A resurfaced recruitment-themed campaign is using SVG files as a delivery container, while a separate Ruby ecosystem intrusion underlines how quickly software trust can be turned against developers.
A malware campaign linked to SVG files and a separate RubyGems supply-chain incident show how developers can be targeted through the tools they use most.
A developer hiring exercise can look routine on the surface, yet the technical path underneath may hide staged malware, credential theft, and file harvesting.
A kernel-level implant and a pre-login Windows backdoor were found together, but their exact relationship and full impact remain unconfirmed.
A resurfaced backdoor and a separate DLL implant found on the same Windows host highlight how attackers can combine low-level network manipulation with logon-time persistence.
A reported Chinese-linked RAT pairs fake software downloads with gRPC-based command traffic, showing how modern delivery and transport choices can make old malware tradecraft harder to spot.
A fresh look at RedHook suggests the threat is moving beyond ordinary permission abuse and into a more dangerous trust zone inside Android.
A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.
A compliance-themed phishing wave aimed at Indian taxpayers shows how official-looking pressure and a signed Windows executable can work together to move remote-access malware onto a victim machine.
A reported SilverFox operation pairs ValleyRAT with a long infection chain and a kernel-rootkit claim, a combination that raises the stakes for detection and cleanup.
A reported ValleyRAT upgrade into an eight-stage chain ending in kernel-mode stealth shows why defenders treat driver-level malware as a different class of problem.
A credential-theft clue can be more than malware noise, especially when investigators use it to map a possible email-fraud path around a named maritime company.
A campaign tied to PolinRider has put malicious packages and browser extensions into npm, Packagist, Go, and Google Chrome, showing how one delivery pattern can travel across very different trust systems.
The latest ValleyRAT activity shows a layered Windows tradecraft chain built to stay in memory, reduce disk artifacts, and make routine detection harder for defenders.
A targeted lure against Japan’s hotel sector shows how complaint-themed emails and blockchain-backed infrastructure can be paired to make malware harder to disrupt.
A newly named loader linked to the StrikeShark cluster shows how public-facing application exposure, DLL side-loading, and in-memory staging can turn a routine foothold into a much harder problem.
A newly named loader family linked to StrikeShark shows how a small foothold can become a wider intrusion chain when the real goal is to stage Cobalt Strike Beacon.
A newly analyzed botnet turns aging routers and NAS appliances into scanning and tunneling nodes, showing how small edge devices can become useful infrastructure for hiding attacker origin and widening reach.
A previously undocumented botnet has been tied to thousands of outdated routers, showing how edge devices can be repurposed into quiet infrastructure for malicious traffic.
A seven-week campaign tied to Dropping Elephant mixed trusted web services with fast-changing infrastructure, showing how attackers can turn ordinary publishing and chat-link features into malware delivery paths.