malware
131 stories on malware, newest first, from 137 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- New Lunex Stealer Uses Fake CAPTCHA Pages and a Vulnerable AMD Driver to Blind Security Tools
- Old Malicious GitHub Actions Briefly Reactivated, Reviving Mini Shai-Hulud Threat
- SectopRAT Malware Resurfaces, Hiding Inside Trusted Software
- Widely Used 'Example' Domain Now Serving Malware to Windows Users
- Fake Cloudflare Checks on Hacked Ukrainian Sites Spread New "Psychedelic" Stealer Malware
- Fake Logistics Apps Hide 'Corp MDM' Spyware That Steals SMS and Hijacks Calls
- ClickFix Attack Now Tops Enterprise Break-Ins, Tricking Users Into Infecting Themselves
- Malicious Terraform Providers and Go Modules Used to Spread North Korea-Linked Malware
- AI-Driven Malware CLOSEDQUORUM Lets Chatbots Vote on Its Next Attack Step
- Malicious npm and PyPI Packages Deliver Credential-Stealing Malware to Developers
- Chinese Hackers Exploit Chrome and Windows Zero-Days to Deploy New CLEANGULP Malware
- Researchers Uncover Windows Malware That Lets AI Models Choose Its Next Move
- New Windows Malware Lets AI Models Decide What to Steal Next
- Malicious npm Package Skips Install Scripts, Hides Malware in Application Code Instead
- Pakistan-Linked SideCopy Hackers Expand Spear-Phishing Attacks to Indian Universities
- Malware Hidden in Pirated Movie Torrents Targets African Users
- Fake LastPass Authenticator on GitHub Uses Signed Driver to Disable Security Software
- North Korean 'Contagious Interview' Scam Hits 30,000 Devices, Steals Over $10 Million in Crypto
- New TASK#STOMP Malware Campaign Steals Documents, Wi-Fi Passwords and Clipboard Data
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- Fake Job Interviews Target Rust Developers to Spread Malware
- Dark Web Roundup: Citizen Data Leak, Multi-Function Malware Kit, and Financial Database for Sale
- New ChainScript Malware Uses ClickFix Scams and Blockchain Tricks to Stay Hidden
- North Korea's Fake Job Interviews Have Infected 30,000 Devices
- Pakistan-Linked Hacking Group Uses GitHub to Control New Backdoor Targeting Government Agencies
- New 'WeaselBiscuit' Malware Found Hidden in 13 npm Packages Targeting Developers
- Weekly Threat Roundup: Gaming Videos and 'Trojanized' Software Used to Spread Malware
- Three Ukrainians Charged Over Mass Theft of 610,000 Roblox Accounts
- Fake 'macOS Toolkit' Sites Spreading AMOS Stealer Malware
- Brazilian Banking Malware 'KREMLIN' Uses Ethereum to Hide Its Command Infrastructure
- Behind the Betting Wheel: How Illegal Gambling Sites Hide Serious Cyber Threats
- New KREMLIN Malware Hijacks Chrome and Edge to Steal Banking Logins
- Iranian State Hackers Deploy 'Chosen Brick' Malware via Fake Apps on WhatsApp and Telegram
- Iran-Linked Malware Spies on Dissidents via Telegram Control
- New BambooToken Malware Hijacks IoT Protocol to Control Windows and Linux Machines
- Pro-Ukraine Hacktivist Group Escalates to Destructive Malware Attacks
- Fake Government Websites Used to Scam Users in Central Asia
- Malicious Twitch Browser Extension Steals 31,000 Users' Account Tokens
- New RAT-as-a-Service 'VectraRAT' Found Targeting Corporate Windows Systems
- Cyclops Blink Malware Returns, Now Targeting Linux Firewalls Directly
- Fake Browser Extensions Caught Stealing Crypto Wallet Data and Login Tokens
- ClickFix Scam Evolves: Fake Crypto 'Exploits' Trick Users into Hijacking Their Own Browsers
