threat-intel Foul Language: WordlistLoader Disguises Malware as Ordinary Text A new malware loader called WordlistLoader is being used to deliver the Amatera infostealer, primarily through ClickFix-style campaigns. WordlistLoader disguises malicious code using lists of ordinary English words, allowing it to evade security controls and deliver the stealer. Amatera, a rapidly growing infostealer,… Dark Reading · 5d ago High malwareloaderinfostealer
threat-intel Enterprise Defenses Recovered at the Edge and Collapsed Inside A new report from Picus Labs reveals a concerning trend in cybersecurity defenses: while overall prevention effectiveness has improved, defenses are significantly weaker *inside* a network, failing to stop quiet, reconna… The Hacker News · Aug 12, 2026 High detectionloggingreconnaissance
threat-intel Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook The Smoke#Screen campaign is a sophisticated social engineering attack leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically ScreenConnect, to gain persistent remote access to compromised netwo… Dark Reading · Aug 4, 2026 High social engineeringremote managementphishing
threat-intel DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution… The Hacker News · Aug 4, 2026 High RUsteganographyclickfixransomware
threat-intel 'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China A sophisticated, full-service mobile malware-as-a-service (MaaS) framework called ‘Flying Eagle’ has emerged from the Chinese cybercriminal underground, enabling criminals to build and deploy mobile malware campaigns wit… Dark Reading · Jul 30, 2026 High CHmaasmobile malwarecybercrime
threat-intel Attackers Combo Up Evasion Tactics for BEC Phishing Attackers are employing increasingly sophisticated evasion techniques to deliver BEC phishing attacks, utilizing a multi-stage process involving disguised font files, Lua interpreters, and fileless execution to bypass en… Dark Reading · Jul 20, 2026 High phishingbecevasion
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks Securonix researchers identified a complex malware delivery framework called ‘Veil#Drop’ that utilizes compromised websites, specifically Blogspot, to deploy information-stealing malware. The framework employs multiple l… SecurityWeek · Jul 6, 2026 High malwareinformation stealerevasion
threat-intel New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS A new Java-based remote access trojan (RAT) called QuimaRAT, offered as a malware-as-a-service (MaaS), has been released by a threat actor. The tool is cross-platform, supporting Windows, Linux, and macOS, and is adverti… The Hacker News · Jul 6, 2026 High javaratmalware-as-a-service
malware VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer A new multi-stage malware attack chain, dubbed VEIL#DROP, is utilizing social engineering and Blogger pages to deliver the PureLogs stealer. The attack begins with a deceptive JavaScript file, leveraging Google's infrast… The Hacker News · Jul 1, 2026 High USspear-phishingbloggerpurelogs
malware RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS A new botnet, RustDuck, is leveraging Rust programming to hijack routers, IP cameras, and servers for DDoS attacks. Developed by QiAnXin's XLab, the botnet utilizes a two-stage approach, exploiting vulnerabilities in dev… The Hacker News · Jun 30, 2026 High CVE-2017-17215CVE-2025-29635CVE-2024-1781CNddosbotnetrust
malware Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses A new browser extension campaign, dubbed Silent Swap by McAfee Labs, is targeting cryptocurrency users by stealthily replacing wallet addresses during transactions. The malicious extension, disguised as a Google Notes ut… The Hacker News · Jun 30, 2026 High INUSBRclipboardwalletcrypto
malware Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts Microsoft removed 119 malicious Edge extensions from its add-on store that employed steganography to hide malware, including credential theft and ad fraud capabilities. The operation, dubbed StegoAd, had been active sinc… The Hacker News · Jun 29, 2026 High CHsteganographycredential theftad fraud
threat-intel GhostTree Attack Abused Recursive Windows Junctions to Hide Malware Security researchers have discovered a novel technique, dubbed "GhostTree," used by attackers to evade detection by security tools. This method leverages recursive loops created using NTFS junctions to hide malicious fil… BleepingComputer · Jun 16, 2026 High USjunctionsntfsrecursion
threat-intel Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility This article from Palo Alto Unit 42 details how attackers are exploiting cloud logging services, specifically AWS CloudTrail and Google Cloud Logging, to evade detection and gain continuous visibility into target environ… Palo Alto Unit 42 · Jun 9, 2026 High cloud securityloggingevasion
threat-intel New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework A new threat cluster, OP-512, is targeting Microsoft IIS servers with a custom web shell framework, exhibiting sophisticated evasion techniques and centralized management capabilities. ReliaQuest has linked the activity… The Hacker News · Jun 5, 2026 High CNiisweb shellespionage
malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
threat-intel China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts. A China-aligned Advanced Persistent Threat (APT) group known as Webworm has shifted its focus from Asia to targeting European governmental organizations, specifically in Belgium, Italy, Serbia, Spain, Poland, and South A… Dark Reading · May 22, 2026 High CHBEITaptdiscordmicrosoft graph
malware From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an a… Cisco Talos · May 19, 2026 Medium CNUSGBseomalware-as-a-serviceiis
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr