-
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified Windows backdoor, dubbed Mistic, that has been observed in intrusions since April 2026 and appears designed for stealthy, long-term access. The malware uses DLL sideloading, in-memory execution, and self-deletion to blend into enterp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Analysis of a .NET backdoor tracked as STOCKSTAY exposes a mature, modular espionage implant actively developed and deployed by the Russia-linked Turla cluster since at least December 2022. STOCKSTAY demonstrates several operational techniques designed…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Woodgnat Hackers use Backdoor.Mistic, a stealthy RAT, to let brokers compromise networks and sell entry points to ransomware groups, putting firms at risk.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks

Japan’s defense infrastructure has faced scrutiny following an investigation that revealed members of the Japan Self-Defense Forces (JSDF) used counterfeit USB drives embedded with malware linked to China on systems handling classified informatio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GTA 6 scams are luring fans with fake early access, crypto payments and malware downloads. Learn why PC and Android gamers face the biggest risks online today.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
LokiBot, a long-lived infostealer first advertised in May 2015, continues to evolve. Recent samples demonstrate deliberate attempts to evade static detection and frustrate analysis by combining API hashing with 3DES-encrypted command-and-control (C2) c…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
During a recent investigation into activity affecting a diplomatic mission in Indonesia, researchers uncovered a previously undocumented loader family they named SharkLoader. What began as an isolated incident rapidly expanded into a multi-country camp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Operation Endgame disrupts StealC malware infrastructure, seizing millions of stolen credentials and targeting servers used in global cybercrime campaigns.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶

