malware AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft has identified a cryptojacking campaign utilizing AI chatbots to recommend malicious download sites, a novel approach to social engineering. The campaign impersonates legitimate system utilities like CrystalDis… The Hacker News · May 27, 2026 High CVE-2025-33073USaicryptojackingsocial engineering
malware Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning Iranian state-sponsored threat actor Nimbus Manticore (UNC1549) has launched a new campaign utilizing the MiniFast backdoor, developed with potential AI assistance, to target organizations in the aviation and software se… The Hacker News · May 26, 2026 High SAAUIRphishingbackdoorappdomain hijacking
malware Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th) This report details the discovery of a fake Claude webpage distributing the ACR Stealer malware, targeting macOS and Windows users. The initial infection vector involves malicious ads leading to the deceptive site, which… SANS Internet Storm Center · May 26, 2026 High USstealermacoswindows
malware Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms The Lazarus Group, a North Korean threat actor, has deployed a new memory-only remote access trojan (RAT) called RemotePE to target financial and cryptocurrency firms. This multi-stage attack chain utilizes several loade… The Hacker News · May 25, 2026 High KPremote access trojannorth koreasocial engineering
malware Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, do… BleepingComputer · May 23, 2026 High USsupply chaincredential theftgithub
malware An Example of Stack String in High Level Language, (Sat, May 23rd) This article discusses a malware obfuscation technique called "stack strings," where strings are dynamically constructed on the stack at runtime rather than being stored as contiguous data in the binary. The example demo… SANS Internet Storm Center · May 23, 2026 Medium obfuscationstackassembly
malware Canadian Man Arrested for Operating Kimwolf Botnet Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges. The post Canadian Man Arrested for Operating Kimwolf Botnet appeared first on SecurityWeek . SecurityWeek · May 22, 2026
malware Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka… The Hacker News · May 22, 2026
malware Cross-Platform NPM Stealer, (Fri, May 22nd) A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chro… SANS Internet Storm Center · May 22, 2026 High USstealerobfuscatedbrowser
malware The art of being ungovernable This analysis focuses on a Cisco Talos report detailing the emergence of a sophisticated, multi-year-old BadIIS malware variant being utilized by Chinese-speaking cybercrime groups as part of a malware-as-a-service (MaaS… Cisco Talos · May 21, 2026 High CHmalware-as-a-serviceseo fraudtraffic hijacking
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
malware Ukraine identifies infostealer operator tied to 28,000 stolen accounts The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation targeting users of an online store in Califo… BleepingComputer · May 20, 2026 High
malware Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs. A coordinated campaign targeting Android users in Malaysia, Thailand, Romania, and Croatia has been identified, utilizing fake apps disguised as popular services to commit carrier billing fraud. The malware, employing te… Dark Reading · May 20, 2026 High MYTHROandroidcarrier billingfraud
malware Tracking TamperedChef Clusters via Certificate and Code Reuse This report details ongoing activity clusters closely resembling the TamperedChef (EvilAI) malware campaign, which involves trojanized productivity software like PDF editors and calendars. These campaigns utilize malicio… Palo Alto Unit 42 · May 20, 2026 High USpersistencecommand and controltrojan
malware Stealer Spoofs Google, Microsoft & Apple, Then Backdoors macOS A new macOS infostealer, dubbed SHub Reaper, is targeting users through fake WeChat and Miro installers, mimicking Google, Microsoft, and Apple to lure victims. This malware combines stealer and backdoor capabilities, ut… Dark Reading · May 19, 2026 High USmacosinfostealerbackdoor
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
malware Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files This report details the evolving tactics of the Gremlin stealer malware, specifically a recent variant employing sophisticated obfuscation techniques to evade detection. The malware, which targets sensitive data like pay… Palo Alto Unit 42 · May 15, 2026 High USobfuscationanti-analysisresource section
malware Fake call logs, real payments: How CallPhantom tricks Android users This report details a widespread Android scam, dubbed CallPhantom, where fraudulent apps masquerading as call log retrieval services tricked users into paying for randomly generated data. Twenty-eight apps, collectively… WeLiveSecurity · May 7, 2026 Medium INscamfraudandroid
malware New NGate variant hides in a trojanized NFC payment app A new variant of the NGate malware, dubbed NGate, is targeting Android users in Brazil by abusing the legitimate HandyPay app. Threat actors used generative AI to modify HandyPay, allowing them to steal NFC data, includi… WeLiveSecurity · Apr 21, 2026 High BRnfcandroidmalware