum, FBI Seizes NetNut Proxy Platform, Popa Botnet (+3 more)
FortiBleed campaign compromised more than 30,000 Fortinet firewalls and VPN gateways worldwide
Researchers say more than 30,000 Fortinet firewalls and virtual private network gateways were compromised and can expose the organizations behind them to further hacking. SOCRadar said a campaign it calls FortiBleed systematically tried known passwords against internet-exposed Fortinet devices, harvested working credentials, then monitored traffic and reused newly captured passwords to spread further; victims span companies and government bodies in more than 190 countries. — Organizations using Fortinet edge devices may already have attackers inside even without a new software flaw. This is urgent for network defenders: audit Fortinet logins, rotate passwords and tokens, review device configurations, and check for signs of credential harvesting or unauthorized access.
Sources: 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs, FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices., Massive password-stealing attack hits 75k Fortinet firewalls (+11 more)
Trojanized GitHub exploit repositories used malicious PyPI packages to install ChocoPoC remote-access malware
Attackers hid malware in GitHub proof-of-concept exploit repositories and infected people who cloned and ran them. Sekoia says at least seven repositories for exploits tied to FortiWeb CVE-2025-64446, React2Shell CVE-2025-55182, MongoBleed CVE-2025-14847, PAN-OS CVE-2026-0257, Ivanti Sentry CVE-2026-10520, Check Point VPN CVE-2026-50751, and Joomla SP Page Builder CVE-2026-48908 pulled malicious PyPI packages including frint and skytext, which installed the ChocoPoC RAT, a remote-access trojan that can run commands and steal credentials and files. — This targets the very people trying to test or defend against vulnerabilities, and it can silently hand over passwords, browser sessions, files, and system access. Anyone who cloned untrusted exploit code from GitHub should review systems for the listed packages and treat such testing as high-risk unless done in isolated environments.
Sources: ChocoPoc malware delivered via trojanized exploits on GitHub, New ChocoPoC malware targets researchers via trojanized PoC exploits, New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Check Point says DeepSeek-generated browser ransomware sample can be turned into a working Chrome-based file-encryption attack
Check Point says code generated by DeepSeek can be adapted into a working browser-based ransomware attack that encrypts a victim’s local files after they approve a browser permission prompt. The sample, dubbed "InfernoGrabber 9000," is a Python Flask web app targeting Android users and abuses Chrome and Chromium-based browsers’ File System Access API to read and write local files without a traditional malware install, relying on phishing-style social engineering rather than a browser exploit or CVE. — This lowers the barrier for criminals to build ransomware-like attacks that run in the browser, where users may trust the prompt because it comes from a legitimate browser feature. Defenders should review controls around Chromium-based browsers and file-access permissions, and users should be wary of websites asking for broad local file access.
Sources: Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
SimpleHelp fixes critical CVE-2026-48558 that lets attackers create rogue remote support accounts
A critical flaw in SimpleHelp remote management software can let an outsider create a privileged support account on vulnerable servers. The bug, CVE-2026-48558, affects SimpleHelp 5.5.15 and earlier plus 6.0 pre-release builds when OpenID Connect (OIDC) login is enabled and certain technician-group settings are in use. An unauthenticated attacker can bypass normal identity checks and multi-factor authentication to gain technician access; fixes are in 5.5.16 and 6.0RC2. — Organizations using SimpleHelp for remote administration could hand attackers the same kind of access trusted support staff have, including remote control of managed devices and script execution. This is urgent for anyone exposing SimpleHelp to the internet: update now, and if you cannot patch immediately, restrict technician logins with IP allowlists and review logs for suspicious new technician accounts.
Sources: SimpleHelp bug lets hackers create rogue remote support accounts, Critical SimpleHelp Vulnerability Exploited for Malware Delivery, Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer (+1 more)
Malicious PyPI packages posing as Pyrogram forks backdoor Telegram bot servers
Attackers published at least eight malicious Python packages on PyPI that target developers building Telegram bots and can give the attackers control of infected servers. The packages are trojanized forks of the Pyrogram Telegram framework and include a hidden backdoor file, secret.py, that registers covert Telegram commands to execute attacker-supplied Python or shell code, read arbitrary files, dump credentials and chats, and exfiltrate output via Telegram. Checkmarx says the campaign, active since November 2025, used multiple package names including pyrogram-styled, pyrogram-navy, VLifeGram, and kelragram. — Developers and organizations running Telegram bots could have had production servers quietly turned into remote-access points for attackers. Anyone who installed the named packages should remove them immediately, rotate credentials and API keys, review bot hosts for persistence, and inspect PyPI dependencies and software bill of materials records.
Sources: Malicious PyPI packages give hackers control of Telegram bot servers
Fake Perplexity Chrome Web Store extension intercepted searches and sent them through attacker servers
A malicious Chrome Web Store extension posing as Perplexity routed users’ searches through attacker-controlled systems and collected browsing data before forwarding people to legitimate search services. Microsoft said the fake add-on, listed as “Search for perplexity ai,” changed Chromium browser search settings via chrome_settings_overrides and used powerful Declarative Net Request permissions to redirect, rewrite, and monitor traffic. The extension used the domain perplexity-ai[.]online instead of the legitimate perplexity.ai; the reported extension ID was flkebkiofojicogddingbdmcmkpbplcd. — Anyone who installed it may have exposed their searches and browsing activity, and the granted permissions could also have supported credential theft if the operator expanded the campaign. Users should remove the extension immediately and, as a precaution, rotate important passwords and review other installed browser add-ons.
Sources: Fake Perplexity extension on Chrome Web Store tracked searches
North Korea-linked Gaslight macOS malware uses fake error messages to mislead AI analysis tools
Researchers found a new macOS malware family called Gaslight that steals data and gives attackers backdoor access while also trying to confuse AI-based malware analysis tools. SentinelOne says the Rust-based sample contains about 3.5 KB of embedded prompt-injection text and 38 fake system, crash, and debug messages meant to make large language model analysis pipelines abort or mistrust their own results; the company attributes the malware with high confidence to a North Korean-linked threat actor. — This matters because it shows attackers are adapting malware to interfere with newer AI-assisted security workflows, not just traditional sandboxes and analysts. Defenders using automated malware triage should validate AI findings against manual and non-LLM tooling, and macOS users and admins should treat the sample as a real backdoor and infostealer threat.
Sources: New macOS malware embeds fake errors to confuse AI analysis tools, In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs
Russia-linked Turla uses new StockStay backdoor to spy on Ukrainian government and military targets
Google says the Russia-linked Turla hacking group has been using a newly detailed backdoor called StockStay to spy on government and military organizations in Ukraine. The .NET malware, developed since 2022, overlaps with Turla’s Kazuar implant and was delivered through phishing emails, malicious RDP configuration files, and in one November 2025 case a WinRAR exploit chain using CVE-2025-8088. Google also says compromised Ukrainian infrastructure and diplomacy- or education-themed lures were used in the campaign. — This is an active espionage campaign against wartime government and defense targets, with tactics defenders can hunt for now. Ukrainian and European public-sector organizations should review phishing defenses, inspect for StockStay-related persistence and WebSocket command-and-control traffic, and investigate any exposure to the cited WinRAR exploit chain.
Sources: Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets, Turla group adds more malware to Russia’s espionage efforts against Ukraine
Suspected Miasma worm compromises more than 70 Microsoft GitHub repositories and breaks Azure CI/CD workflows
GitHub disabled more than 70 Microsoft repositories after attackers allegedly used a compromised contributor account to push malicious commits into projects including Azure/durabletask and Azure/functions-action. StepSecurity says the Miasma worm planted configuration files that could trigger remote code execution when a developer opened the repository in an integrated development environment or AI coding tool such as Claude Code, Gemini CLI, or Cursor, and the takedowns disrupted workflows that depended on Azure/functions-action@v1. — This affects developers and organizations that rely on Microsoft's open-source Azure tooling, with both supply-chain risk and immediate build-pipeline disruption. Teams using the affected repositories should review recent commits, rotate contributor and automation tokens, check developer machines for malicious config execution, and verify dependencies before restoring pipelines.
Sources: GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections, Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks, GitHub disables Microsoft repos pushing password-stealing malware (+3 more)
Symantec and Zscaler link new Mistic backdoor to KongTuke ransomware access broker
Researchers say a newly identified backdoor called Mistic is being used to quietly keep access inside company networks in attacks tied to KongTuke, an initial access broker linked to ransomware groups. Symantec says Mistic has been used since April 2026 against organizations in insurance, education, IT, and professional services, including deployment after ModeloRAT in at least one case. The malware is side-loaded through MpExtMs.exe and a malicious version.dll, can run payloads in memory, steal credentials via a fake login prompt, and receive commands from attacker-controlled servers; Zscaler says it also appeared in a multi-stage ClickFix infection chain and can load Beacon Object Files for in-memory post-exploitation. — Organizations in the named sectors may be facing a low-visibility foothold used to prepare ransomware attacks, not just one-off malware infections. Defenders should hunt for KongTuke and ClickFix activity, review Symantec and Zscaler indicators, and watch for suspicious DLL side-loading, fake login prompts, and Microsoft Teams-based social engineering.
