malware DOUBLECUP's PNG Payload, (Mon, Aug 24th) A new DOUBLECUP malware campaign utilizes a clever technique to bypass traditional steganography detection. The malware, delivered via PNG images, uses a simple PowerShell script appended to the file, easily extracted using the Windows `FINDSTR` command, avoiding the need for specialized extraction tools. SANS Internet Storm Center · 6d ago Medium powershellsteganographywindows
malware APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit The HoneyMyte APT group has significantly evolved its CoolClient backdoor, now incorporating a kernel-mode driver for enhanced stealth and data exfiltration. The latest variant, observed in campaigns targeting countries… Securelist · Aug 14, 2026 High
malware Kimwolf v7: An Evolution of the Kimwolf Botnet A new version (v7) of the Kimwolf botnet, primarily targeting Android TV boxes, has been identified. This version significantly enhances DDoS attack capabilities through HTTP/2-based flooding and browser fingerprinting,… Palo Alto Unit 42 · Aug 11, 2026 CVE-2016-5195
malware Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits A new Windows stealer, dubbed ‘Sneaky,’ is targeting over 300 applications, providing criminals with an AI profiler to maximize profits from stolen data. The malware leverages vulnerabilities in extensions to compromise… The Register · Jul 22, 2026 High malwareextensiondata theft
malware TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development A new IoT botnet framework, TuxBot v3 Evolution, has been identified, leveraging LLM assistance during development. Developed by an Iranian-based developer, the framework is modular and includes features like DDoS-for-hi… Palo Alto Unit 42 · Jul 15, 2026 CVE-2022-1388CVE-2022-22965CVE-2020-8515
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
malware My Stack Simulator, (Wed, Jul 8th) The stack is a memory region where a program stores temporary data -&#;x26;#;xc2;&#;x26;#;xa0;like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plat… SANS Internet Storm Center · Jul 8, 2026 Medium
malware PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords PamStealer, a new macOS information stealer developed by Jamf Threat Labs, utilizes deceptive tactics like mimicking the Maccy clipboard manager and exploiting Pluggable Authentication Modules (PAM) to steal login creden… The Hacker News · Jul 3, 2026 High RUBYKZmacosstealercredential theft
malware New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos A new remote access trojan (RAT) called ChocoPoC is targeting vulnerability researchers through deceptive proof-of-concept (PoC) repositories on GitHub. The malware, disguised within Python dependencies, steals sensitive… The Hacker News · Jul 2, 2026 High CVE-2025-64446CVE-2025-55182CVE-2025-14847KRproof-of-conceptremote access trojangithub
malware VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer A new multi-stage malware attack chain, dubbed VEIL#DROP, is utilizing social engineering and Blogger pages to deliver the PureLogs stealer. The attack begins with a deceptive JavaScript file, leveraging Google's infrast… The Hacker News · Jul 1, 2026 High USspear-phishingbloggerpurelogs
malware Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures The Ousaban banking trojan, originating in Brazil and previously tracked as Javali, is targeting Windows users in Spain and Portugal with a phishing campaign utilizing fake PDF lures. The trojan, which has evolved over t… The Hacker News · Jul 1, 2026 High PTESbanking trojanphishinggeofencing
malware The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign A large-scale cyber campaign utilized the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware onto compromised systems. Threat actors disguised installers of popular software like OBS Studio and DNS Ju… Securelist · Jul 1, 2026 High GDremote accessdll sideloadingpersistence
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
malware Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses A new browser extension campaign, dubbed Silent Swap by McAfee Labs, is targeting cryptocurrency users by stealthily replacing wallet addresses during transactions. The malicious extension, disguised as a Google Notes ut… The Hacker News · Jun 30, 2026 High INUSBRclipboardwalletcrypto
malware USB drives carrying China-linked malware infected Japanese military networks for nearly a year Japanese military networks, specifically the Ground Self-Defense Force (JGSDF), were compromised by a year-long campaign utilizing counterfeit USB drives loaded with malware. The incident, discovered in February 2025, in… Graham Cluley · Jun 30, 2026 High JACHusb drivesmalwarejapan
malware Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input A malicious Chrome extension disguised as the Perplexity AI search engine was discovered by Microsoft, intercepting user searches and address bar input. The extension secretly logged this data by routing it through an at… The Hacker News · Jun 29, 2026 High chromeextensiondata collection
malware Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acroni… The Hacker News · Jun 29, 2026 Medium
malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
malware Clean GitHub repo tricks AI coding agents into running malware An agentic coding tool tasked with running a seemingly benign GitHub repository could execute a malicious payload that is invisible to both security agents and human reviewers. BleepingComputer · Jun 27, 2026 Medium