top of page
ALL POSTS
North Korean Recruitment Campaign Deploys Malware Through Fake Coding Assessments
Key Findings DPRK-aligned group REF9403 running active social engineering campaign targeting software developers with trojanized coding projects Malware payload hidden in SVG image files within legitimate-looking coding repositories, evading antivirus detection Four-part stealer modules collect browser credentials, crypto wallets, developer keys, and grant remote shell access across Windows, macOS, and Linux Campaign active since at least 2022; some victims unknowingly pushed
Jul 253 min read
UAC-0099 Deploys MATCHBOIL.V2 Malware via Counterfeit Notepad++ Plugin
Key Findings UAC-0099, a Russia-aligned threat group active since mid-2022, is distributing MATCHBOIL.V2 malware through trojanized Notepad++ plugins via phishing campaigns Attack chain begins with a phishing email containing an image that, when clicked, downloads a VBScript disguised as a PDF document from a file-sharing service The VBScript downloads Notepad++ version 8.8.3 bundled with a malicious DLL plugin called LUNCHPOKE that establishes persistence through scheduled t
Jul 243 min read
Adobe Acrobat Extension Vulnerability Exposed WhatsApp Web Messages to Malicious Sites
Key Findings Adobe Acrobat Chrome extension vulnerability (CVE-2026-48294, CVSS 7.4) affected 314+ million users and allowed silent theft of WhatsApp Web data Exploitation required only user interaction - visiting a malicious webpage - with no malware, credential theft, or session cookie compromise needed Vulnerability chain consisted of three separately unremarkable flaws in message passing, storage handling, and feature flags that composed into a critical attack Attack coul
Jul 223 min read
Project CAV3RN Abuses Outlook Calendar Events for C2 Communication and Covert Israeli Surveillance
Key Findings Project CAV3RN, an espionage framework targeting Israeli organizations, now uses Outlook calendar events as a command-and-control channel accessed through Microsoft Graph The new AzureCommunication.dll module hides commands in calendar events dated to 2050 to avoid detection; operators use encrypted attachments for payload delivery If Microsoft Graph fails, the malware retrieves backup credentials through DNS AAAA records, using the recovery domain cloudlanecdn[.
Jul 213 min read
LG Monitors Found Auto-Installing Adware via Windows Device Metadata
Key Findings LG monitors automatically install companion software on Windows PCs without user consent, triggering McAfee antivirus advertisements The practice exploits Microsoft's device metadata system, which allows hardware vendors to bundle apps alongside drivers McAfee promotions appeared in 31 of 32 system boots during testing, converting trial subscriptions to paid plans automatically The LG Monitor App Installer runs with full system trust privileges outside Windows se
Jul 213 min read
HollowGraph Malware Exploits Microsoft 365 Events to Conceal C2 Communications and Stolen Data
Key Findings HollowGraph malware uses hijacked Microsoft 365 calendar events dated 2050 as a command-and-control channel, disguising malicious traffic as legitimate Microsoft Graph API activity The .NET implant supports only two commands (get and send) and never connects to attacker-owned servers, instead treating a compromised mailbox calendar as a two-way dead drop Tasking and exfiltrated files are encrypted with hybrid RSA-OAEP and AES-256-GCM encryption, with separate key
Jul 204 min read
SonicWall SMA Zero-Day Chain Exploited to Root VPN Appliances and Deploy Stealth Malware
Key Findings Threat actor UTA0533 exploited a critical zero-day chain in SonicWall SMA 1000 VPN appliances to gain root access Two flaws chained together: CVE-2026-15409 (SSRF in Workplace interface) and CVE-2026-15410 (command injection in management console) Attacker deployed custom malware toolkit including KNUCKLEBALL loader, ORANGETAIL webshell, and Suo5 proxy tool At least two appliances confirmed compromised; exploitation originating from over 200 IP addresses using VP
Jul 194 min read
NadMesh Botnet Targets Exposed AI Services to Steal Cloud Credentials and Kubernetes Tokens
Key Findings Go-based botnet NadMesh emerged in early July targeting exposed AI services including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio Operator dashboard shows 3,811 unique AWS keys harvested with credential theft as primary objective Botnet extracts cloud credentials, Kubernetes service account tokens, Docker configs, and environment variables from compromised hosts Docker API exploitation dominates observed traffic at 30.31%, followed by Jenkins script ex
Jul 184 min read
Russian Threat Actors Deploy Starland RAT Through Counterfeit Video Conferencing Installers
Key Findings Russian-speaking threat actor UAT-11795 has been running a malware campaign since June 2025 targeting users in the U.S. and Europe Campaign distributes trojanized installers for legitimate software including Zoom, Webex, MobaXterm, DBeaver, and FACEIT gaming platform Two newly documented malware families deployed: Starland RAT (Python-based) and WLDR (PowerShell memory-only implant) Initial access achieved through ClickFix social engineering technique Starland RA
Jul 183 min read
ClickFix Campaign Distributes ACR Stealer to Harvest Browser Tokens and Microsoft 365 Credentials
Key Findings ACR Stealer, active since 2024, steals browser passwords, session tokens, PDFs, and Microsoft 365 documents through ClickFix social engineering lures Two distinct delivery chains identified: one leaves disk artifacts, the other operates entirely in memory using steganography and pixel-embedded payloads No vulnerabilities exploited; both chains rely entirely on victims pasting commands into Run boxes or PowerShell Microsoft recommends revoking tokens rather than r
