Hidden desktops are a legitimate Windows capability, often used by specialized software, and occasionally used by malware. MedusaHVNC is a remote access trojan (RAT) being sold as malware-as-a-service (MaaS). It is promoted through its own website and a Telegram channel. It was found and analyzed by BlackFog, with the analysis finding a hidden virtual network ..
Tag : malware
A recently discovered piece of malware abuses the Microsoft 365 calendar for command-and-control (C&C) communication, Group-IB reports. Dubbed HollowGraph, the malware is believed to be part of a larger toolkit and is likely linked to Cavern Manticore, an Iran-nexus threat actor that Check Point detailed earlier this month. The malware’s communication mechanism relies on the ..
Two recently patched SonicWall appliance zero-days were exploited by threat actors for weeks before patches were released, according to cybersecurity firm Volexity. SonicWall released a public advisory for the vulnerabilities on July 14, informing customers that CVE-2026-15409 and CVE-2026-15410 had been exploited in the wild. Remote, unauthenticated attackers can exploit the flaws to hack SMA1000 ..
Il team GReAT di Kaspersky ha documentato nel report di Securelist OkoBot, un framework malevolo composto da oltre venti moduli che colpisce gli utenti di criptovaluta su Windows. La catena di attacco è stata ridisegnata a fine aprile 2025; la telemetria sulle vittime copre il periodo aprile 2025-giugno 2026 e GReAT ne ha identificato gli ..
A new macOS malware named ClickLock Stealer leverages social engineering and process killing to bypass the operating system’s protections and obtain valuable information from victims. Cybersecurity firm Group-IB came across ClickLock Stealer in early June, and the malware appears to have been around since at least late May. Researchers say it has targeted at least ..
Microsoft, law enforcement, and several cybersecurity companies have collaborated to take down infrastructure shared by two widely used malware families: Amadey and StealC. The action, part of the long-running Operation Endgame, involved the use of AI, legal action, and the exploitation of a vulnerability in a malware control panel, and resulted in hundreds of domains ..
An initial access broker (IAB) linked to multiple ransomware families has been using a new remote access trojan (RAT) in recent attacks, Broadcom’s Symantec and Carbon Black threat hunter team reports. The threat actor, tracked as Woodgnat and KongTuke, and active since at least May 2024, is known to have ties to ransomware groups such ..
Microsoft warns of a Windows-based cryptocurrency clipper that establishes a lightweight backdoor blending data exfiltration and remote code execution (RCE) capabilities. Dubbed CryptoBandits, the malware has been used in attacks since February 2026, deploying a portable Tor client on the infected systems and routing traffic through a local SOCKS5 proxy. “The clipper in this campaign ..
Google (Google Play) Honor (HONOR App Market) OPlus (OPPO App Market) Samsung (Galaxy Store) Transsion (Palm Store) vivo (V-Appstore) Xiaomi (GetApps) Developers will also have access to new APIs to make registering as an external developer less arduous. In the coming months, Google will release an Android Developer ID Status API that will check if ..
Giu 04, 2026 Giancarlo Calzetta Attacchi, In evidenza, News, RSS, Scenario 0 Un gruppo cybercriminale di lingua cinese fino a poco tempo fa concentrato prevalentemente sul mercato asiatico sta ampliando rapidamente il proprio raggio d’azione verso Europa e Africa. Secondo le analisi pubblicate da Proofpoint, il gruppo chiamato TA4922 ha aumentato sensibilmente il volume delle ..


