Malware

Group Policy abuse reveals China-aligned espionage group targeting governments

Group Policy abuse reveals China-aligned espionage group targeting governments 2025-12-18 at 13:42 By Anamarija Pogorelec ESET Research has identified a previously undocumented China-aligned advanced persistent threat group that uses Windows Group Policy to deploy malware and move through victim networks. The group, tracked as LongNosedGoblin, has targeted government institutions in Southeast Asia and Japan with […]

Group Policy abuse reveals China-aligned espionage group targeting governments Read More »

France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry

France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry 2025-12-18 at 13:42 By Associated Press France’s counterespionage agency is investigating a suspected cyberattack plot targeting an international passenger ferry The post France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry appeared first on SecurityWeek. This article is an excerpt

France Probes ‘Foreign Interference’ After Remote Control Malware Found on Passenger Ferry Read More »

GhostPoster Firefox Extensions Hide Malware in Icons

GhostPoster Firefox Extensions Hide Malware in Icons 2025-12-17 at 12:47 By Ionut Arghire The malware hijacks purchase commissions, tracks users, removes security headers, injects hidden iframes, and bypasses CAPTCHA. The post GhostPoster Firefox Extensions Hide Malware in Icons appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

GhostPoster Firefox Extensions Hide Malware in Icons Read More »

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery 2025-12-15 at 16:01 By Eduard Kovacs Google has also mentioned seeing React2Shell attacks conducted by Iranian threat actors. The post Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery Read More »

Wide Range of Malware Delivered in React2Shell Attacks

Wide Range of Malware Delivered in React2Shell Attacks 2025-12-11 at 14:54 By Eduard Kovacs Cybersecurity companies have been seeing a wide range of malware being delivered in attacks exploiting the critical React vulnerability dubbed React2Shell. A researcher discovered recently that React, the popular open source library for creating application user interfaces, is affected by a

Wide Range of Malware Delivered in React2Shell Attacks Read More »

V3G4 Botnet Evolves: From DDoS to Covert Cryptomining

V3G4 Botnet Evolves: From DDoS to Covert Cryptomining 2025-12-10 at 08:53 By rohansinhacyblecom Executive Summary Cyble Research & Intelligence Labs (CRIL) has identified an active Linux-targeting campaign that deploys a Mirai-derived botnet, paired with a stealthy, fileless-configured cryptominer. The threat actor employs a multi-stage infection chain starting with a downloader that delivers architecture-specific V3G4 binaries

V3G4 Botnet Evolves: From DDoS to Covert Cryptomining Read More »

US Organizations Warned of Chinese Malware Used for Long-Term Persistence

US Organizations Warned of Chinese Malware Used for Long-Term Persistence 2025-12-05 at 16:35 By Ionut Arghire Warp Panda has been using the BrickStorm, Junction, and GuestConduit malware in attacks against US organizations. The post US Organizations Warned of Chinese Malware Used for Long-Term Persistence appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

US Organizations Warned of Chinese Malware Used for Long-Term Persistence Read More »

MuddyWater cyber campaign adds new backdoors in latest wave of attacks

MuddyWater cyber campaign adds new backdoors in latest wave of attacks 2025-12-02 at 15:15 By Sinisa Markovic ESET researchers say an Iran aligned threat group is refining its playbook again, and the latest activity shows how much its tactics have shifted. MuddyWater is a long running cyberespionage group, and new findings points to a campaign

MuddyWater cyber campaign adds new backdoors in latest wave of attacks Read More »

Fake “Windows Update” screens fuels new wave of ClickFix attacks

Fake “Windows Update” screens fuels new wave of ClickFix attacks 2025-11-25 at 15:02 By Zeljka Zorz A convincing (but fake) “Windows Update” screen can be the perfect lure for tricking users into infecting their computers with malware. Add a multi-stage delivery chain with some offbeat techniques, and infostealer operators have everything they need to slip

Fake “Windows Update” screens fuels new wave of ClickFix attacks Read More »

640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack

640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack 2025-11-25 at 12:58 By Ionut Arghire The new self-replicating worm iteration has destructive capabilities, erasing home directory contents if it cannot spread to more repositories. The post 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack appeared first on SecurityWeek. This article is an

640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack Read More »

Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks

Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks 2025-11-21 at 13:46 By Ionut Arghire APT24 has been relying on various techniques to drop the BadAudio downloader and then deploy additional payloads. The post Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Chinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks Read More »

New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages

New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages 2025-11-20 at 17:56 By Eduard Kovacs The Android malware is in development and appears to be mainly aimed at users in Europe. The post New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages Read More »

MacOS DigitStealer malware poses as DynamicLake, targets Apple Silicon M2/M3 devices

MacOS DigitStealer malware poses as DynamicLake, targets Apple Silicon M2/M3 devices 2025-11-20 at 15:03 By Zeljka Zorz A new infostealer is targeting macOS users by masquerading as the legitimate DynamicLake UI enhancement and productivity utility and possibly Google’s Drive for desktop app. Multi-stage delivery Dubbed DigitStealer by Jamf researchers, this threat is unusually sophisticated. Before

MacOS DigitStealer malware poses as DynamicLake, targets Apple Silicon M2/M3 devices Read More »

Rhadamanthys infostealer operation disrupted by law enforcement

Rhadamanthys infostealer operation disrupted by law enforcement 2025-11-13 at 14:05 By Zeljka Zorz The rumors were true: Operation Endgame, a joint effort between law enforcement and judicial authorities of several European countries, Australia, Canada, the UK and the US, has disrupted the infrastructure supporting the operation of the Rhadamanthys infostealer. “Between 10 and 14 November

Rhadamanthys infostealer operation disrupted by law enforcement Read More »

GlassWorm Malware Returns to Open VSX, Emerges on GitHub

GlassWorm Malware Returns to Open VSX, Emerges on GitHub 2025-11-10 at 14:46 By Ionut Arghire Three more VS Code extensions were infected last week and the malware has emerged in GitHub repositories as well. The post GlassWorm Malware Returns to Open VSX, Emerges on GitHub appeared first on SecurityWeek. This article is an excerpt from

GlassWorm Malware Returns to Open VSX, Emerges on GitHub Read More »

Attackers upgrade ClickFix with tricks used by online stores

Attackers upgrade ClickFix with tricks used by online stores 2025-11-07 at 15:42 By Zeljka Zorz Attackers have taken the ClickFix technique further, with pages borrowing tricks from online sellers to pressure victims into performing the steps that will lead to a malware infection. Push Security has spotted one of these pages, showing an embedded tutorial

Attackers upgrade ClickFix with tricks used by online stores Read More »

Google uncovers malware using LLMs to operate and evade detection

Google uncovers malware using LLMs to operate and evade detection 2025-11-05 at 20:53 By Zeljka Zorz PromptLock, the AI-powered proof-of-concept ransomware developed by researchers at NYU Tandon and initially mistaken for an active threat by ESET, is no longer an isolated example: Google’s latest report shows attackers are now creating and deploying other malware that

Google uncovers malware using LLMs to operate and evade detection Read More »

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns 2025-11-05 at 17:25 By Eduard Kovacs Google has released a report describing the novel ways in which malware has been using AI to adapt and evade detection. The post Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns

Malware Now Uses AI During Execution to Mutate and Collect Data, Google Warns Read More »

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks 2025-11-03 at 12:28 By Ionut Arghire PowerShell and .NET variants of the malware abuse AirWatch’s MDM API to establish a C&C communication channel. The post Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks Read More »

Scroll to Top