Threat hunters have shed light on a sophisticated and evolving malware toolkit called Ragnar Loader that's used by various cybercrime and ransomware groups like Ragnar Locker (aka Monstrous Mantis), FIN7, FIN8, and Ruthless Mantis (ex-REvil).
ClickFix malware has evolved to deploy MetaStealer using fake CAPTCHAs, File Explorer exploits, and MSI-based lures, bypassing traditional security measures. This affects organizations and end-users relying on unpatched systems, particularly those with Windows-based environments. Immediate threat intelligence updates and behavioral monitoring are critical to mitigate risks.
A large-scale ad fraud operation, SlopAds, infiltrated 224 Android apps with 38 million downloads using steganography and hidden WebViews to generate 2.3 billion fraudulent ad bids daily. The scheme exploited legitimate apps to redirect users to threat actor-owned sites, undermining digital advertising and posing risks to users and businesses globally.
Google removed 224 malicious Android apps from the Play Store as part of the 'SlopAds' ad fraud operation, generating 2.3 billion fraudulent ad requests daily. The campaign targeted Android users, advertisers, and the integrity of the mobile ad ecosystem, exploiting automated clicks and hidden ad displays. Users and developers must remain vigilant to detect and prevent such stealthy fraud schemes.
The FileFix malware campaign exploits fake Facebook security alerts to distribute the StealC infostealer, tricking users into downloading malicious files that steal sensitive data. The campaign rapidly evolved from a proof-of-concept to a global threat within two months, targeting millions of users. Immediate vigilance and proactive security measures are required to mitigate risks.
A new FileFix variant is distributing StealC malware via multilingual phishing sites, leveraging advanced obfuscation and anti-analysis techniques to evade detection. The campaign primarily targets users of social media and file-sharing platforms, with potential for large-scale data theft and credential harvesting. Organizations and end-users must prioritize enhanced phishing awareness and heuristic-based security measures to mitigate risks.
The FileFix attack leverages fake Meta account suspension warnings to trick users into downloading StealC infostealer malware hidden via steganography in seemingly legitimate files. This campaign targets Meta users globally, stealing sensitive data including login credentials, financial details, and browser history. Users are urged to verify suspicious communications before taking any action.
The China-linked APT group Mustang Panda deployed the SnakeDisk USB worm targeting Thai government networks, leveraging geopolitical tensions. SnakeDisk drops the Yokoi backdoor and establishes reverse shells for remote command execution via infected USB drives. The attack highlights the growing threat of USB-based malware in cyber espionage against high-value targets.
Attackers compromised over 40 npm packages, including the widely used `@ctrl/tinycolor` library (2.2M weekly downloads), by injecting malicious code to steal developer credentials, cloud secrets, and automate further repository compromises. This supply chain attack exposes all projects relying on these packages to credential theft, data exfiltration, and potential full system breaches. Developers must urgently audit dependencies, rotate exposed tokens, and monitor for suspicious activity.
A malicious SEO poisoning campaign is exploiting Chinese-speaking users by distributing malware (HiddenGh0st, Winos, kkRAT) through fake software websites ranked via manipulated search results. The attackers use lookalike domains and SEO plugins to deceive users into downloading trojanized software, posing significant risks to individuals and organizations relying on legitimate software sources. Immediate user vigilance and proactive security measures are critical to mitigate exposure.
China-aligned APT group Mustang Panda deployed a novel USB worm named SnakeDisk and updated TONESHELL backdoor to infect systems with Thailand-based IP addresses, delivering the Yokai backdoor for espionage. This campaign specifically targets government and private sector entities in Thailand via removable media, enabling data theft and persistence. Immediate mitigation is critical to prevent lateral spread within affected networks.
State-sponsored threat actors compromised the widely used npm packages `debug` (v4.3.1) and `chalk` (v4.1.2) to inject malicious JavaScript code, allowing remote code execution (RCE) in downstream applications. The attack targeted developers across Western Europe and the U.S., potentially exposing thousands of projects to supply-chain risks and data breaches.