Sources: Stealthy Mistic backdoor linked to ransomware access broker KongTuke, New ‘Mistic’ RAT Opens Door to Several Ransomware Families, New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns (+1 more)
Malicious Microsoft Edge extension used Native Messaging to install a Python backdoor in ransomware-linked attacks
Attackers used a fake Microsoft Edge update process to trick employees into installing a malicious browser extension that helped deploy malware on their computers. Zscaler says the 'Edgecution' campaign starts with Microsoft Teams messages from fake IT support and uses Chrome Native Messaging in Microsoft Edge to let the extension communicate with a local Python-based backdoor outside the browser sandbox. The activity is linked by tactics and infrastructure patterns to an initial access broker associated with the Payouts Kings ransomware operation. — This matters because it turns a browser extension into a bridge for full system compromise, not just in-browser abuse, and it is being used in real ransomware-linked intrusions. Organizations should warn users about fake IT support messages, restrict extension installs, and monitor or lock down Native Messaging host configurations on managed endpoints.
Sources: Malicious Edge extension abuses Native Messaging as bridge to malware
Operation Endgame removes SocGholish malware from nearly 15,000 WordPress sites and seizes 106 servers tied to Evil Corp
Police in Europe and North America removed SocGholish malware from nearly 15,000 hacked WordPress websites and took more than 100 related servers and domains offline. Authorities in the Netherlands, Canada, the United States, and Germany said the action targeted the SocGholish botnet, also known as FakeUpdates or GhoLoader, which infects visitors through fake browser-update prompts on compromised sites. Europol and Eurojust said the operation was part of Operation Endgame and disrupted infrastructure linked to the Evil Corp cybercrime group. — This cuts off a long-running malware infection path that has been used to infect everyday web visitors and deliver other crimeware and ransomware. WordPress site owners should check for compromise, rotate credentials, enable multi-factor authentication, and remove unknown accounts; users should avoid software update prompts shown on random websites.
Sources: Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp, 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown, Police raid malware network tied to Russia's Evil Corp hacker group (+3 more)
Microsoft, Europol and partners disrupt shared Amadey and StealC malware infrastructure in Operation Endgame
Microsoft, Europol, and industry partners said they disrupted hundreds of domains and command-and-control servers used by the Amadey loader and StealC infostealer malware families. The action was part of Operation Endgame and targeted shared infrastructure identified through analysis of both malware families; authorities said they seized more than 25 million stolen credentials from over 385,000 systems, identified 18,000 compromised computers, and also used a vulnerability in the StealC control panel to support the takedown. — This matters because Amadey and StealC are widely used to break into computers and steal passwords, cookies, and crypto-wallet data at scale. Organizations should hunt for signs of these malware families, rotate exposed credentials, and check endpoints for infostealer or loader infections if they may have been affected.
Sources: Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware, Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered, Microsoft uses AI to link two malware operations in racketeering suit (+1 more)
WhatsApp malware campaign uses compromised accounts and fake business documents to install remote access on Windows PCs
Attackers are using hijacked WhatsApp accounts to send fake business and financial documents that infect Windows computers when opened. Kaspersky says the campaign delivers heavily obfuscated VBScript files through WhatsApp, then downloads additional scripts that modify User Account Control settings in the Windows Registry and silently installs ManageEngine Endpoint Central configured to connect to attacker-controlled servers. Victims have been seen in Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia. — People can be infected by files that appear to come from trusted contacts, turning a chat message into full remote access on their PC. Users should avoid opening script attachments from WhatsApp and verify unexpected files out-of-band; defenders should look for suspicious wscript.exe activity and unauthorized ManageEngine Endpoint Central installs.
Sources: WhatsApp phishing attack uses fake business docs to hack PCs
ShapedPlugin supply-chain attack used official WordPress plugin updates to install backdoors on customer sites
ShapedPlugin’s official update system was compromised and pushed malware-tainted WordPress plugin updates to paying customers, putting affected websites at risk of credential theft and remote tampering. WordPress is tracking the incident as CVE-2026-10735. Affected paid plugins were Product Slider Pro before 3.5.4 for WooCommerce, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2; Wordfence says the malicious code acted as a loader that fetched a second-stage backdoor, hid it as fake WooCommerce plugins, and stole admin logins, two-factor authentication secrets, database credentials, and recent WooCommerce order data. — Website owners who installed these paid plugin updates may have had their WordPress and store credentials stolen and their sites quietly backdoored. Affected admins should update immediately, look for the fake WooCommerce plugins, rotate passwords and keys, and review their sites for unauthorized changes.
Sources: ShapedPlugin update flow hacked to infect WordPress sites, ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Microsoft says North Korea's Sapphire Sleet was behind the Mastra AI npm supply-chain attack affecting 140+ packages
Microsoft says a North Korean hacking group compromised the Mastra AI software supply chain by hijacking an npm maintainer account and pushing malicious updates to more than 140 packages. The attacker used the compromised account "ehindero" to add a typosquatted dependency, "easy-day-js," to packages in the @mastra scope; its post-install script dropped cross-platform malware for Windows, macOS, and Linux that stole credentials, API keys, authentication tokens, browser data, and cryptocurrency-wallet information, and established persistence on infected systems. — Developers and organizations that installed affected Mastra packages could have had secrets and crypto-wallet data stolen from their machines. This is urgent for software teams: identify any use of affected @mastra packages, remove malicious versions, rotate exposed credentials and tokens, and investigate systems that contacted the attackers' command-and-control servers.
Sources: Microsoft links Mastra AI supply chain attack to North Korean hackers, North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
Gizmodo site compromise served ClickFix malware prompts to readers through a hijacked account
Gizmodo readers were briefly exposed to fake verification prompts on the news site after a compromised account was used to inject malicious code into article pages. The attack delivered ClickFix social-engineering lures that tried to make users run commands locally; according to reporting and researcher analysis, the Windows flow attempted to install NetSupport RAT, a remote-access trojan, while the macOS payload appeared misconfigured and did not execute cleanly. — Anyone who followed the prompt on a Windows device may have installed remote-access malware that can steal files or pull down more malicious tools. Affected users should check for suspicious commands or downloads, run endpoint scans, and site operators should review account security and script-injection controls.
Sources: Gizmodo readers hit with ClickFix malware prompts after account compromise
Canada’s spy agency used a first-of-its-kind warrant to remove malware from botnet-infected devices
Canada’s signals intelligence agency reportedly got court approval to access and clean malware from devices infected by a botnet, marking a new kind of government cyber operation affecting victims inside Canada. The report centers on the Communications Security Establishment using a warrant to disrupt infections on victim systems rather than only monitor or seize infrastructure, raising questions about legal authority, oversight, and how defensive government hacking will be used in future botnet takedowns. — This matters because it could set a precedent for governments remotely accessing privately owned devices in the name of cyber defense. People and organizations in Canada should watch for official guidance on whether their systems were affected and what safeguards, notification, and oversight rules apply.
Sources: Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
AryStinger botnet hijacked more than 4,000 D-Link routers to act as attacker-controlled proxies
A newly documented botnet called AryStinger infected more than 4,000 older D-Link routers and turned them into systems that relay malicious traffic and help attackers scan and probe other networks. XLab said the malware targets end-of-life D-Link DIR-850L and DIR-818LW devices by exploiting older flaws including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837; researchers also found a Go-based variant aimed at network-attached storage systems. Infected devices can proxy traffic, tamper with Domain Name System settings, execute commands, and monitor network traffic. — People and organizations still using these unsupported routers may have their internet traffic monitored or redirected without noticing, and their devices can be used to help attack others. Replace end-of-life hardware, apply the latest firmware if any is available, change admin passwords, and disable remote management.
Sources: AryStinger botnet infected thousands of D-Link routers worldwide, AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
Prinz Eugen ransomware uses stolen RDP access and encrypts recently changed files first
Researchers say a new ransomware group called Prinz Eugen is breaking into organizations and encrypting their newest or most recently changed files first to increase pressure to pay. ThreatDown says the operators appear to use stolen Remote Desktop Protocol (RDP) credentials, legitimate remote monitoring and management tools such as RemotePC, and hands-on-keyboard activity. The Go-based encryptor uses ChaCha20-Poly1305, appends a .prinzeugen extension, may delete originals after verifying decryption works, and currently shows at least several known victims, including a reported Standard Bank incident. — Organizations with exposed or weakly protected remote access are at risk, especially if attackers can reuse stolen credentials and blend in with legitimate admin tools. Defenders should review RDP exposure, audit remote-management tool use, hunt for the listed indicators of compromise, and watch for unusual admin account creation.
Sources: New Prinz Eugen ransomware prioritizes recent files for encryption
China-linked Velvet Ant hijacked Linux authentication and spied on an isolated critical infrastructure network for 10 years
A China-linked hacking group secretly controlled a large organization's critical infrastructure network for a decade, even after the sensitive environment was separated from the internet. Sygnia attributes the campaign, called Operation Highland, to Velvet Ant, which first compromised internet-facing systems and then built an execution path into the isolated network by altering Nginx and FastCGI (a web-server request handler) configurations. The attackers used modified GS-Netcat and SOCKS5 tools for access and pivoting, then replaced Linux PAM authentication modules and OpenSSH components with trojanized versions to backdoor logins, steal credentials, and record administrator commands. — This is notable because it shows a sophisticated state-linked actor quietly maintaining access to critical systems for years by tampering with core login and remote-access components. Organizations running Linux in segmented or industrial environments should hunt for altered PAM, OpenSSH, Nginx, and startup-service files and review long-term credential exposure and administrative access.
