malware
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync info-stealing malware targeting macOS systems now uses public iCloud calendar events to deliver fresh payloads. MacSync is a Swift-based malware that emerged in April 2025 and has been observed recently being delivered in ClickFix campaigns disguised as Homebrew and macOS disk space analyzer tools. Kaspersky researchers say that while […]
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. The malware features worm-like capabilities and was discovered in an unauthenticated Docker registry that contained nearly 60 repositories and 4.3 GB of image data. Researchers at enterprise security company ThreatDown retrieved operational evidence […]
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. Although the infrastructure has been active since at least May, the first samples were observed in July and contained more than 30 phishing overlays designed to steal banking credentials. Researchers at cybersecurity company Group-IB say […]
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. The Go-based malware acts with no commands from a human operator, using reconnaissance information and a voting system to decide its next step on infected hosts. When […]
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. The package, spotted by Checkmarx researchers, attempts to impersonate the legitimate ‘sorted-btree’ library and has already amassed 2 million weekly downloads. The campaign may […]
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. LastPass and Delphos Labs uncovered the campaign, which they report impersonates the password manager brand and at least 39 other companies. Alongside the Rapuncel infostealer, the repositories deliver a Microsoft-signed kernel driver that […]
New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. Zimperium zLabs researchers analyzed the malware and believe it is linked to threat actors from China after finding it using LLM prompts written in Chinese. The researchers say the malware is distributed through malvertising, […]
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. The malware features data theft and espionage capabilities that collect email, Telegram, and WhatsApp communications, take screenshots, and record audio. The threat actor primarily targeted individuals in the U.S., U.K., and […]
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. The malware adopted MQTT for command-and-control communications in variants developed between 2024 and 2025, compromising servers used by mobile apps, legal and financial services, and software […]
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. Researchers at cybersecurity company Gen Digital warn that the security issue is a one-click remote code execution (RCE) flaw. “We observed this vulnerability actively exploited in the wild by […]