tagβMalware
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RATA new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second
New DOUBLECUP ClickFix service hides malware in browser cache imagesA new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems.
Fake Roblox Xeno script launcher pushes infostealer, RAT malwareFake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information.
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected AccountsMalware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareA fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as
Arch Linux disables AUR package adoption to stop malware floodThe Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during testsOne of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing MalwareThreat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.jsBeta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/[email protected] @joyfill/[email protected] The two packages "contain an import-time JavaScript implant that resolves encrypted code
- 1
- 2
- 3
- 4
- 5
- 6
- 132