Sources: Chinese hackers hijack auth flow, spy on isolated network for a decade, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Awesome Motive CDN breach injected malware into OptinMonster, TrustPulse, and PushEngage WordPress plugins
Attackers compromised Awesome Motive's content delivery network and briefly pushed malicious code to websites using OptinMonster, TrustPulse, and PushEngage, putting those sites at risk of takeover. According to Awesome Motive and Sansec, the attackers first breached a marketing server by exploiting a known flaw in the UpdraftPlus WordPress plugin, stole a CDN API key, and altered JavaScript served from Awesome Motive CDN domains. The malicious code activated when a WordPress administrator loaded a page, stole authentication tokens and nonces, created rogue admin accounts, and installed hidden backdoor plugins that enabled arbitrary PHP code execution and web-shell access. — Website owners using these plugins may still have hidden attacker access even though the malicious CDN files were removed. Administrators should immediately check for rogue admin users and unknown plugins, rotate passwords and keys, and scan affected WordPress servers for persistence.
Sources: OptinMonster WordPress plugin hacked in CDN supply-chain attack, In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Microsoft says CryptoBandits Windows malware steals cryptocurrency and uses Tor as a backdoor
Microsoft says a Windows malware family called CryptoBandits is infecting systems and stealing cryptocurrency by swapping copied wallet addresses, while also giving attackers remote access. The campaign has been active since February 2026 and spreads through malicious .lnk shortcut files and infected USB devices. It drops a portable Tor client, uses a local SOCKS5 proxy for hidden command-and-control traffic, achieves persistence with scheduled tasks, and can steal seed phrases, private keys, clipboard data, and screenshots while receiving follow-on commands. — This matters to both consumers and organizations because an infection can silently redirect crypto payments and provide attackers with ongoing access to a Windows device. Defenders should watch for suspicious .lnk files, USB-based propagation, unexpected local SOCKS5/Tor activity, and script execution via Windows Script Host, while users should avoid opening untrusted shortcut files and verify wallet addresses before sending funds.
Sources: CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
KrebsOnSecurity links The Gentlemen ransomware group to a suspected administrator in Izhevsk, Russia
A new report identifies a suspected real-world operator behind The Gentlemen, one of 2026's most active ransomware groups. KrebsOnSecurity, drawing on Check Point, Intel 471, Flashpoint, and Constella data, says the ransomware-as-a-service group has claimed at least 332 victims since mid-2025 and more than 240 in 2026, recruits affiliates with a 90/10 ransom split, and commonly gains entry through internet-facing VPN and firewall devices before rapidly encrypting networks. — This is a major ransomware actor by victim volume, so the attribution and tradecraft details help defenders prioritize monitoring of exposed remote-access and edge devices. Organizations should review exposure of VPNs and firewalls, harden remote access, and watch for intrusion patterns associated with fast-moving affiliate-led ransomware attacks.
Sources: Who Runs the Ransomware Group ‘The Gentlemen?’, Gentlemen ransomware uses multiple EDR killers to disable defenses
Google says China-linked UNC6508 hid in REDCap servers at North American medical and military research organizations for more than a year
Google says a China-linked espionage group spent more than a year inside North American medical and military research networks, stealing sensitive data and searching Gmail for defense and disease-research information. Google tracks the group as UNC6508 and says the intrusions began by exploiting internet-facing REDCap (Research Electronic Data Capture) servers, then deploying custom InfiniteRed malware to maintain access, harvest REDCap credentials, backdoor the application, and search for data tied to drone technology, defense companies, and Chikungunya research. — Organizations running REDCap in healthcare, research, government, or defense-adjacent environments should treat this as a high-priority intrusion risk and investigate for compromise, not just patch. The campaign shows long-term espionage against sensitive medical and military research, including theft from email and internal systems.
Sources: PRC-linked spies hid inside medical and military networks for more than a year, snooping through Gmail and stealing data, Chinese hackers breach REDCap servers, steal medical research, Chinese Hackers Target Medical, Military, and AI Research in North America (+1 more)
Microsoft says USB shortcut worm is spreading crypto-stealing clipper malware through infected Windows drives
Microsoft says a Windows malware campaign is spreading through USB drives and stealing cryptocurrency by swapping copied wallet addresses with attacker-controlled ones. The malware uses malicious LNK shortcut files to launch from removable media, hides real documents and replaces them with lookalike shortcuts, propagates to newly connected USB devices, and uses Tor for command-and-control. It also looks for seed phrases and private keys, captures screenshots, and supports remote code execution through JavaScript fetched from a .onion address. — This can hit ordinary users and organizations that still share files by USB, especially anyone handling cryptocurrency wallets or recovery phrases. Defenders should watch for suspicious wscript.exe and cscript.exe activity, Tor proxy traffic such as localhost:9050, and unusual shortcut files on removable drives; users should avoid opening unexpected files from USB media and verify wallet addresses carefully.
Sources: USB worm spreads crypto-stealing malware via Windows shortcut files
DragonForce ransomware used Microsoft Teams relay infrastructure to hide malware traffic in a real attack
DragonForce ransomware operators used Microsoft Teams network relays to disguise malware communications during an attack on a major U.S. services company. Symantec says the attackers deployed a custom Go-based backdoor called Backdoor.Turn that abused Teams' TURN relays (servers that help route traffic when direct connections fail) to mask command-and-control traffic as Microsoft activity. The December 2025 intrusion also used bring-your-own-vulnerable-driver tactics, including HWAuidoOs2Ec.sys, wsftprm.sys (CVE-2023-52271), GameDriverx64.sys (CVE-2025-61155), and K7RKScan.sys (CVE-2025-1055), before data theft and ransomware deployment. — This matters because defenders may see the malware's traffic as legitimate Microsoft Teams activity, making detection and blocking harder during a ransomware attack. Organizations should review Microsoft Teams-related network trust assumptions, hunt for the listed indicators, and prioritize controls against driver-based security-tool tampering and suspicious use of SQL/MSSQL servers.
Sources: Ransomware gang abuses Microsoft Teams relays to hide malicious traffic, Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic, Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack (+1 more)
Rokarolla Android banking trojan targets 217 banking and cryptocurrency apps through fake Chrome and TikTok downloads
A newly reported Android malware strain called Rokarolla is stealing financial data from people who install fake Chrome or TikTok apps from malicious websites. Zimperium says the trojan abuses Android Accessibility permissions, notifications, SMS, and call access, then checks for 217 targeted banking and crypto apps and downloads matching fake login overlays to capture credentials, card data, lock-screen PINs, contacts, SMS, and other device data. The malware also uses 137 command-and-control instructions and can disable Google Play Protect and hide its icon. — This can let criminals take over phones and drain financial accounts, especially when victims sideload apps outside Google Play. Android users should avoid APKs from unofficial sites, review Accessibility requests carefully, and treat unexpected prompts to install Chrome, TikTok, or security updates as suspicious.
Sources: New Rokarolla Android malware targets 217 banking, crypto apps, Rokarolla Banking Trojan Targets 200 Applications
Researcher releases RoguePlanet Windows zero-day that can give SYSTEM access on patched Windows 10 and 11
A security researcher published a new Windows zero-day exploit that can give an attacker full SYSTEM privileges on fully patched consumer PCs. The proof-of-concept, dubbed RoguePlanet, abuses a race condition in Microsoft Defender to achieve local privilege escalation on Windows 10 and Windows 11 systems with June 2026 updates installed; the researcher says earlier versions also enabled remote code execution through malicious .vhd(x) files on remote SMB shares and BitLocker bypass paths, but the currently released exploit is validated primarily as local escalation and reportedly does not yet work on Windows Server. — This matters because a public exploit can help malware or intruders turn limited access on a Windows machine into full control even after current patches are installed. Organizations should watch for Microsoft guidance, restrict untrusted SMB and disk-image handling where possible, and prioritize detection for SYSTEM-level escalation from Defender-related activity.
Sources: New Windows Zero-Day Exploit ‘RoguePlanet’ Released, Angry bug hunter with Microsoft beef drops new Windows 0-day, ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker (+2 more)
Malicious JetBrains Marketplace plugins stole OpenAI, DeepSeek, and other AI API keys from developers
At least 15 plugins listed in the JetBrains Marketplace were built to steal AI service API keys from developers who installed them. Aikido Security says the plugins, published under seven vendor accounts since October 2025 and still appearing as late as June 10, 2026, exfiltrated keys entered into plugin settings to a hardcoded server over HTTP, including credentials for OpenAI, DeepSeek, and SiliconFlow. The plugins reportedly posed as AI coding assistants, code-review tools, and Git utilities, with nearly 70,000 total downloads claimed across the set. — Developers and organizations using JetBrains IDEs may have had sensitive AI credentials stolen, creating risk of unauthorized model access, data exposure, and billing abuse. Affected users should remove the named plugins, rotate exposed API keys immediately, and review usage logs and downstream secrets access.