- Hidden in Plain Sight: Malware Campaign Uses YouTube and Fake Software to Infect Thousands
- F5 BIG-IP APM Attackers Hide Malware in Memory to Dodge Disk Scans
- ClickFix Scams Evolve: Attackers Abuse Trusted Services to Stay Hidden
- Fake 'Verification' Pages Trick Users into Running Hidden Malware Loaders
- BengalSEO Campaign Poisons Bing Results to Spread MayaBot Malware and Scam Call Centres
- PEEP Malware Turns Chrome and Edge Into Backdoors on Already-Compromised Machines
- Worm-Like Attack Turns ScreenConnect Into a Malware Delivery Chain
- JSCeal Malware Steals Browser Sessions to Bypass Google Login Security
- New Malware Toolkit Disables Windows Defender and Updates to Hide a Crypto Miner
- Trojanized HAProxy Builds Used to Hijack Web Traffic in South Korea
- BraZetsu Malware Fuels Underground Market for Hacked Windows Computers
- Hackers Exploit Trusted Node.js Tool to Sneak Malware Past Defences
-
Decades-Old Sality Botnet Dismantled in Global Law Enforcement Operation
Also covered by The Hacker News
- Fake Software Download Sites Used to Disable Windows Security Defences
-
Russian National Extradited Over Malware Scheme Targeting Freelance Platform Users
Also covered by The Hacker News
- Government and Education Websites Hijacked to Push Betting Scams
-
Decades-Old Sality Botnet Finally Taken Down
Also covered by Decrypt
- Fake CAPTCHA Prompts Hide Malware in Blockchain-Powered Attack
- Five Plead Guilty in ATM 'Jackpotting' Scheme in the US
- Russia-Linked Hackers Try to Trick AI Security Tools With Fake 'Nuclear Weapon' Prompt
- Inside the Takedown of Sality: A Long-Running Peer-to-Peer Botnet
- New 'TerminalFix' Attack Tricks Users Into Running Malicious PowerShell Commands
- Researchers Crack Open JSCeal, a Crypto-Stealing Malware Hidden in Compiled Code
- Fake Wallpaper App Used to Sneak ValleyRAT Backdoor Past Antivirus
- Anthropic Alerts Claude Users to Infostealer Malware Risk
- Voice Phishing Scam Uses Microsoft Teams to Break Into Business Networks
- 18 Chrome and 1 Edge Extension Caught Stealing Crypto Wallets
- New GoCaracal Malware Uses Ethereum Blockchain to Stay in Contact With Hackers
- New Malware Campaign Disables Security Software Using a Trusted Driver
- New GoCaracal Malware Uses Ethereum Blockchain to Hide Its Command Servers
- New Malware 'GoCaracal' Uses Ethereum Blockchain as Backup Hacking Channel
- Russian State Hackers Target European Diplomats with New Backdoor Malware
- State-Linked Hackers Unveil New Espionage Malware 'GoCaracal'
- Iranian State-Backed Hackers Add New Backdoor and Tunneling Tool to Arsenal
- AI Helps Hackers Write Malware Faster—But Not Better, Study Finds
- New 'SLEEPWALKER' Backdoor Hides Silently Until a Secret Signal Activates It
- Critical Gitea Flaw Under Active Attack — Patch Now Before It Drops Malware
- New RATs Hide Commands Inside FTP Server Banners
- New Malware Targets Car Infotainment Systems, Feeds Global Botnet
- New ClickFix Malware Trick Hides Attacks as Plain Text Files
- Fake Minecraft Downloads Used to Spread 'Weedhack' Malware
- New 'SynkLoader' Malware Combines Old Tricks with Modern Evasion to Steal Passwords
- ToxicPanda Banking Trojan Evolves, Expanding Beyond Personal Finance Apps
- New Malware Loaders WordlistLoader and SynkLoader Target Windows Users
- Chinese Hackers Use Fake Graduation Invites to Breach Myanmar Government Systems
- Banking Trojans on the Rise: What Small Businesses Should Know About Manic, Grandoreiro and ToxicPanda 2.0
