threat-intel DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT DOUBLECUP, a new Russian LaaS service, is using ClickFix lures to deliver malware, specifically CountLoader (Windows and macOS) and DeviceManager (Windows and macOS). DeviceManager utilizes blockchain-based C2 resolution… The Hacker News · Aug 4, 2026 High RUsteganographyclickfixransomware
threat-intel 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users A sophisticated supply chain attack targeting Chinese-speaking developers using Alibaba tools has been discovered. Researchers found a set of malicious npm packages, including wrappers mimicking private Alibaba packages,… The Hacker News · Aug 3, 2026 High CHsupply chainmalwarenpm
threat-intel Russian spies turn public Wi-Fi into malware delivery systems Russian state actors are leveraging public Wi-Fi networks to deliver malware to victims, specifically by impersonating Signal support to launch phishing attacks. This tactic is part of a broader trend of Russian intellig… The Register · Aug 3, 2026 High RUIRphishingmalwarerussian
threat-intel Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS A Chinese threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to deploy GHOSTBLADE, an information-stealing malware, targeting Apple iOS devices. Censys identified over 100 web properties us… The Hacker News · Aug 3, 2026 High HOJACHiosexploit kitmalware
threat-intel Pass the Passkey: A Novel Attack Surface in Passwordless Authentication This report details a new attack vector, dubbed ‘Pass-ta-key,’ that allows malware running on a compromised endpoint to bypass traditional security measures and gain unauthorized access to passkey-protected accounts. Res… Palo Alto Unit 42 · Aug 3, 2026 High USpasskeyauthenticationmalware
threat-intel Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd) A researcher at the SANS Internet Storm Center identified an Atomic MacOS (AMOS) stealer infection campaign originating from a web page at getmacouscloud[.]com. The campaign involved tricking users into pasting malicious… SANS Internet Storm Center · Aug 2, 2026 High macosstealerc2
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
threat-intel The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version The XCSSET malware family has returned with version 40, exhibiting enhanced stealth and persistence techniques to evade detection and compromise macOS systems, particularly those of software developers. This latest itera… Palo Alto Unit 42 · Jul 31, 2026 High SOmacossupply chainmalware
vulnerability ISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging a newly discovered vulnerability in a popular PDF reader. Attackers are using this vulnerabil… SANS Internet Storm Center · Jul 31, 2026 Critical pdfphishingvulnerability
threat-intel Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Amazon has attributed the September 2025 compromise of npm packages debug and chalk, along with subsequent incidents involving typo-crypto and axios, to North Korea’s Sapphire Sleet group. While initial reports attribute… The Hacker News · Jul 30, 2026 High KPnpmthreat intelligencemalware
threat-intel 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack A recent study reveals that 73% of organizations aren't fully prepared to withstand a major cyberattack, despite having incident response plans and security tools. The core issue isn't simply having these capabilities, b… The Hacker News · Jul 29, 2026 High incident responsecybersecurityvulnerability
threat-intel Pages piégées à Saint-Denis, le test avant l’opération d’influence ? A French swimming pool website was infiltrated in June 2026 by pirates, who have since been altering pages to test the pool's defenses and gather intelligence. The attackers are using the website's modification patterns… ZATAZ · Jul 29, 2026 High FRcyber espionagereconnaissancedisinformation
threat-intel Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Two compromised npm packages within the @joyfill namespace have been injected with a remote access trojan (RAT) linked to the DEV#POPPER malware family. These packages utilize a complex blockchain-based infrastructure (T… The Hacker News · Jul 29, 2026 High KPnpmmalwareremote access trojan
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
threat-intel AI Agent Drives Espionage Attack on Thai Ministry of Finance Threat actors used an autonomous AI agent, Hermes, to conduct espionage against Thailand's Ministry of Finance. The attack, supported by open-source tools like LinPEAS and Hades (a custom Windows/Linux malware), involved… Dark Reading · Jul 28, 2026 High CHHOaiespionagemalware
threat-intel Health system in South Carolina, Georgia closes offices after malware affects networks AnMed Health, a multi-state healthcare system in South Carolina and Georgia, has been forced to temporarily close numerous facilities due to a malware attack. The system is working to restore operations and ensure patien… The Record · Jul 27, 2026 High cyberattackhealthcaremalware
threat-intel Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update A sophisticated phishing campaign, dubbed Operation BlueDash, is leveraging Microsoft Teams-themed lures to deliver malicious Remote Management and Monitoring (RMM) tools, primarily Level RMM and ConnectWise ScreenConnec… The Hacker News · Jul 27, 2026 High NGphishingrmmremote access
threat-intel Hackers used autonomous AI agent to spy on Thailand's finance ministry Hackers used an autonomous AI agent, Hermes developed by Nous Research, to conduct a cyber-espionage campaign targeting Thailand's Ministry of Finance. The agent independently explored the ministry's network, gathering i… The Record · Jul 27, 2026 High CNaicyberespionageautonomous agent
threat-intel Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware The China-linked cybercrime group behind tax-themed phishing campaigns is utilizing a sophisticated crypter service called Cruciferra to deliver a wide range of malware, including remote access trojans and information st… The Hacker News · Jul 27, 2026 High CNcrypterransomwarephishing
threat-intel BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery North Korean threat actors, operating under the BlueNoroff campaign, are using a sophisticated phishing kit to target crypto investors and venture capitalists. The kit leverages compromised trusted contacts and typosquat… The Hacker News · Jul 24, 2026 High KPphishingzoommicrosoft teams