Sources: Malicious JetBrains Marketplace plugins steal AI API keys from developers, Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
Attackers use FortiClient EMS zero-day CVE-2026-35616 to push infostealer malware to managed devices
Attackers are using a critical Fortinet server flaw to send malware to computers managed by FortiClient Endpoint Management Server (EMS). The issue, CVE-2026-35616, is a remote code execution bug in FortiClient EMS that can be exploited without authentication via crafted requests; Fortinet patched it in April after warning it had already been used as a zero-day, and Arctic Wolf now says fresh attacks are abusing EMS scripting workflows to deploy EKZ Infostealer disguised as a Fortinet patch. — This can turn a central management server into a way to infect every device it manages, putting passwords, browser cookies, and other sensitive data at risk. Organizations running FortiClient EMS should patch immediately, check for suspicious PowerShell/script activity, and investigate whether fake update jobs were pushed to endpoints.
Sources: Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks, Hackers exploit FortiClient EMS flaw to push infostealer malware, FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch (+2 more)
Mini Shai-Hulud supply-chain attack compromises 320+ npm packages in @antv namespace via stolen maintainer account
Researchers say a compromised npm maintainer account ('atool') was used to publish hundreds of malicious package versions across the @antv namespace, including downstream widely used packages such as echarts-for-react and timeago.js. The payload steals GitHub Actions secrets and credentials from cloud, Kubernetes, Vault, wallet, and developer-tool paths, exfiltrates data via GitHub and fallback infrastructure, and can republish tampered packages using stolen npm tokens. Reports also link the campaign to malicious PyPI uploads, a compromised GitHub Action, and a VS Code extension. — This is a high-impact ecosystem compromise with downstream risk to developer workstations, CI environments, and software consumers through trusted package updates. Defenders should immediately identify affected package versions, rotate exposed secrets and npm tokens, review CI runners and GitHub repositories for exfiltration, and block known malicious artifacts.
Sources: Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack, Shai-Hulud copycat worm infects yet another npm package, TanStack weighs invitation-only pull requests after supply chain attack (+3 more)
Shai-Hulud supply-chain attack trojanizes 19 PyPI bioinformatics packages to steal developer and cloud secrets
Attackers compromised 19 Python packages on PyPI, including popular science and bioinformatics tools, and planted malware that can steal secrets from developer machines and continuous integration systems. Socket linked the activity to the broader Shai-Hulud campaign and said 37 malicious releases used executable .pth startup hooks to trigger code when Python starts, then fetched the Bun JavaScript runtime to run an obfuscated payload that targeted GitHub, npm, PyPI, AWS, GCP, Azure, Kubernetes, SSH, Docker, Vault, and Claude/MCP credentials. — Developers, researchers, and organizations using these packages may have had passwords, tokens, and cloud keys stolen without obvious signs. Anyone who installed affected versions should treat the environment as compromised, rotate secrets, and rebuild from known-good backups.
Sources: New Shai-Hulud attack trojanizes 19 science-focused PyPI packages, Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks, The ‘Miasma’ worm source code briefly leaked on GitHub (+1 more)
Fake recruiter used a malicious GitHub repo and npm install hook to target a developer with backdoor malware
A developer says a supposed recruiter tried to trick him into reviewing a booby-trapped code repository that would have infected his system. The attack used a GitHub-hosted Node.js project whose package.json contained a prepare post-install hook, so running npm install would execute app/test/index.js; that script used an obfuscated URL and remote command execution logic to fetch and run attacker-supplied code. — This is a real-world example of job-lure social engineering aimed at developers, where normal review steps like cloning a repo and installing dependencies can trigger compromise. Developers and employers should treat unsolicited coding tests and recruiter-supplied repositories as high risk, inspect package scripts before running them, and use isolated analysis environments.
Sources: Python dev saved from disaster by intuition...and AI, Python dev saved from disaster by intuition... and AI
Steam Workshop malware campaign used Wallpaper Engine uploads to infect users with stealers, backdoors, miners, and ransomware
Attackers used Steam Workshop uploads for the Wallpaper Engine app to trick Steam users into installing malicious wallpapers. Kaspersky says the abuse has been active since at least late 2025 and relies on Wallpaper Engine's 'application wallpaper' feature, which can run Windows executables as desktop backgrounds. Researchers found dozens of malicious uploads delivering DarkKomet, Lumma, Vidar, cryptominers, botnet loaders, RanEngine, and some ransomware, with some downloads reaching the thousands or tens of thousands before Valve removed the identified items. — This matters to Steam users because installing what looks like harmless custom content can lead to stolen game accounts or full device compromise. Users who installed Wallpaper Engine content from Steam Workshop should review their systems for malware, change Steam credentials, and be cautious with executable community uploads.
Sources: Steam Workshop abused to spread malware via Wallpaper Engine app
Atomic Arch supply-chain attack floods Arch Linux AUR with 1,500 malicious packages
Attackers uploaded more than 1,500 malicious packages to Arch Linux’s user-run AUR repository, putting users at risk if they installed poisoned software. Arch Linux suspended new AUR account registrations while cleaning up the ongoing 'Atomic Arch' campaign. Researchers say attackers first modified abandoned packages, then added new ones, using altered PKGBUILD install scripts to fetch malicious npm and later Bun-based components that appear designed to steal credentials, SSH artifacts, Vault tokens, browser cookies, and to gain stealthy persistence through eBPF, a Linux kernel technology. — Arch Linux users who installed affected AUR packages should treat those systems as fully compromised, rebuild from clean media, and rotate credentials and secrets. This matters because AUR is widely used for unofficial software and the malware appears built for stealth, persistence, and secret theft rather than a one-off nuisance.
Sources: Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
China-linked Earth Lusca used new Windows SprySOCKS malware variants against government organizations in four countries
Researchers say a China-linked hacking group used new Windows versions of the SprySOCKS backdoor to attack government organizations in Taiwan, Thailand, Pakistan, and Honduras. ESET attributes the activity to Earth Lusca, also tracked as FishMonger, and says the malware includes two Windows variants, WIN_DRV and WIN_PLUS, with capabilities such as file theft, keylogging, process control, SOCKS proxying, and stealth features through a kernel driver. The more advanced variant also used a driver signed with a leaked certificate from the PastDSE project, and ESET saw signs of a possible UEFI bootkit component linked to CVE-2023-24932, though that part was not confirmed. — This matters because it shows a state-linked espionage group expanding from Linux to Windows with stealthier tools for long-term access to government networks. Government, foreign-affairs, technology, and telecom defenders should hunt for the published indicators of compromise, review persistence mechanisms such as scheduled tasks and print processors, and check for Secure Boot-related abuse.
Sources: Windows version of SprySOCKS Linux malware used to attack govt orgs, China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
Cyberattack on Astral disrupted tax reporting and business services for Russian government and enterprise customers
Russian software company Astral said a cyberattack knocked multiple services offline for about a week, disrupting customers that depend on its tools for tax reporting, electronic document management, cash-register operations, and digital-certificate logins. Astral said Russian government agencies are investigating, that it is restoring systems only after security reviews, and that it found no evidence so far of customer-data theft. The company did not name an attacker or disclose technical details about the intrusion. — This is a significant service-disruption incident affecting organizations that rely on Astral for core business and government workflows, even without confirmed data theft. Customers should review continuity plans, monitor vendor guidance, and verify the integrity of certificate-based access and connected business processes as services return.
Sources: Cyberattack on Russian tech firm Astral disrupts business, government services for week
More than 400 Arch Linux AUR packages were hijacked to install a Linux rootkit and credential-stealing malware
More than 400 community packages for Arch Linux were modified to infect users with malware that steals passwords, tokens, and developer secrets. The attack hit the Arch User Repository (AUR), where a spoofed maintainer and hijacked orphaned packages were used to add install scripts that fetched a malicious npm package named atomic-lockfile. Researchers say the payload includes a Linux infostealer and optional eBPF rootkit features, with theft targets including GitHub, npm, SSH, HashiCorp Vault, Docker, browser cookies, and Slack, Discord, Teams, and Telegram data. — Arch users and developers who installed affected AUR packages may have exposed account credentials and system access, especially on developer workstations and build environments. Review the affected package list and indicators of compromise, remove malicious packages, rotate exposed secrets, and investigate for root-level persistence.
Sources: Over 400 Arch Linux packages compromised to push rootkit, infostealer, 400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer, Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit (+1 more)
Ukrainian man pleads guilty in U.S. over role in Conti ransomware attacks
A Ukrainian national has pleaded guilty in the United States for helping carry out Conti ransomware attacks that hit victims in the U.S. and other countries. The Justice Department said Oleksii Lytvynenko admitted joining the Conti conspiracy in 2021, possessing data stolen from 12 victims, and helping code a loader, malware used to install tools needed for ransomware intrusions. Prosecutors say Conti targeted more than 1,000 victims worldwide and collected over $150 million before the group fragmented in 2022. — This matters because Conti was one of the most damaging ransomware groups of its era, and the case adds concrete attribution and operational detail defenders can use to understand how these attacks were carried out. It also shows continued law-enforcement pressure on the people behind major ransomware campaigns and their successor groups.
Sources: Ukrainian national pleads guilty to role in Conti ransomware operation, Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges
Belarus-linked GhostWriter uses fake Prometheus training certificates to phish Ukrainian government officials
Belarus-linked hackers are sending fake course-certificate emails to Ukrainian government staff to infect their computers with espionage malware. CERT-UA says the campaign, active since spring 2026, uses compromised email accounts and messages posing as Ukraine’s Prometheus learning platform; a PDF leads victims to a ZIP that installs OysterFresh, then OysterBlues and OysterShuck, which collect host and user details and may later deliver Cobalt Strike. — This is a targeted government espionage campaign, so affected organizations should treat related Prometheus certificate emails as suspicious, hunt for the named malware and infrastructure, and isolate infected systems quickly. For users, the practical takeaway is not to open certificate attachments or download archives from unexpected training-platform emails, even if they come from known contacts.
