threat-intel 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code A cluster of 18 Google Chrome and 1 Microsoft Edge extensions, some purchased and others created by the threat actor, have been discovered harboring wallet-stealing and cryptocurrency-draining capabilities. The campaign, dubbed ‘Superior’ by Socket, has been active since February 2024 and involves acquiring legitimate… The Hacker News · 2d ago High extensionmalwarewallet
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allo… Dark Reading · 5d ago High malwareloaderinfostealer
threat-intel WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords Two new malware families, WordlistLoader and SynkLoader, are being used to deliver the Amatera Stealer via ClickFix phishing campaigns. WordlistLoader reconstructs shellcode for Amatera, utilizing techniques to evade det… The Hacker News · 6d ago High phishingransomwaremalware
threat-intel Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts Three distinct clusters of suspected Russian cyber espionage groups – UNC6293, UNC7005, and UNC5976 – are leveraging legitimate authentication flows to target individuals in academia, aerospace/defense, governments, and… The Hacker News · Aug 20, 2026 High UKARRUoauthapp passworddevice linking
threat-intel ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories This week's ThreatsDay Bulletin highlights a diverse range of security threats, including AI-related attacks, data breaches, and malware campaigns. Key concerns include GhostJacking, where AI agents are hijacked to execu… The Hacker News · Aug 13, 2026 High CVE-2026-20685USUKSWaiagentjackingdata breach
threat-intel ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets ClickFix-style attacks are being used to deliver a Go-based macOS stealer that can drain cryptocurrency wallets and steal browser-stored passwords and Apple iCloud Keychain data. The malware, developed by the Aeza Group… The Hacker News · Aug 7, 2026 High USUKAUmacoscryptocurrencystealer
threat-intel BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery North Korean threat actors, operating under the BlueNoroff campaign, are using a sophisticated phishing kit to target crypto investors and venture capitalists. The kit leverages compromised trusted contacts and typosquat… The Hacker News · Jul 24, 2026 High KPphishingzoommicrosoft teams
threat-intel ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing ClickLock Stealer, a new macOS malware, bypasses macOS security through social engineering and aggressive process killing to steal sensitive data, including browser data, cryptocurrency wallets, and password manager info… SecurityWeek · Jul 16, 2026 High DEFRITmacossocial engineeringprocess killing
threat-intel New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password A new macOS infostealer, dubbed ClickLock Stealer, is actively targeting users by forcing them to enter their passwords repeatedly through a loop of killing apps. The malware, a copy of GSocket, uses a deceptive Cloudfla… The Hacker News · Jul 16, 2026 High EUmacosinfostealerpassword
threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
ransomware Amadey, StealC malware operations disrupted in Operation Endgame action Operation Endgame, a coordinated law enforcement effort involving Microsoft, Europol, and international partners, successfully disrupted infrastructure used by the Amadey and StealC malware operations. The operation resu… BleepingComputer · Jun 24, 2026 High USCADKmalware-as-a-servicecredential theftransomware
threat-intel Stealthy Mistic backdoor linked to ransomware access broker KongTuke A new stealthy backdoor, dubbed Mistic, has been identified as a tool used by the initial access broker KongTuke to facilitate ransomware attacks against organizations in the insurance, education, IT, and professional se… BleepingComputer · Jun 24, 2026 High USbackdoorinitial accessransomware
threat-intel ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories This week’s ThreatDay Bulletin highlights several concerning security incidents, including browser extension abuse, macOS malware attacks, AI-powered malware delivery, and a global phishing campaign targeting travel book… The Hacker News · Jun 18, 2026 High CVE-2026-20127CVE-2026-49975USCNJPbrowser extensionsmacos malwareai abuse
threat-intel DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks A sophisticated cybercriminal operation, dubbed DriveSurge, has been hijacking thousands of legitimate websites to distribute malware, primarily through ClickFix and FakeUpdate attacks. The operation utilizes a traffic d… Dark Reading · Jun 2, 2026 High USmalwaretraffic distributionclickfix
threat-intel Why the browser is now the front line for AI security This BleepingComputer article highlights the escalating threat of AI-powered phishing attacks, primarily targeting the browser environment. Adversaries are leveraging AI to rapidly create and deploy phishing kits, automa… BleepingComputer · Jun 2, 2026 High USaiphishingbrowser
malware ChatGPT share links abused to host fake outage pages to deliver malware Threat actors are exploiting ChatGPT's content-sharing feature to host convincing fake outage pages designed to trick users into downloading malware. This 'LLMShare' campaign leverages Google ads and a legitimate OpenAI… BleepingComputer · May 29, 2026 High aimalwarephishing