threat-intel Who’s Tracking You? Use This New Service to Find Out DecryptAds is a new service designed to expose the complex ecosystem of adtech companies tracking users online. By scraping data from files like ads.txt, app-ads.txt, and sellers.json, it reveals a network of data brokers and advertising firms, many of which are based in countries with geopolitical concerns, including… Krebs on Security · Aug 14, 2026 High CHRUUAadtechdata-brokermalvertising
threat-intel 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One A massive collection of 737 Chrome VPN and proxy extensions are being used to route user traffic through a single SOCKS5 proxy infrastructure, primarily targeting Russian-speaking users seeking access to blocked content.… The Hacker News · Aug 12, 2026 High RUvpnproxychrome
threat-intel Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Maksim Silnikau, the mastermind behind the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for his role in a multi-year criminal scheme targeting organizations across the US and abroad. The o… SecurityWeek · Aug 6, 2026 High BEUKRUransomwarecybercrimeextradition
threat-intel DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious co… The Hacker News · Jul 30, 2026 High KPmacosmalvertisingcrypto-stealer
threat-intel Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A sophisticated malvertising campaign, dubbed SourTrade and linked to Confiant, is using legitimate browser technologies like Bun and a ServiceWorker to build Windows executables for victims, primarily targeting retail t… The Hacker News · Jul 25, 2026 High malvertisingbrowserbun
threat-intel China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks A China-nexus operation, tracked by Group-IB, dubbed JadeProx, is using a new loader called TriBack Loader to target government, healthcare, and education organizations across Asia and Latin America. The operation levera… The Hacker News · Jul 23, 2026 High CVE-2018-11511CVE-2021-24139CVE-2021-31755CHHOVIloaderspear-phishingvulnerability
malware Vidar Infostealer Hammers SMBs via Malvertising Campaign A financially motivated operation is using malvertising to deliver a two-for-one malware payload – the Vidar infostealer and XMRig cryptominer – to consumers and SMBs globally. The campaign employs sophisticated evasion… Dark Reading · Jul 8, 2026 High USEUmalvertisingmaascryptomining
threat-intel Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A financially motivated campaign utilizing Vidar stealer and XMRig cryptocurrency miner has been active since April 2026, targeting consumers and small- and medium-sized businesses globally, primarily in the U.S. and EU.… Palo Alto Unit 42 · Jul 7, 2026 High USDEmalvertisingdll hijackinganti-forensic
malware FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads A new macOS malvertising campaign, dubbed Operation FlutterBridge, is utilizing FlutterShell, a backdoor that spreads adware via malicious Google and YouTube ads. The campaign, traced back to the CL-CRI-1089 threat actor… The Hacker News · Jun 4, 2026 High USCAAUmalvertisingmacoswebview
malware Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor Palo Alto Unit 42 is tracking ‘Operation FlutterBridge,’ a widespread malvertising campaign targeting macOS users. The campaign, a follow-up to the ‘JSCoreRunner’ campaign, utilizes malicious desktop applications built w… Palo Alto Unit 42 · Jun 2, 2026 High USmacosmalvertisingbackdoor
malware Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps A new Android ad fraud scheme, dubbed Trapdoor, has been identified by HUMAN Threat Intelligence, utilizing 455 malicious apps and 183 C2 domains to generate 659 million daily bid requests. The operation leverages malver… The Hacker News · May 19, 2026 High USandroidad fraudmalvertising