Sources: Belarus-linked hackers use fake training certificates to target Ukrainian officials, Belarus-linked hackers target Gmail accounts of Polish public figures and their families
Group-IB links thousands of fake FIFA World Cup 2026 domains to fraud campaigns targeting ticket buyers
Researchers say multiple criminal groups have built fake FIFA websites to steal World Cup fans’ passwords, payment details, and money through bogus ticket sales. Group-IB identified four separate campaigns since August 2025, including a Chinese-speaking operation it calls GHOST STADIUM that uses more than 300 active lookalike domains and roughly 3,800 dormant ones. The phishing kit closely copies FIFA’s login flow, can trigger password-reset steps to lock victims out, and is being promoted through Facebook ads offering unrealistically cheap tickets. — Fans trying to buy 2026 World Cup tickets could lose their accounts, have legitimate tickets resold, or pay scammers for fake seats. Users should only type fifa.com directly into their browser, avoid ad-linked ticket offers, and treat lookalike FIFA domains as suspicious.
Sources: Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans, FBI warns of fake FIFA websites running World Cup fraud schemes, In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks (+2 more)
OnyxC2 stealer malware is being sold to cybercriminals as a subscription service
A newly analyzed malware service called OnyxC2 is being rented to criminals for as little as $250 a month, giving buyers a ready-made tool to steal passwords, cookies, wallet data, and other sensitive information from infected Windows systems. BlackFog says the stealer targets about 210 applications and browser extensions across browsers, password managers, cryptocurrency wallets, FTP and email clients, and some 2FA extensions, and uses encrypted payloads, DLL sideloading, in-memory execution, HVNC hidden remote control, keylogging, reverse proxying, and LSASS dumping to evade detection and maintain access. — This lowers the barrier for account theft and follow-on fraud or intrusion by packaging advanced credential-stealing and remote-access features as a commercial criminal product. Organizations and consumers should treat it as a high-risk infostealer threat: watch for suspicious installers, strengthen endpoint detection, and rotate credentials and session tokens if infection is suspected.
Sources: OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month
China-linked JDY botnet grows and expands reconnaissance targeting of U.S. military networks
Researchers say the China-linked JDY botnet has grown to more than 1,500 compromised small-office/home-office and internet-connected devices and is increasingly used to probe U.S. military and related networks. Black Lotus Labs says JDY is tied to China-nexus activity previously associated with Volt Typhoon and is used for distributed scanning, banner grabbing, TLS certificate collection, and fingerprinting to find vulnerable systems soon after flaws are disclosed, including scans for FortiClient EMS bug CVE-2026-35616. The botnet uses infected routers and IoT devices from vendors including Cisco, Ubiquiti, DrayTek, Hikvision, Linksys, Araknis, and Mimosa, with command-and-control routed through Tor hidden services. — This matters because compromised routers and IoT gear are being used to quietly map weak points in networks tied to sensitive U.S. targets, helping follow-on intrusions. Organizations should patch exposed network devices quickly, reduce internet-facing services, and watch for scanning and unusual activity from SOHO and IoT infrastructure.
Sources: China-linked JDY botnet expands targeting of U.S. military networks, China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance, Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate
Red Hat says more than 30 npm packages were backdoored to steal developer and cloud credentials
More than 30 npm packages in Red Hat's @redhat-cloud-services namespace were compromised and used to deliver credential-stealing malware to developers who installed them. Researchers say attackers likely took over a Red Hat employee GitHub account, added malicious GitHub Actions workflows, and abused npm trusted publishing to release 96 backdoored package versions. The malware, a new Shai-Hulud variant dubbed Miasma, targeted GitHub Actions secrets, cloud credentials, SSH keys, package publishing tokens, Vault tokens, Kubernetes service-account tokens, Docker credentials, GPG keys, and .env files. — Developers and organizations that installed the affected packages may have had sensitive keys and tokens stolen, which can lead to wider compromise of code, cloud systems, and build pipelines. This is urgent: identify affected installs, remove the packages, and rotate all credentials and secrets that were present on impacted machines or CI/CD systems.
Sources: Red Hat npm packages compromised to steal developer credentials, Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week, Supply Chain Attack Hits 32 Red Hat NPM Packages (+3 more)
SiribClone uses fake romance and aid lures on Telegram to spy on Russian soldiers with SafeLoveStealer and SiribGrabber malware
Hackers posing as women seeking relationships or volunteers offering help tricked Russian military personnel into installing spyware or surrendering their Telegram accounts. Researchers at F6 say the previously undocumented SiribClone group has operated since at least summer 2025, targeting troops in border regions and combat zones with Android spyware dubbed SafeLoveStealer, desktop malware called SiribGrabber, and phishing sites masquerading as Telegram logins, invite pages, medical portals, and other services to steal messages, files, location data, and microphone audio. — This is an active espionage campaign aimed at people in combat zones and shows how romance lures and fake support offers can turn personal chats into battlefield surveillance. Anyone in sensitive roles should treat unsolicited Telegram contacts, app downloads, and login pages as high risk, avoid sideloading apps, and use phishing-resistant account protections where possible.
Sources: Hackers pose as women seeking romance to spy on Russian soldiers
Suspected North Korean phishing campaign sends fake developer job offers to steal credentials and cryptocurrency
A likely North Korean-linked group sent more than 250 fake job and code-review emails to developers at nearly 100 organizations, mainly in the United States, to steal login credentials and cryptocurrency wallets. Proofpoint tracks the activity as UNK_DeadDrop and says the attackers used spoofed company brands and attacker-controlled GitHub repositories posing as coding tests or crypto projects; victims were told to clone and open the repos in tools such as Visual Studio Code or Cursor, triggering cross-platform malware on macOS, Linux, and Windows. — Developers and the companies that employ them are the direct targets, and a single successful lure can expose source code, cloud access, and crypto assets. Organizations should warn staff about unsolicited recruiting emails, scrutinize GitHub-based coding tests, and isolate or block unknown repositories and scripts.
Sources: Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
NFCShare Android malware uses fake banking app updates on GitHub to steal payment card data from European bank customers
Attackers are tricking bank customers into installing fake Android banking app updates from GitHub so they can steal card data and PINs. D3Lab says newer NFCShare variants, seen since May 14, target banks mainly in Italy and Spain after victims visit phishing sites impersonating real banks. The malware abuses near-field communication (NFC) on Android to read card details via IsoDep and EMV commands, then sends the data to command-and-control servers over WebSocket. — This can lead directly to payment-card fraud because victims are persuaded to hand over both card details and their PIN during a fake security check. Android users should only install banking apps from Google Play and treat any request to scan a bank card with their phone or sideload an update from GitHub as suspicious.
Sources: NFCShare Android malware spreads via fake banking app updates on GitHub
C0XMO Gafgyt botnet exploits DD-WRT router flaw CVE-2021-27137 to spread across routers and IoT devices
A new botnet called C0XMO is infecting DD-WRT routers and other internet-connected devices so they can be used in denial-of-service attacks. Fortinet says the malware exploits CVE-2021-27137, an unauthenticated buffer overflow in DD-WRT, and also brute-forces Telnet and SSH logins while carrying binaries for multiple CPU architectures including ARM, MIPS, PowerPC, x86, and x86_64. The botnet establishes persistence with cron jobs and startup-file changes, then removes rival malware and tooling from infected systems. — Organizations and users with exposed routers, DVRs, and similar devices may be silently pulled into a botnet and used in attacks. Patch affected firmware where available, disable unnecessary remote administration, and change weak or reused device credentials immediately.
Sources: C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
China-linked UNC5221 used Brickstorm, Plenet and AgentPSD malware to keep long-term access to victim networks and Microsoft 365
A China-linked espionage group kept access to a victim organization and its managed services provider for at least 18 months, using multiple backdoors to return even after cleanup. Volexity says UNC5221, also tracked as VerdantBamboo, used Brickstorm on Egnyte Storage Sync, pfSense, Synology NAS and a retired Linux email server, then used Plenet (also called Grimbolt) and AgentPSD to maintain persistence and reach the victim’s Microsoft 365 environment through stolen credentials and SSL VPN access. No new CVE is named in this report. — Organizations using Microsoft 365, MSPs, and internet-facing edge devices should treat this as a reminder that sophisticated attackers can survive remediation and re-enter through trusted providers. Review VPN and firewall changes, hunt for Brickstorm/Plenet/AgentPSD, audit MSP access paths, and rotate credentials and tokens tied to compromised systems.
Sources: Chinese APT deploys new malware to keep access to hacked networks
Microsoft links GPU cryptojacking malware campaign to poisoned search results and AI chatbot software recommendations
Attackers are tricking people looking for popular PC utilities into installing malware that secretly uses their graphics cards to mine cryptocurrency. Microsoft says the campaign uses search-engine optimization (SEO) poisoning and, in some cases, attacker-controlled links surfaced in AI chatbot responses for tools such as CrystalDiskInfo, HWMonitor, FurMark, K-Lite Codec Pack, PDFgear, and Display Driver Uninstaller. The fake downloads bundle a legitimate program with a malicious dynamic-link library (DLL), install ScreenConnect for remote access, add multiple Windows persistence mechanisms, evade Microsoft Defender, and then deploy GPU miners including gminer, lolMiner, and SRBMiner-MULTI. — This campaign targets owners of powerful Windows systems and can leave victims with both hijacked hardware and a remote-access backdoor for follow-on attacks. Users and defenders should avoid downloading software from AI-generated or unfamiliar links, verify vendor domains, and hunt for the listed indicators of compromise and unauthorized ScreenConnect installs.