- Banking Trojan 'Grandoreiro' Returns With New Tricks Despite Police Takedown
- New 'SPECTRE' Malware Uses Advanced Tricks to Hide from Security Software
- Chinese-Speaking Hackers Deploy AI to Automate Attacks After Breaching Web Servers
- New Espionage Campaign 'SilkParasite' Deploys Five Undocumented Hacking Tools
- Nearly 2,000 Hacked WordPress Sites Turned Into Malware Distribution Network
-
New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services
Also covered by The Hacker News
- Fake RubyGems Packages Caught Stealing Browser Data and Crypto Wallets
-
AI Agents Turned Rivals: Anthropic Testing Reveals Self-Replicating Malware Risk
Also covered by Security Week
- Critical macOS Screen Sharing Flaw Exploited for Silent Crypto Mining
- Cybercriminals Spend Millions Buying Expired Domains to Spread Scams and Malware
- Chinese Hacking Group Adds Stealth Rootkit to Evade Detection
- New macOS Malware 'AmnesiaStealer' Targets Passwords and Browser Data
- 737 Fake VPN Extensions Found Hijacking Browser Traffic in Chrome Web Store
- Supply Chain Attack on LiteLLM Hits Over 2,500 Organizations
- North Korean Hackers Exploit New Windows Zero-Day to Seize Control of Victim Systems
- Fake Job Interviews Used to Trick IT Workers Into Installing Malicious VPN Software
- New Kimwolf v7 Botnet Targets Android IoT Devices with Advanced Evasion Tricks
- New 'Aeternum' Malware Uses Blockchain to Hide Its Command Centre
- North Korean Hackers Go Offline with Custom AI to Supercharge Cyberattacks
- Fake VS Code Extension 'Solidity Pro' Caught Stealing Crypto Wallets and Credentials
-
Microsoft Uncovers Malware Hiding Commands in Blockchain Smart Contracts
Also covered by Blockonomi
- Nearly 800 Fake npm Packages Caught Spreading Malware Across Windows, Mac and Linux
- New Mac Malware Uses Fake 'Fix It' Prompts to Steal Crypto and Passwords
- Hackers Use Fake CAPTCHAs and Blockchain Tricks to Spread Malware
- Fake CAPTCHA Scam Uses Blockchain to Deliver Malware
- Windows Hello for Business Flaw Lets Malware Hijack Cloud Logins
- North Korean Hackers Hijack Telegram Accounts to Target Crypto Professionals
- Microsoft Warns of ClickFix Malware Campaign Abusing Blockchain to Evade Takedowns
- Microsoft Warns of ClickFix Malware Using Blockchain to Hide Attack Instructions
- Microsoft Warns Hackers Are Using Blockchain to Hide Malware from Takedown Efforts
- Microsoft Uncovers Malware Campaign Abusing BNB Smart Chain
- ThreatsDay Roundup: RCE Flaws, One-Click Exploits, and Trusted Tools Turned Against You
- Hackers Exploit SQL Injection to Hijack Oracle Databases and Gain Full System Control
- Fake 'ClickFix' Sites Now Screen Visitors Before Delivering Mac Malware
- Hackers Hide Malicious Server Addresses Inside Fake Ethereum Transactions
- Passkeys Aren't Foolproof: New Malware Attacks Target Google's Synced Passkeys
- 77 Fake Extensions Caught Stealing Developer Data from Open VSX Marketplace
- Massive Supply Chain Attack Hits Over 400 NPM Software Packages
- AI Agent Caught Trying to Sneak Malware Into Open-Source Software — Then Covered Its Tracks
- Beware Fake Adobe and Zoom Update Pop-Ups Hiding Remote Access Malware
- New Russian 'DOUBLECUP' Malware Service Hides Malicious Code in Cached Images
- Malicious npm Packages Target Alibaba Developer Tool Users With Hidden Remote Access Trojan
- Malware Could Bypass Passkey Security in Google Password Manager, Researchers Warn