malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit
malware What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th) This SANS Internet Storm Center guest diary details an analysis of automated cybercrime activity observed through a honeypot, focusing on the Terrabot IoT botnet. The author, a BACS student, highlights the prevalence of… SANS Internet Storm Center · Jun 25, 2026 Medium CVE-2016-20017CVE-2018-10561CVE-2016-20016USiotbotnetscanning
malware Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension, ‘Edgecution,’ was used in a ransomware attack by exploiting Native Messaging to bypass browser security sandboxes and deploy a Python-based backdoor. The attack, linked to the Payout… BleepingComputer · Jun 24, 2026 High USbrowser extensionnative messagingransomware
malware Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies. The post Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware appeared first… SecurityWeek · Jun 24, 2026 High
malware New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently deploy the Atomic macOS Stealer (AMOS) infostealer, targeting users through fake CAPTCHA pages. The malware steals sensitive data like browser credenti… BleepingComputer · Jun 23, 2026 High USmacosclickfixinfostealer
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
malware WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool A WhatsApp-based campaign is utilizing malicious VBScript files to trick users into installing ManageEngine RMM tool software. The campaign, currently active across multiple countries, leverages deceptive document names… The Hacker News · Jun 23, 2026 Medium MYBRINsocial engineeringvbsremote access
malware New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer A new malware loader, dubbed OXLOADER, is being used to distribute the CastleStealer information stealer through malicious Google Ads. The campaign, codenamed REF8372, leverages deceptive advertising and PowerShell execu… The Hacker News · Jun 22, 2026 Medium RUUAgoogle adsmalware loadercastlestealer
malware A VBScript campaign distributed through WhatsApp deploying RMM software A WhatsApp-distributed malware campaign, active as of June 2026, leverages deceptive VBScript files disguised as financial documents to trick users into executing malicious code. This code ultimately installs legitimate… Securelist · Jun 22, 2026 High MYBRINsocial engineeringvbswhatsapp
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
malware Police raid malware network tied to Russia's Evil Corp hacker group An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp. The Record · Jun 19, 2026 Medium
malware 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown appeared first on SecurityWe… SecurityWeek · Jun 19, 2026 High
malware Majority of Internet-Accessible REDCap Servers Outdated These servers are regularly targeted by China-linked UNC6508 for initial access and backdoor deployment. The post Majority of Internet-Accessible REDCap Servers Outdated appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026
malware USB worm spreads crypto-stealing malware via Windows shortcut files Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication. BleepingComputer · Jun 18, 2026 Medium
malware Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has detailed a new Windows-based malware campaign, dubbed Windows Clipper, that leverages USB LNK files and a Tor-based command-and-control infrastructure to steal cryptocurrency data. The clipper silently moni… The Hacker News · Jun 18, 2026 High clipboardtorusb
malware Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. BleepingComputer · Jun 18, 2026 High
malware Embedding Forbidden Text in Spyware to Discourage AI Analysis At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. Details : The _index.js payload begins with a large JavaScript block commen… Schneier on Security · Jun 18, 2026 Medium
malware Rokarolla Banking Trojan Targets 200 Applications The Android malware allows its operators to take control of infected devices and harvest sensitive information. The post Rokarolla Banking Trojan Targets 200 Applications appeared first on SecurityWeek . SecurityWeek · Jun 18, 2026 Medium
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft