Malware

Latest malware news, vulnerabilities, CVEs, and threat intelligence from 50+ trusted cybersecurity sources.

Evolving Cyber Threats: How ClickFix Malware Mutates into MetaStealer Attacks

ClickFix malware has evolved to deploy MetaStealer using fake CAPTCHAs, File Explorer exploits, and MSI-based lures, bypassing traditional security measures. This affects organizations and end-users relying on unpatched systems, particularly those with Windows-based environments. Immediate threat intelligence updates and behavioral monitoring are critical to mitigate risks.

#cybersecurity #malware #threat intelligence

Read full article →

SlopAds: How a Massive Ad Fraud Scheme Infected 224 Android Apps with 38M Downloads

A large-scale ad fraud operation, SlopAds, infiltrated 224 Android apps with 38 million downloads using steganography and hidden WebViews to generate 2.3 billion fraudulent ad bids daily. The scheme exploited legitimate apps to redirect users to threat actor-owned sites, undermining digital advertising and posing risks to users and businesses globally.

#ad fraud #cybersecurity #android malware

Read full article →

Google Removes 224 Malicious Android Apps Linked to Massive Ad Fraud Scheme

Google removed 224 malicious Android apps from the Play Store as part of the 'SlopAds' ad fraud operation, generating 2.3 billion fraudulent ad requests daily. The campaign targeted Android users, advertisers, and the integrity of the mobile ad ecosystem, exploiting automated clicks and hidden ad displays. Users and developers must remain vigilant to detect and prevent such stealthy fraud schemes.

#android malware #ad fraud #cybersecurity

Read full article →

FileFix Malware Campaign: How Fake Facebook Security Alerts Spread StealC Infostealers

The FileFix malware campaign exploits fake Facebook security alerts to distribute the StealC infostealer, tricking users into downloading malicious files that steal sensitive data. The campaign rapidly evolved from a proof-of-concept to a global threat within two months, targeting millions of users. Immediate vigilance and proactive security measures are required to mitigate risks.

#malware #cybersecurity #infostealer

Read full article →

FileFix Variant Exploits Multilingual Phishing Sites to Distribute StealC Malware: A Deep Dive

A new FileFix variant is distributing StealC malware via multilingual phishing sites, leveraging advanced obfuscation and anti-analysis techniques to evade detection. The campaign primarily targets users of social media and file-sharing platforms, with potential for large-scale data theft and credential harvesting. Organizations and end-users must prioritize enhanced phishing awareness and heuristic-based security measures to mitigate risks.

#stealc malware #phishing attacks #cybersecurity threats

Read full article →

FileFix Attack: How Steganography Hides StealC Malware in Fake Meta Account Suspensions

The FileFix attack leverages fake Meta account suspension warnings to trick users into downloading StealC infostealer malware hidden via steganography in seemingly legitimate files. This campaign targets Meta users globally, stealing sensitive data including login credentials, financial details, and browser history. Users are urged to verify suspicious communications before taking any action.

#steganography #stealc malware #social engineering

Read full article →

Mustang Panda Deploys SnakeDisk USB Worm: A New Cyber Threat Targeting Thailand

The China-linked APT group Mustang Panda deployed the SnakeDisk USB worm targeting Thai government networks, leveraging geopolitical tensions. SnakeDisk drops the Yokoi backdoor and establishes reverse shells for remote command execution via infected USB drives. The attack highlights the growing threat of USB-based malware in cyber espionage against high-value targets.

#mustang panda #snakedisk #usb worm

Read full article →

Massive Supply Chain Attack Compromises 40+ npm Packages: What Developers Need to Know

Attackers compromised over 40 npm packages, including the widely used `@ctrl/tinycolor` library (2.2M weekly downloads), by injecting malicious code to steal developer credentials, cloud secrets, and automate further repository compromises. This supply chain attack exposes all projects relying on these packages to credential theft, data exfiltration, and potential full system breaches. Developers must urgently audit dependencies, rotate exposed tokens, and monitor for suspicious activity.

