malware Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT A new malspam campaign is leveraging Google's DoubleClick domain to deliver the DesckVB RAT, a .NET-based remote access trojan. The campaign’s scalability and cost-effectiveness stem from its ability to dynamically perso… The Hacker News · Jun 3, 2026 High USmalspamratdoubleclick
malware Argamal: Malware hidden in hentai games A new malware campaign, dubbed "Argamal," is targeting users of hentai games. The campaign involves injecting a malicious implant into legitimate game files, leveraging COM hijacking to establish persistence and achieve… Securelist · Jun 3, 2026 High UShentaicom hijackingpersistence
malware Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poiso… The Hacker News · Jun 3, 2026 High USDEINminecraftmalwareyoutube
malware ISC Stormcast For Wednesday, June 3rd, 2026 https://isc.sans.edu/podcastdetail/9956, (Wed, Jun 3rd) The SANS Internet Storm Center's Stormcast for June 3rd, 2026 highlighted a concerning increase in malicious activity across the internet landscape. The broadcast detailed several ongoing threats, including observed phis… SANS Internet Storm Center · Jun 3, 2026 High phishingransomwaremalware
malware Over 116,000 Mincraft systems infected in WeedHack malware campaign A large-scale malware campaign, dubbed WeedHack, has infected over 116,000 Minecraft systems since January, primarily through malicious mods and clients promoted via YouTube and SEO poisoning. The malware operates as a M… BleepingComputer · Jun 2, 2026 High USDEINminecraftmalwaremaas
malware Over 116,000 Minecraft systems infected in WeedHack malware campaign A large-scale malware campaign, dubbed WeedHack, has infected over 116,000 Minecraft systems since January, primarily through malicious mods and clients promoted on YouTube and via SEO poisoning. The operation is a malwa… BleepingComputer · Jun 2, 2026 Medium USDEINminecraftmalwaremaas
malware Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor Palo Alto Unit 42 is tracking ‘Operation FlutterBridge,’ a widespread malvertising campaign targeting macOS users. The campaign, a follow-up to the ‘JSCoreRunner’ campaign, utilizes malicious desktop applications built w… Palo Alto Unit 42 · Jun 2, 2026 High USmacosmalvertisingbackdoor
malware Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites. BleepingComputer · Jun 1, 2026 Medium
malware Dutch Police Dismantle Massive 17-Million-Device Botnet Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime. The post Dutch… SecurityWeek · Jun 1, 2026
malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
malware Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st) Introduction SANS Internet Storm Center · Jun 1, 2026 Medium
malware Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the D… The Hacker News · May 31, 2026
malware ChatGPT share links abused to host fake outage pages to deliver malware Threat actors are exploiting ChatGPT's content-sharing feature to host convincing fake outage pages designed to trick users into downloading malware. This 'LLMShare' campaign leverages Google ads and a legitimate OpenAI… BleepingComputer · May 29, 2026 High aimalwarephishing
malware Dutch govt disrupts malware botnet with 17 million infected devices Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. BleepingComputer · May 29, 2026 Medium
malware Analysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th) Using the data collected over the past year and using Kibana these two ES|QL query to summarize the data, this shows the list of the most uploaded threat to two DShield sensors (local and cloud) over the past year. I hav… SANS Internet Storm Center · May 28, 2026 Medium
malware BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model An advanced Android remote access Trojan, BTMOB RAT, is spreading across Brazil and Latin America through a malware-as-a-service (MaaS) model. Delivered via a no-code interface, it allows cybercriminals to create malicio… Dark Reading · May 28, 2026 High BRARandroidratmaas
malware Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years In April 2026, a cybercrime gang has been using fake video player plugin updates to distribute a cryptocurrency miner, a tactic that has been ongoing since at least 2022. The gang leverages pirated digital libraries and… Securelist · May 28, 2026 High RUTOcryptominerstackoverflowfake update
malware GPU mining malware spreads via SEO poisoning, AI chatbots A cryptojacking campaign utilizing SEO poisoning and AI chatbot manipulation is spreading through malicious downloads of popular system utilities. The campaign leverages a ZIP archive containing a malicious DLL and a Scr… BleepingComputer · May 27, 2026 High UScryptojackingseo poisoningai chatbots
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading
malware Malicious npm Package Stole Files From Claude AI User Directory via GitHub A malicious npm package, "mouse5212-super-formatter," was discovered that leveraged GitHub to steal files from Anthropic's Claude AI user directory. The package masqueraded as a legitimate archive deployment sync utility… The Hacker News · May 27, 2026 High USnpmgithubai