news.mlab.sh
80 results
threat-intel

Almost Half of Malware Samples Communicate Direct to IP

Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including…

Palo Alto Unit 42 · Aug 4, 2026 High
threat-intel

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

A researcher at the SANS Internet Storm Center identified an Atomic MacOS (AMOS) stealer infection campaign originating from a web page at getmacouscloud[.]com. The campaign involved tricking users into pasting malicious…

SANS Internet Storm Center · Aug 2, 2026 High
threat-intel

AutoIT Payload Injector , (Tue, Jul 28th)

A wave of emails containing RAR archives containing AutoIT scripts are delivering a VIPKeylogger malware. The AutoIT scripts use legitimate tools like `charmap.exe` to inject and execute the malware, leveraging AutoIT's…

SANS Internet Storm Center · Jul 28, 2026 High