#supply chain attack #npm security #malware

Read full article →

Chinese Malware Campaign Exploits SEO Poisoning and GitHub Pages to Target Users

A malicious SEO poisoning campaign is exploiting Chinese-speaking users by distributing malware (HiddenGh0st, Winos, kkRAT) through fake software websites ranked via manipulated search results. The attackers use lookalike domains and SEO plugins to deceive users into downloading trojanized software, posing significant risks to individuals and organizations relying on legitimate software sources. Immediate user vigilance and proactive security measures are critical to mitigate exposure.

#malware #seo poisoning #cybersecurity

Read full article →

Mustang Panda’s SnakeDisk USB Worm: Targeting Thailand with Yokai Backdoor

China-aligned APT group Mustang Panda deployed a novel USB worm named SnakeDisk and updated TONESHELL backdoor to infect systems with Thailand-based IP addresses, delivering the Yokai backdoor for espionage. This campaign specifically targets government and private sector entities in Thailand via removable media, enabling data theft and persistence. Immediate mitigation is critical to prevent lateral spread within affected networks.

#mustang panda #cybersecurity #usb worm

Read full article →

Emerging Malware Threats: Key Insights from Security Affairs Newsletter Roundup

State-sponsored threat actors compromised the widely used npm packages `debug` (v4.3.1) and `chalk` (v4.1.2) to inject malicious JavaScript code, allowing remote code execution (RCE) in downstream applications. The attack targeted developers across Western Europe and the U.S., potentially exposing thousands of projects to supply-chain risks and data breaches.

#malware #cybersecurity #threat intelligence

Read full article →

Apple Spyware Alerts: CERT-FR Confirms Targeted Attacks on iCloud-Linked Devices

Apple issued four spyware attack warnings in 2025 targeting iCloud-linked devices via email, iMessage, and iCloud login notifications. CERT-FR confirmed these highly sophisticated, zero-day exploits targeted high-risk individuals including journalists, activists, and executives, requiring no user interaction. Users are advised to preserve evidence, update devices, and enable Lockdown Mode to mitigate risks.

#spyware #apple #cybersecurity

Read full article →

HybridPetya Ransomware Exploits CVE-2024-7344 to Bypass UEFI Secure Boot: What You Need to Know

HybridPetya ransomware exploits CVE-2024-7344 to bypass UEFI Secure Boot on Microsoft Windows systems, enabling execution even on protected firmware. This attack combines MBR overwrite capabilities with file encryption, threatening enterprise and individual users by rendering systems unbootable or data inaccessible without decryption keys.

CVEs: CVE-2024-7344

#ransomware #cybersecurity #uefi

Read full article →

HybridPetya Ransomware: How It Bypasses UEFI Secure Boot and Threatens System Security

HybridPetya ransomware bypasses UEFI Secure Boot by infecting the EFI System Partition, enabling persistent, pre-OS execution of malicious payloads. This attack threatens all modern systems relying on UEFI Secure Boot, including enterprise workstations, servers, and IoT devices, with potential for full system compromise and data encryption. Immediate mitigation is critical to prevent widespread exploitation and data loss.

#ransomware #uefi secure boot #cybersecurity threats

Read full article →

EggStreme Malware: How China-Linked Cyber Threats Targeted Philippines Military

Bitdefender researchers uncovered the EggStreme malware, a fileless in-memory framework linked to Chinese APT groups, deployed against a Philippines military company to establish persistent access for cyber espionage. The attack leverages advanced evasion techniques to evade detection, highlighting the growing risk of state-sponsored cyber operations targeting critical infrastructure. Immediate mitigation is required to prevent further compromise of sensitive systems.

#cybersecurity #malware #threat-intelligence

Read full article →

ConnectWise ScreenConnect Exploited: Hackers Deploy AsyncRAT via Fileless Malware Tactics

Threat actors exploited ConnectWise ScreenConnect to deploy AsyncRAT via fileless malware techniques using VBScript and PowerShell loaders. This campaign affects IT professionals and MSPs using ScreenConnect, enabling data theft and persistent access to compromised systems. Organizations must urgently mitigate unauthorized ScreenConnect deployments to prevent in-memory execution of malicious payloads.

#asyncrat #fileless malware #cybersecurity

Read full article →