Jul 174 min read
Global SocGholish Takedown: Nearly 15,000 WordPress Sites Cleaned in Major Operation
Key Findings Operation EndGame, a coordinated international law enforcement action, dismantled SocGholish infrastructure on June 18, 2026 106 servers and domains taken down globally; 14,971 compromised WordPress sites remediated Law enforcement from Netherlands, Canada, United States, and Germany executed the coordinated takedown with support from Europol SocGholish serves as initial access broker for major ransomware families including LockBit, RansomHub, and WastedLocker Be
Jun 193 min read
Microsoft Uncovers Windows Clipper Malware Campaign with USB Worm and Tor-Based Command & Control
Key Findings Windows-based clipper malware campaign active since February 2026 targets cryptocurrency wallets through USB-distributed LNK shortcut files Malware uses bundled Tor client with SOCKS5 proxy to communicate with hidden-service C2 servers, avoiding traditional IP-based infrastructure detection Attack chain involves worm component that replicates across USB drives by masking itself as legitimate documents like DOC, XLSX, and PDF files Clipper steals BIP39 seed phrase
Jun 183 min read
Argamal Malware and RAT Discovered Embedded in Trojanized Hentai Games
Key Findings Kaspersky discovered Argamal, a remote access Trojan hidden in hentai game installers, detected in April 2026 The malware is distributed through adult game sites, file-sharing platforms like PixelDrain, and torrent trackers such as AniRena Infected games function perfectly, allowing users to remain unaware their systems are compromised The malware establishes persistence through COM hijacking of Windows Color System Calibration Loader Hundreds of users infected,
Jun 142 min read
Conti Ransomware Member's Guilty Plea Signals Breakthrough in Global Cybercrime Crackdown
Key Findings Ukrainian national Oleksii Oleksiyovych Lytvynenko pleaded guilty to wire fraud conspiracy related to Conti ransomware operations Conti attacked over 1,000 organizations across 47 U.S. states and 31 countries from 2020 to 2022, extorting at least $150 million Lytvynenko joined the conspiracy in September 2021 and developed malware used in the attacks He faces up to 20 years in prison with sentencing scheduled for September 10, 2026 Authorities continue pursuing f
Jun 133 min read
Atomic Arch Campaign Hijacks 400+ Linux AUR Packages to Deploy Infostealer and eBPF Rootkit
Key Findings Over 400 packages in the Arch User Repository (AUR) were hijacked this week with malicious build scripts Attackers modified PKGBUILD files to inject a credential stealer written in Rust that harvests developer secrets The malware can load an eBPF rootkit when running with root privileges to hide its presence Attack targets orphaned packages with abandoned maintainers, then spoofs commit metadata to appear legitimate Malware collects browser cookies, SSH keys, Git
Jun 124 min read
Miasma Worm Supply Chain Attack Compromises 73 Microsoft GitHub Repositories
Key Findings A self-replicating worm called Miasma compromised 73 Microsoft GitHub repositories across Azure infrastructure and core .NET, Go, Java, JavaScript, and Python frameworks GitHub staff disabled affected repositories after attackers injected malicious workflows that harvested OIDC tokens and developer credentials The attack exploited AI coding tools as an automatic execution mechanism, triggering malware when developers cloned infected repos and opened them in IDEs
Jun 93 min read
Operation FlutterBridge: macOS Backdoor Campaign Leverages Fake Google Ads and Targeted Distribution
Key Findings Operation FlutterBridge is a sophisticated malvertising campaign targeting macOS users since late 2025, evolving from basic adware into a dangerous backdoor called FlutterShell Threat actors use fake shell companies to purchase verified Google and YouTube ads, bypassing security filters through artificial aging and legitimate developer credentials The malware masquerades as productivity tools including Podcasts Lounge, PDF-Brain, and PDF-Ninja, with three distinc
Jun 83 min read
PyPI Supply Chain Attack Exploits Malware Startup Hooks at Scale
Key Findings Coordinated PyPI supply chain attack compromised multiple popular open-source packages through maintainer account takeover Malware uses Python startup hooks (.pth files) to execute automatically during installation without requiring explicit package imports 448 affected artifacts identified spanning both npm and PyPI registries Threat actors dubbed the Hades cluster, part of broader Shai-Hulud and Miasma malware lineage Socket malware detection systems identified
Jun 73 min read
Critical Miasma Worm Campaign Targets Microsoft and Red Hat in Expanding Supply Chain Attack Wave
Key Findings Miasma worm infected 73 Microsoft GitHub repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations, forcing GitHub to disable access Attack represents re-compromise of previously infected "durabletask" PyPI package, suggesting threat actors maintained persistent access for over a month Miasma operates as self-replicating malware variant of Mini Shai-Hulud worm, exploiting the trust model of package registries rather than technical vulne
Jun 64 min read
China-Linked TA4922 Hackers Deploy SilentRunLoader Malware Against UK and European Targets
Key Findings TA4922, a suspected China-aligned cybercrime group, has expanded operations from East Asia to target organisations in the UK, Germany, Italy, and South Africa The group uses locally-tailored phishing emails impersonating tax authorities, benefits services, and government agencies to increase open rates SilentRunLoader, a new Python-based malware likely developed with LLM assistance, steals Chrome credentials, cookies, and browsing data TA4922 employs a diverse to
Jun 32 min read
bottom of page