Sources: GPU mining malware spreads via SEO poisoning, AI chatbots, In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
Sophos says ransomware operator used AI agents from Cursor and Claude to build EDR-evasion and Active Directory attack tools
Sophos says it found a ransomware attack toolkit in a customer environment that was built with help from AI coding agents and used to hide from security software and map a victim's Windows network. The framework included Cobalt Strike traffic-masking profiles, Telegram-based command and control, a Cloudflare Worker redirector, and Python tools that generated Rust and Go payloads for evasion and execution. Sophos found operator logs referencing a ransom note and organizations listed on a ransomware leak site, indicating criminal use rather than legitimate red-team testing. — This shows AI tools are being used to speed up real ransomware tradecraft, especially defense evasion and internal network discovery. Defenders should review detections for Telegram and Cloudflare-backed command channels, unusual payload loaders, and suspicious Active Directory reconnaissance, and treat AI-assisted malware development as an operational threat rather than a theory.
Sources: AI-built ransomware toolkit automates EDR evasion, AD discovery, In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
Hola Browser for Windows supply-chain compromise delivered a Monero cryptominer to some users
Hola says its Windows browser installer was compromised and, in some cases, delivered hidden mining malware to users. AppEsteem certification checks and analysis by Sophos found an undeclared executable, 'me.exe,' installed under the Hola program folder; the binary was unsigned, obfuscated, added a Microsoft Defender exclusion, copied itself as 'HolaMonitorService.exe,' created the 'hola_monitor_svc' Windows service for persistence, and appeared to mine Monero when the PC was idle. Hola said about 0.1% of users were affected and that it rebuilt its distribution pipeline after separately confirming the compromise with Sygnia. — People who installed Hola Browser on Windows may have unknowingly run malware that abuses their computer for cryptocurrency mining and weakens local defenses. Affected users and admins should treat this as urgent: verify installations, look for the named files and service, remove Hola if necessary, and reinstall only from a trusted, verified build.
Sources: Hola Browser for Windows compromised to deliver cryptominer, In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
Magecart campaign uses Google Tag Manager and Stripe API to steal payment cards from Magento checkout pages
Researchers say a new Magecart card-skimming campaign is stealing shoppers’ payment details from compromised online stores and hiding both its malware and stolen data inside trusted Google Tag Manager and Stripe services. Sansec says the skimmer targets Magento and Adobe Commerce checkout pages, pulls JavaScript from a Google Tag Manager container, retrieves payload code from Stripe customer metadata tied to customer ID cus_TfFjAAZQNOYENR, and exfiltrates stolen card, billing, email, and phone data by creating fake Stripe customer records; a variant uses Google Firestore instead of Stripe. The Stripe record was reportedly created on December 24, 2025, suggesting the campaign may have been active for months. — This matters because stores may allow traffic to Google Tag Manager and Stripe by default, letting the skimmer blend in and evade common security controls while stealing card data from real customers. Online retailers using Magento or Adobe Commerce should urgently inspect GTM containers, Stripe API activity, and checkout-page scripts for unauthorized changes.
Sources: Credit card theft campaign abuses Stripe to host stolen payment info
IronWorm malware backdoors 36 npm packages to steal cloud, AI, and developer credentials
Attackers uploaded 36 malicious npm packages carrying a new malware strain called IronWorm, putting developers and continuous integration systems at risk if they installed the poisoned versions. JFrog says the Rust-based malware steals 86 environment variables and 20 credential-file types, including AWS, OpenAI, Anthropic, npm, SSH, vault, and crypto-wallet data; it was first linked to the compromised npm account 'asteroiddao' and can self-propagate by abusing stolen npm publishing and Trusted Publishing secrets to push trojanized package updates. — This can spread from one compromised developer or build system into many other packages and organizations, making it a high-priority software supply-chain threat. Developers and defenders should identify any affected package versions, upgrade to clean releases, rotate exposed credentials, review GitHub Actions and npm publishing tokens, and enforce two-factor authentication.
Sources: New IronWorm malware hits 36 packages in npm supply-chain attack
Proofpoint says TA4922 is targeting European organizations with new Atlas RAT malware and phishing lures
A Chinese-speaking cybercrime group is using new malware and localized phishing messages to break into organizations in Europe and beyond. Proofpoint says TA4922, linked to activity overlaps with Silver Fox and Void Arachne, has targeted entities in Germany, Italy, the United Kingdom, South Africa, and parts of Southeast Asia since March 2026 using payroll, tax, VAT, invoice, and HR lures sent by email and messaging apps including WhatsApp, LINE, and Microsoft Teams. The campaigns deploy Atlas RAT, RomulusLoader, SilentRunLoader, and Winos4.0/ValleyRAT for remote access, file theft, credential theft, keylogging, screenshots, and webcam or audio capture. — Organizations in the targeted regions should treat this as an active intrusion and phishing threat, especially finance, HR, and compliance teams that may receive convincing local-language messages. Defenders should hunt for the named malware families and remote-management tools, tighten phishing controls, and warn staff to verify unexpected payroll, tax, invoice, or compliance messages across email and chat platforms.
Sources: Chinese hackers use new Atlas RAT malware in European cyberattacks, Chinese Cybercrime Group in Spotlight for Record Campaign Pace, China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa
Espionage hackers spent 150 days inside a senior executive’s email at a major global stock exchange
Hackers secretly monitored and stole email data from a senior executive at a major global stock exchange for about five months. Broadcom’s Symantec and Carbon Black teams said the intrusion began in October 2025 and lasted until March 2026, with malware on the victim’s device disguised as Adobe and OneDrive software, scheduled-task persistence masked as Adobe, Lenovo, and OneDrive services, and exfiltration of Outlook mailbox data in small archives via Dropbox and OneDrive. The initial access method and the victim exchange were not disclosed, but investigators published indicators of compromise. — This is a high-impact espionage case because a stock exchange executive’s mailbox can expose market-moving information, internal deliberations, contacts, and travel details. Financial institutions and other high-value targets should hunt for the published indicators, review executive mailbox and endpoint activity, and scrutinize cloud-storage exfiltration and suspicious scheduled tasks.
Sources: Hackers Target Global Stock Exchange in Espionage Operation, Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Europol-backed Operation KRATOS 2 dismantles nine illegal streaming crime groups across 13 countries
Police in Europe and the United States say they broke up nine organized crime groups running illegal streaming services and arrested 29 suspects. The seven-month Operation KRATOS 2, led by Bulgaria with Europol support, involved 13 countries and led to the removal of more than 27,000 illegal streaming URLs, identification of 18,000 IP addresses tied to illegal services, 4,370 piracy-linked domains, nearly 400,000 additional URLs flagged for suspension, and 126,000 infringing objects. Investigators say the operators split public-facing sites from backend hosting across jurisdictions to evade takedowns. — People using pirate streaming services are not just risking copyright trouble; Europol says these platforms can also expose users to malware, spyware, and theft of personal data. The story matters because it shows the scale and international reach of the criminal infrastructure behind these services, and affected users should avoid such platforms and check devices for suspicious software if they used them.
Sources: Police dismantles 9 crime groups in illegal streaming crackdown
WeedHack malware campaign infects more than 116,000 systems through fake Minecraft mods and cheats
A large malware campaign has infected more than 116,000 computers by tricking Minecraft players into downloading booby-trapped mods, cheat clients, and utilities. McAfee says the WeedHack operation has been active since January 2026, spreads via YouTube links and search-result manipulation, and uses thousands of malicious Java archive (JAR) files. The malware steals browser passwords and cookies, Minecraft session IDs, Discord, Steam and Telegram credentials, and crypto-wallet data, while paid tiers add remote-control features such as keylogging, webcam access, shell access, and file management. — This is a broad consumer-focused infostealer campaign hitting gamers at scale, with stolen passwords, session tokens, and wallet data creating immediate account-takeover and financial risk. Minecraft players and parents should avoid unofficial mod download sites, remove suspicious JAR files, run antivirus scans, and reset passwords for any accounts used on affected devices.
Sources: Over 116,000 Mincraft systems infected in WeedHack malware campaign, Over 116,000 Minecraft systems infected in WeedHack malware campaign
DriveSurge hijacks thousands of legitimate websites to push ClickFix and fake browser update malware
A threat actor called DriveSurge has compromised thousands of real websites and is using them to redirect visitors into malware traps. Silent Push says the actor operates as an initial access broker, using the zTDS traffic distribution system to decide whether each visitor sees a ClickFix lure that tricks them into running malicious PowerShell commands or a FakeUpdate page posing as browser updates for Chrome, Firefox, Edge, Safari and others; researchers also found macOS-targeting JavaScript and more than 80 malicious injection domains. — People can get infected just by visiting a legitimate site that has been silently hijacked, so the risk extends beyond obviously shady pages. Organizations should hunt for the identified JavaScript injection patterns and domains, and users should only update browsers through the built-in updater and never paste commands from pop-ups into Terminal or PowerShell.
Sources: Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
Dutch police say they disrupted a botnet of at least 17 million infected devices after tracing 200 servers in the Netherlands
Dutch police say they helped dismantle a botnet made up of at least 17 million compromised devices, with 200 supporting servers traced to the Netherlands and seized or shut down with help from a hosting provider. Authorities and NCSC-NL did not name the botnet or specify the exact malware family, but said affected devices likely included poorly secured routers, mobile devices, and Internet of Things hardware commonly abused for phishing, distributed denial-of-service attacks, and online fraud. — A botnet this large can be used to hide attacks, knock services offline, and abuse ordinary people's devices without their knowledge. Users and organizations should check internet-connected devices for updates, replace default passwords, and avoid unofficial app sources while defenders watch for follow-on indicators once police release more details.
Sources: Dutch cops wrest 17M devices from mystery botnet's clutches, Dutch govt disrupts malware botnet with 17 million infected devices, Dutch Police Dismantle Massive 17-Million-Device Botnet
Malware on nearly 2,000 WordPress sites used Steam profiles to hide command data and maintain backdoor access
A long-running malware campaign infected about 1,980 WordPress websites and hid its command-and-control data inside Steam Community profile comments. GoDaddy says the malware, tracked since July 2025, uses invisible Unicode characters in Steam comments to encode a payload that builds a hello-mywordl[.]info URL, then injects JavaScript disguised as common libraries and installs a PHP backdoor that executes code sent in specially crafted POST requests with a specific cookie. The initial compromise route is unknown but may involve stolen WordPress or FTP credentials, vulnerable themes or plugins, or a supply-chain compromise. — WordPress site owners and hosting teams should treat this as an active website compromise, not just a nuisance script, because it includes a persistent backdoor that can reinfect a site if cleanup is incomplete. Check for outbound requests to Steam from WordPress servers, suspicious JavaScript injections, and restore from a known-good backup where possible.
Sources: WordPress malware campaign hides payloads in Steam profiles
Suspected Pakistan-linked SideCopy phishing campaign targets Afghanistan finance officials with XenoRAT malware
Afghan Ministry of Finance and provincial government officials were targeted in a phishing campaign that installed remote-access malware on victims' computers. Seqrite attributed the activity with medium-to-high confidence to the Pakistan-linked SideCopy group, which used Pashto-language lure documents inside ZIP archives and delivered them through compromised Afghan government server infrastructure; opening the file installed XenoRAT, a remote access trojan, which then contacted attacker-controlled servers in Europe. — This matters because it shows a suspected state-linked espionage operation aimed at government financial and provincial officials, using trusted local-language lures and compromised government infrastructure to improve success. Afghan public-sector defenders should investigate suspicious ZIP attachments, review access to government-hosted domains, and hunt for XenoRAT-related activity.
Sources: Afghan finance officials targeted by suspected Pakistani cyberespionage campaign
Microsoft says 14 malicious npm packages impersonated OpenSearch and Elasticsearch libraries to steal cloud and CI/CD credentials
A single attacker published 14 malicious npm packages that pretended to be OpenSearch, Elasticsearch, and related developer tools, putting developers and build systems at risk of secret theft. Microsoft said the packages were uploaded under the alias "vpmdhaj" and used typosquatting, spoofed metadata, and inflated version numbers; on install, preinstall hooks fetched a second-stage credential harvester targeting Amazon Web Services, HashiCorp Vault, GitHub Actions, and npm tokens. The packages were removed after publication. — Anyone who installed or built these packages may have exposed credentials that can be reused to access cloud accounts, code pipelines, and package publishing systems. Organizations should identify affected installs from May 28 onward, rotate AWS Identity and Access Management or Security Token Service credentials, Vault tokens, npm publish tokens, and GitHub Actions secrets, and review for follow-on compromise.
Sources: Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
Attackers abuse ChatGPT share links and Google ads to deliver malware through fake OpenAI outage pages
Attackers are using legitimate ChatGPT share links to show fake OpenAI outage notices that tell people to download a bogus ChatGPT desktop app. Push Security says the LLMShare campaign buys Google ads for ChatGPT searches, serves the lure from chatgpt.com/s/ pages rendered with custom HTML and CSS inside ChatGPT, then redirects victims to openew[.]app, which offers cloaked Windows and macOS malware downloads; the Windows sample checks whether it is running on a real device or a virtual machine. — This matters because the scam is hosted partly on a real OpenAI domain, making it more convincing to ordinary users and harder for defenders to spot. Users should avoid sponsored results for AI tools, download apps only from the official vendor site or app store, and security teams should monitor for chatgpt.com share-link abuse and block the impersonation domain.
Sources: ChatGPT share links abused to host fake outage pages to deliver malware
WithSecure links new Russia-aligned GreyVibe campaign to phishing and malware attacks on Ukrainian targets
Researchers say a previously undocumented Russia-linked group called GreyVibe has targeted Ukrainian military, government, civilian, and business organizations since August 2025. WithSecure says the actor used at least six spear-phishing campaigns, fake adult-club websites, Telegram and dating-site lures, and file-sharing links to deliver PhantomRelay and LegionRelay malware on Windows and Fallspy on Android; the report also says the group used ChatGPT, Gemini, Ideogram, and other generative artificial intelligence tools across lure creation, malware development, obfuscation, and post-compromise tooling. — This matters because it describes an active espionage-focused campaign against Ukrainian targets and shows how lower-sophistication operators can use generative artificial intelligence to scale convincing phishing and malware operations. Organizations supporting Ukraine should review indicators, harden email and mobile defenses, and warn users about archive-based lures, fake personas, and links delivered over chat and dating platforms.
Sources: Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks, GreyVibe hackers use ChatGPT, Gemini to power cyberattacks, Russia-linked threat group put ChatGPT to work from lure to payload
ESET warns BTMOB Android malware sold as a kit can steal data and remotely control infected phones
A newly highlighted Android malware family called BTMOB can give criminals broad control over infected phones, including stealing data and taking over the device. ESET says the remote access trojan (RAT) is spread through phishing pages and fake app stores, abuses Android Accessibility Services to gain elevated privileges, and is sold with an APK-building kit that lets buyers customize lures by country and brand. The campaign has mainly been observed in Latin America. — This is more serious than a typical banking trojan because it can turn an Android phone into a remotely controlled spying and theft tool. Android users should avoid app downloads from links in messages or fake stores, and defenders should watch for phishing infrastructure and abuse of Accessibility permissions.
Sources: New BTMOB Android Malware Enables Full Device Takeover, BTMOB Android malware service generates custom phishing payloads
CrowdStrike, Google and Shadowserver disrupt GlassWorm botnet targeting Visual Studio, npm, PyPI and GitHub developers
Security firms say they disrupted the GlassWorm botnet, a malware operation that infected developers and open source software ecosystems and could be used to steal credentials, cryptocurrency wallet data, and remote access to infected machines. CrowdStrike says GlassWorm spread through trojanized Visual Studio extensions on OpenVSX and later through GitHub and compromised Python projects, while using Solana blockchain transactions, Google Calendar, BitTorrent and VPS-hosted servers as layered command-and-control channels. The malware hid code with Unicode variation selectors and stole npm, GitHub and Git credentials, creating downstream software supply-chain risk. — This matters because a compromise of developers can spread to the software and updates many other organizations rely on. Teams should check for beaconing to 164.92.88[.]210, investigate developer machines and repositories for compromise, rotate exposed credentials, and review software supply-chain protections.
Sources: GlassWorm Botnet Disrupted, Glassworm botnet disrupted after resilient C2 infrastructure takedown, CrowdStrike, Google shatter Glassworm botnet
Researchers link LA Metro cyberattack to Iranian government hackers after disruptive March breach
Researchers say the March cyberattack on Los Angeles Metro was likely carried out by Iranian state-linked hackers, not just a self-described hacktivist group. LA Metro said the breach caused internal operational disruption and required hundreds of servers to be checked before restoration, while the attackers claimed to have wiped hundreds of terabytes and stolen more than 1 terabyte of data. Gambit linked the operation to infrastructure associated with Black Shadow, a group previously attributed to Iran's Ministry of Intelligence and Security, and said the attackers also accessed systems including virtualization management, Microsoft IIS servers, and a train-monitoring operational technology system. — A breach at a major transit agency raises concern not only about data theft but also about disruption to public services and potential access to operational systems. Transit operators and other public-sector defenders should review exposure of administrative platforms and monitoring systems, hunt for data theft and destructive activity, and treat claimed hacktivist incidents as possible state-backed operations.
Sources: LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers, Iranian intelligence service behind hack of LA transit system, researchers say
Attackers exploited KnowledgeDeliver zero-day CVE-2026-5426 to install web shells and backdoors on LMS servers
Hackers used a previously unknown flaw in Digital Knowledge’s KnowledgeDeliver learning platform to break into servers and plant persistent malware. Mandiant says CVE-2026-5426 affects KnowledgeDeliver deployments before February 24, 2026, because a standardized ASP.NET web.config file contained hardcoded machineKey values, enabling ViewState deserialization attacks for remote code execution. The observed intrusions deployed Godzilla web shells, altered JavaScript to show fake plugin alerts, and ultimately installed a tailored Cobalt Strike backdoor. — Organizations using KnowledgeDeliver, especially enterprise and education users, may already be compromised, not just vulnerable. Admins should urgently rotate machine keys, restrict access to the LMS, hunt for the published indicators of compromise, and check for web shells, modified JavaScript, and follow-on malware.
