-
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed Windows malware. The campaign used a fake Web3 recruitment process to deploy a three-payload s…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The ChainDrop campaign has exposed a gap in modern software supply-chain defenses: malware no longer needs a durable npm publishing token or even an npm install event to spread through developer environments. The self-propagating npm worm, also tracked…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Four incidents involving OpenAI, Anthropic, Meta and the UK AI Security Institute (AISI) describe AI agents reaching systems belonging to other organizations without their consent. The defining capability is now persistence: models can repeatedly test …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows that customers can now buy payload obfuscation, in-memory execution, anti-analysis controls, p…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to distribute botnet instructions without relying on a conventional server or domain. The design shi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly obfuscated malware payloads in documents that victim implants retrieve and execute. The technique all…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Seashell Blizzard. The activity, observed since at least May 2026, begins on job-search platforms…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


