Its decoded payloads search local drives, watch for new files, and send collected data to two command-and-control servers. The malware ...
A custom GPT titled Plus 5.6 has been sending people who search for ChatGPT to a counterfeit Cloudflare verification page, ...
Hackers use fake Zoom and PDF downloads to deliver signed MSP360 remote-control software, giving attackers access to business ...
VectraRAT is a $250/month Windows malware service that lets attackers steal data, run commands, and monitor victims.
NeedyMantis malware, linked to China-based threat actors, has silently infiltrated telecoms, universities, and government ...
The TASK#STOMP backdoor steals office documents on Windows PCs, grabs new files as they're saved, and can rebuild itself if partly removed.
Windows Developer Config automates setup for power users, killing MSN clutter and tweaking Windows 11 with one command. Here ...
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other ...
MSP360 phishing attacks abuse trusted remote-management tools to deploy ScreenConnect and maintain persistent access to Windows systems.
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM ...
HBO Max's verified Reddit account was hijacked to push 108 malicious ads using ClickFix, a technique that tricks victims into running dangerous commands.
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.