Sources: Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment, KnowledgeDeliver flaw exploited as a zero-day to install web shells
Iran-linked Nimbus Manticore targets aviation and software companies with new MiniFast backdoor and fake job lures
An Iran-linked hacking group is using fake job offers and trojanized software downloads to break into aviation and software companies, including targets in Saudi Arabia, Australia, and the United States. Check Point says Nimbus Manticore (also known as Bohrium, TA455, and UNC1549) switched from DLL sideloading to AppDomain hijacking, using malicious .NET configuration files to load payloads, and deployed updated MiniJunk malware plus a new Windows DLL backdoor called MiniFast through ZIP files on OnlyOffice, a fake Zoom installer, and a fake SQL Developer site boosted with search-engine optimization. — This campaign shows continued state-linked targeting of sensitive industries during heightened regional tensions, with lures that can fool both job seekers and employees downloading familiar tools. Organizations in aviation, defense-adjacent, and software sectors should warn staff about recruiter and installer lures, review detections for MiniJunk and MiniFast, and hunt for suspicious .config-based AppDomain hijacking activity.
Sources: Iranian APT Targets Aviation, Software Companies With Updated Tools
Attackers exploit Ghost CMS SQL injection flaw CVE-2026-26980 to booby-trap hundreds of websites with ClickFix malware lures
Attackers are using a Ghost CMS bug to hijack websites and show visitors fake verification prompts that can infect their computers. The campaign abuses CVE-2026-26980, a critical unauthenticated SQL injection flaw affecting Ghost 3.24.0 through 6.19.0, to steal admin API keys and inject malicious JavaScript into article pages; researchers say more than 700 domains were hit, including university, media, fintech, and tech sites. Victims who follow the ClickFix instructions paste commands into Windows that download malware. — This affects both website owners and ordinary visitors: unpatched Ghost sites can be silently turned into malware delivery pages, and people browsing them can be tricked into infecting their own systems. Ghost administrators should update to 6.19.1 or later immediately, rotate exposed keys, and check for injected scripts and suspicious admin API activity.
Sources: Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign, Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
Laravel Lang Composer packages hijacked through rewritten Git tags to deliver credential-stealing malware
Attackers compromised Laravel Lang localization packages and made legitimate-looking Composer installs fetch malware instead. The attackers rewrote existing GitHub release tags across laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and possibly laravel-lang/actions to point to malicious commits in a fork, affecting hundreds of historical versions; the payload drops a PHP stealer that targets cloud keys, CI/CD secrets, SSH keys, browser data, crypto wallets, and on Windows launches a helper executable dubbed DebugElevator to decrypt Chromium-based browser credentials. — Developers and organizations that installed these packages could have had passwords, cloud credentials, and deployment secrets stolen without realizing it. Treat this as urgent: identify affected installs, remove compromised versions, rotate any exposed secrets, and review developer and build systems for follow-on access.
Sources: Laravel Lang packages hijacked to deploy credential-stealing malware, Laravel-Lang Packages Poisoned for Malware Delivery
Megalodon campaign poisons more than 5,500 GitHub repositories to steal CI/CD and cloud credentials
A new automated attack dubbed Megalodon pushed malicious commits to more than 5,500 GitHub repositories, putting developers and organizations that merge those changes at risk of credential theft. Researchers say the malware runs in continuous integration and continuous delivery (CI/CD) pipelines after a poisoned commit is merged, then steals GitHub, Bitbucket, AWS, Google Cloud, Azure, SSH, Docker, Kubernetes, Vault, and Terraform secrets and can spread further; SafeDep also linked backdoored Tiledesk npm releases 2.18.6 through 2.18.12 to a compromised GitHub repository rather than a stolen npm account. — This can turn a routine code merge into a cloud-account and source-code compromise, especially for organizations that automatically build code from GitHub. Repo maintainers and security teams should review recent pull requests and commits, block suspicious automation, rotate CI/CD and cloud secrets, and check whether affected packages or repositories were used.
Sources: Megalodon chums the waters in 5.5K+ GitHub repo poisonings, Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack
Underminr CDN routing flaw lets attackers disguise malicious traffic as connections to trusted domains
Researchers say attackers are exploiting a weakness in shared content delivery network (CDN) infrastructure to make malicious connections look like they are going to legitimate websites. The technique, dubbed Underminr, is described as a variant of domain fronting that abuses mismatches between DNS lookups, server name indication (SNI), HTTP Host headers, edge IP addresses, and CDN tenant routing; ADAMnetworks says it affects roughly 88 million domains and has been used to bypass Protective DNS filtering, conceal command-and-control traffic, and tunnel VPN or proxy connections over TCP port 443. — Organizations that rely on DNS filtering or allowlists could miss malicious outbound traffic that appears to be headed to trusted domains. Defenders should review CDN egress controls, correlate DNS, SNI, Host header, and destination IP telemetry, and watch for guidance or mitigations from affected providers.
Sources: ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains
Canadian police arrest alleged Kimwolf botnet operator over record-scale DDoS attacks
Canadian authorities arrested Ottawa resident Jacob Butler, alleged online as “Dort,” and U.S. prosecutors unsealed charges accusing him of running the Kimwolf Internet-of-Things botnet that hijacked millions of connected devices. The complaint says Kimwolf infected devices such as cameras and digital photo frames, issued more than 25,000 attack commands, powered distributed denial-of-service attacks measured at nearly 30 terabits per second, and was also rented to other criminals; the case follows March seizures of Kimwolf infrastructure and related botnets Aisuru, JackSkid, and Mossad. — This matters to internet providers, enterprises, and anyone running exposed connected devices because it shows how insecure Internet-of-Things products can be turned into large-scale attack infrastructure. Defenders should keep internet-facing devices patched, disable unnecessary exposure, and review mitigations tied to the exploitation path Kimwolf used to spread.
Sources: Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada, US and Canada arrest and charge suspected Kimwolf botnet admin, Canadian Man Arrested for Operating Kimwolf Botnet (+1 more)
China-linked Calypso hackers target telecom providers with Showboat Linux malware and JFMBackdoor for Windows
A China-linked hacking group has been targeting telecommunications providers in Asia Pacific and parts of the Middle East with new malware for both Linux and Windows systems. Researchers at Lumen Black Lotus Labs and PwC attributed the campaign to Calypso, also called Red Lamassu, and say it has been active since at least mid-2022. The Linux implant, Showboat, is a modular post-compromise framework used for persistence, file transfer, and SOCKS5 proxying to move through victim networks, while the Windows implant, JFMBackdoor, uses DLL sideloading and supports remote commands, file operations, registry changes, screenshots, and anti-forensics. — Telecom providers are high-value targets because they sit in the middle of sensitive communications and critical infrastructure. Organizations in the sector should hunt for these malware families and related telecom-themed impersonation domains, review persistence mechanisms and proxy activity, and check Linux and Windows systems for signs of long-term intrusion.
Sources: Chinese hackers target telcos with new Linux, Windows malware
Ukraine identifies infostealer operator linked to theft of 28,000 online store accounts
Ukrainian cyberpolice, working with U.S. law enforcement, identified an 18-year-old suspect from Odesa as a central operator in an infostealer campaign that stole browser sessions and credentials from users of a California online store between 2024 and 2025. Authorities say 28,000 accounts were compromised, 5,800 were used for unauthorized purchases totaling about $721,000, and devices and crypto-related evidence were seized in searches. — The case highlights ongoing risk from infostealers and stolen session tokens, which can enable account takeover and sometimes bypass MFA. Online retailers, fraud teams, and users should treat session theft as a significant threat and review account security, monitoring, and token invalidation practices.
Sources: Ukraine identifies infostealer operator tied to 28,000 stolen accounts, Ukraine probes teen suspect in cyber theft scheme targeting California online shoppers
Microsoft disrupts Fox Tempest code-signing service used by ransomware and malware operators
Microsoft said it seized domains and hundreds of VMs tied to Fox Tempest, a criminal service that abused Microsoft Artifact Signing using more than 580 fraudulent accounts created with fake identities. The operation allegedly sold code-signing certificates used to sign malware including Oyster, Lumma, Vidar, and Rhysida, and was linked to ransomware actors including Vanilla Tempest as well as INC, Qilin, and Akira affiliates. — Trusted code-signing helps malware bypass user suspicion and some security controls, so this service likely enabled broader, more effective intrusions. Defenders should review detections and hunting for suspicious signed binaries and malware families named by Microsoft.
Sources: Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware
SentinelOne details Reaper macOS stealer variant that steals credentials and crypto wallets and installs a persistent backdoor
SentinelOne documented Reaper, an updated SHub macOS infostealer delivered via fake WeChat and Miro installer sites spoofing trusted brands and abusing Script Editor instead of Terminal. The malware steals passwords, browser and Keychain data, Telegram sessions, and cryptocurrency wallet data, injects some wallet apps for continued theft, and installs a LaunchAgent-backed backdoor that beacons to C2 and can execute attacker-supplied code. — macOS users are being targeted with a more evasive stealer that bypasses recent Apple defenses against Terminal-based social engineering. Defenders should block the typosquatted infrastructure, hunt for the fake GoogleUpdate persistence path and LaunchAgent, and warn users about malicious installer lures.
Sources: Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them