Malware & Threats

‘Stanley’ Malware Toolkit Enables Phishing via Website Spoofing

‘Stanley’ Malware Toolkit Enables Phishing via Website Spoofing 2026-01-26 at 14:37 By Ionut Arghire Priced $2,000 – $6,000 on a cybercrime forum, the MaaS toolkit promises publication on the Chrome Web Store. The post ‘Stanley’ Malware Toolkit Enables Phishing via Website Spoofing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

‘Stanley’ Malware Toolkit Enables Phishing via Website Spoofing Read More »

Russian Sandworm Hackers Blamed for Cyberattack on Polish Power Grid

Russian Sandworm Hackers Blamed for Cyberattack on Polish Power Grid 2026-01-26 at 10:55 By Ionut Arghire 10 years after disrupting the Ukrainian power grid, the APT targeted Poland with data-wiping malware. The post Russian Sandworm Hackers Blamed for Cyberattack on Polish Power Grid appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Russian Sandworm Hackers Blamed for Cyberattack on Polish Power Grid Read More »

North Korean Hackers Target macOS Developers via Malicious VS Code Projects

North Korean Hackers Target macOS Developers via Malicious VS Code Projects 2026-01-21 at 15:23 By Ionut Arghire The hackers trick victims into accessing GitHub or GitLab repositories that are opened using Visual Studio Code. The post North Korean Hackers Target macOS Developers via Malicious VS Code Projects appeared first on SecurityWeek. This article is an

North Korean Hackers Target macOS Developers via Malicious VS Code Projects Read More »

APT-Grade PDFSider Malware Used by Ransomware Groups

APT-Grade PDFSider Malware Used by Ransomware Groups 2026-01-20 at 14:24 By Ionut Arghire Providing cyberespionage and remote code execution capabilities, the malware is executed via DLL sideloading. The post APT-Grade PDFSider Malware Used by Ransomware Groups appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

APT-Grade PDFSider Malware Used by Ransomware Groups Read More »

‘SolyxImmortal’ Information Stealer Emerges

‘SolyxImmortal’ Information Stealer Emerges 2026-01-19 at 17:21 By Ionut Arghire The information stealer abuses legitimate APIs and libraries to exfiltrate data to Discord webhooks. The post ‘SolyxImmortal’ Information Stealer Emerges appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

‘SolyxImmortal’ Information Stealer Emerges Read More »

Malicious Chrome Extension Crashes Browser in ClickFix Variant ‘CrashFix’

Malicious Chrome Extension Crashes Browser in ClickFix Variant ‘CrashFix’ 2026-01-19 at 13:14 By Ionut Arghire Posing as an ad blocker, the malicious extension crashes the browser to lure victims into installing malware. The post Malicious Chrome Extension Crashes Browser in ClickFix Variant ‘CrashFix’ appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Malicious Chrome Extension Crashes Browser in ClickFix Variant ‘CrashFix’ Read More »

VoidLink Linux Malware Framework Targets Cloud Environments

VoidLink Linux Malware Framework Targets Cloud Environments 2026-01-15 at 11:58 By Ionut Arghire Designed for long-term access, the framework targets cloud and container environments with loaders, implants, and rootkits. The post VoidLink Linux Malware Framework Targets Cloud Environments appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

VoidLink Linux Malware Framework Targets Cloud Environments Read More »

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits 2026-01-14 at 16:03 By Kevin Townsend The Predator spyware is more sophisticated and dangerous than previously realized. The post Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits Read More »

GoBruteforcer Botnet Targeting Crypto, Blockchain Projects

GoBruteforcer Botnet Targeting Crypto, Blockchain Projects 2026-01-13 at 20:08 By Ionut Arghire The botnet’s propagation is fueled by the AI-generated server deployments that use weak credentials, and legacy web stacks. The post GoBruteforcer Botnet Targeting Crypto, Blockchain Projects appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GoBruteforcer Botnet Targeting Crypto, Blockchain Projects Read More »

Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities

Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities 2026-01-12 at 14:39 By Ionut Arghire APT28 was seen impersonating popular webmail and VPN services, including Microsoft OWA, Google, and Sophos VPN portals. The post Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities Read More »

FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes

FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes 2026-01-09 at 17:34 By Ionut Arghire The North Korean state-sponsored espionage group Kimsuky has targeted government organizations, think tanks, and academic institutions. The post FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes Read More »

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats 2026-01-07 at 17:35 By Ionut Arghire Impersonating a legitimate extension from AITOPIA, the two malicious extensions were also exfiltrating users’ browser activity. The post Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats Read More »

Hackers Exploit Zero-Day in Discontinued D-Link Devices

Hackers Exploit Zero-Day in Discontinued D-Link Devices 2026-01-07 at 14:34 By Ionut Arghire The critical-severity vulnerability allows unauthenticated, remote attackers to execute arbitrary shell commands. The post Hackers Exploit Zero-Day in Discontinued D-Link Devices appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploit Zero-Day in Discontinued D-Link Devices Read More »

Sophisticated ClickFix Campaign Targeting Hospitality Sector

Sophisticated ClickFix Campaign Targeting Hospitality Sector 2026-01-06 at 15:44 By Ionut Arghire Fake Booking reservation cancellations and fake BSODs trick victims into executing malicious code leading to RAT infections. The post Sophisticated ClickFix Campaign Targeting Hospitality Sector appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Sophisticated ClickFix Campaign Targeting Hospitality Sector Read More »

Dozens of Major Data Breaches Linked to Single Threat Actor

Dozens of Major Data Breaches Linked to Single Threat Actor 2026-01-06 at 14:32 By Ionut Arghire The initial access broker (IAB) relies on credentials exfiltrated using information stealers to hack organizations. The post Dozens of Major Data Breaches Linked to Single Threat Actor appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Dozens of Major Data Breaches Linked to Single Threat Actor Read More »

Kimwolf Android Botnet Grows Through Residential Proxy Networks

Kimwolf Android Botnet Grows Through Residential Proxy Networks 2026-01-05 at 14:53 By Ionut Arghire The 2-million-device-strong botnet allows monetization through DDoS attacks, app installs, and the selling of proxy bandwidth. The post Kimwolf Android Botnet Grows Through Residential Proxy Networks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Kimwolf Android Botnet Grows Through Residential Proxy Networks Read More »

RondoDox Botnet Exploiting React2Shell Vulnerability

RondoDox Botnet Exploiting React2Shell Vulnerability 2026-01-02 at 14:42 By Ionut Arghire In December, the botnet’s operators focused on weaponizing the flaw to compromise vulnerable Next.js servers. The post RondoDox Botnet Exploiting React2Shell Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

RondoDox Botnet Exploiting React2Shell Vulnerability Read More »

Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit

Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit 2025-12-30 at 12:25 By Ionut Arghire The threat actor uses a signed driver file containing two user-mode shellcodes to execute its ToneShell backdoor. The post Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit Read More »

Infostealer Malware Delivered in EmEditor Supply Chain Attack

Infostealer Malware Delivered in EmEditor Supply Chain Attack 2025-12-29 at 13:40 By Eduard Kovacs The ‘download’ button on the official EmEditor website served a malicious installer. The post Infostealer Malware Delivered in EmEditor Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Infostealer Malware Delivered in EmEditor Supply Chain Attack Read More »

NPM Package With 56,000 Downloads Steals WhatsApp Credentials, Data

NPM Package With 56,000 Downloads Steals WhatsApp Credentials, Data 2025-12-23 at 13:16 By Ionut Arghire The package provides legitimate functionality to evade detection, while stealing users’ data and deploying a backdoor. The post NPM Package With 56,000 Downloads Steals WhatsApp Credentials, Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

NPM Package With 56,000 Downloads Steals WhatsApp Credentials, Data Read More »

Scroll to Top