Apple issued four spyware attack warnings in 2025 targeting iCloud-linked devices via email, iMessage, and iCloud login notifications. CERT-FR confirmed these highly sophisticated, zero-day exploits targeted high-risk individuals including journalists, activists, and executives, requiring no user interaction. Users are advised to preserve evidence, update devices, and enable Lockdown Mode to mitigate risks.
HybridPetya ransomware exploits CVE-2024-7344 to bypass UEFI Secure Boot on Microsoft Windows systems, enabling execution even on protected firmware. This attack combines MBR overwrite capabilities with file encryption, threatening enterprise and individual users by rendering systems unbootable or data inaccessible without decryption keys.
HybridPetya ransomware bypasses UEFI Secure Boot by infecting the EFI System Partition, enabling persistent, pre-OS execution of malicious payloads. This attack threatens all modern systems relying on UEFI Secure Boot, including enterprise workstations, servers, and IoT devices, with potential for full system compromise and data encryption. Immediate mitigation is critical to prevent widespread exploitation and data loss.
Apple has alerted users about targeted spyware attacks on their devices. Discover the details, potential risks, and steps to protect yourself from these sophisticated cyber threats.
Discover how cybercriminals are leveraging ConnectWise ScreenConnect to deploy AsyncRAT malware, stealing sensitive credentials and cryptocurrency. Learn about the attack mechanism, implications, and how to protect your systems.
Bitdefender researchers uncovered the EggStreme malware, a fileless in-memory framework linked to Chinese APT groups, deployed against a Philippines military company to establish persistent access for cyber espionage. The attack leverages advanced evasion techniques to evade detection, highlighting the growing risk of state-sponsored cyber operations targeting critical infrastructure. Immediate mitigation is required to prevent further compromise of sensitive systems.
Threat actors exploited ConnectWise ScreenConnect to deploy AsyncRAT via fileless malware techniques using VBScript and PowerShell loaders. This campaign affects IT professionals and MSPs using ScreenConnect, enabling data theft and persistent access to compromised systems. Organizations must urgently mitigate unauthorized ScreenConnect deployments to prevent in-memory execution of malicious payloads.
Discover how a sophisticated Chinese APT group deployed the undocumented EggStreme fileless malware to infiltrate Philippine military systems. Learn about the tactics, implications, and how fileless malware evades detection.
Discover the latest cybersecurity threats: CHILLYHELL, a macOS backdoor, and ZynorRAT, a Go-based RAT targeting Windows and Linux. Learn about their capabilities, risks, and how to protect your systems.
Discover how the ChillyHell macOS malware evaded Apple's security for four years, its potential origins, and the implications for cybersecurity. Learn how this modular backdoor operated undetected and what it means for macOS users.
Discover how cybercriminals are leveraging advanced phishing techniques and AI-driven malware like MostereRAT and ClickFix to bypass security measures. Learn about the evolving threats, evasion tactics, and how to protect your systems.
Discover how the GPUGate malware campaign uses deceptive Google Ads and fake GitHub commits to target IT firms. Learn about the tactics, risks, and how to protect your organization.
Explore the latest malware threats, APT campaigns, and cybersecurity risks in September 2025. Discover how North Korean APT37, Lazarus Group, and other threat actors are targeting global entities, along with insights into AI-driven attacks, cryptojacking, and ransomware detection methods.
Discover how VirusTotal uncovered a sophisticated phishing campaign using SVG files to impersonate Colombia’s judicial system and deliver malware. Learn about the risks, tactics, and how to protect yourself from this emerging cyber threat.
Discover how an AI-driven malware attack, dubbed 's1ngularity,' compromised 2,180 GitHub accounts, leaking sensitive tokens and repository secrets. Learn about the implications for cybersecurity and supply chain security.
Discover the groundbreaking story behind the first AI-powered ransomware, its origins as a research experiment, and its implications for cybersecurity. Learn how this innovation reshapes the threat landscape.
Discover how the threat actor TAG-150 has developed CastleRAT, a Remote Access Trojan (RAT) in Python and C, to enhance the capabilities of the CastleLoader malware-as-a-service (MaaS) framework.
Cybersecurity researchers reveal a sophisticated phishing campaign using SVG files to deploy Base64-encoded malicious pages. Learn how these undetected threats impersonate judicial systems and evade security measures.