Tuesday 14 July 2026 21:27:51 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

July 2026

03 July 2026


When Devices Outlive Their Support, Attackers Move In Quietly

Published: 03 July 2026 18:16Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A weekly security roundup points to a familiar pattern: stale endpoints, obscure payloads, and consumer devices that behave more like unmanaged computers than appliances.

Two Million Ghost Devices, One Proxy Machine: The Hidden Layer Behind a Botnet Disruption

Published: 03 July 2026 16:38Category: Malware & BotnetsGeo: Middle East / IsraelAuthor: NEXUSGUARDIAN

A reported disruption involving NetNut points to a wider problem in cybercrime: residential proxy infrastructure turns ordinary devices into disposable cover for abuse.

Fake Clipboard Tool Turns a Familiar Mac Utility into a Password Trap

Published: 03 July 2026 16:08Category: Malware & BotnetsAuthor: IRONQUERY

A lookalike of an open-source clipboard manager is being used as a lure for a macOS infostealer that leans on native automation, local password checks, and clipboard scraping.

When a CAPTCHA Becomes the Malware Trigger

Published: 03 July 2026 14:41Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Fake Google and Cloudflare verification screens are being used as a trust trap, pushing victims to run commands that load a rotating mix of stealers, loaders, and remote access tools.

Fake Verification Pages Are Becoming Malware Front Doors

Published: 03 July 2026 14:39Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

ClickFix lures that impersonate Google and Cloudflare turn a routine browser check into a user-driven launchpad for stealers, loaders, and remote-access malware.

The Fake Clipboard Trap: A macOS Stealer That Checks Passwords on the Machine It Just Infected

Published: 03 July 2026 14:17Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A disguised Mac utility, a two-stage payload, and local password validation through PAM reveal a stealthier playbook for credential theft.

Fake Utility, Real Password Risk: Inside the Mac Stealer Dressing Up as Maccy

Published: 03 July 2026 12:42Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A compiled AppleScript lure, a cloned download page, and a local authentication check show how macOS trust can be turned against the user.

The Loader That Hides in Plain Memory

Published: 03 July 2026 10:37Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A newly identified Windows loader shows how operators can pair fake installers and exposed services with in-memory Beacon staging to make intrusion chains harder to spot.

When a Fake Transcript Becomes the Doorway: PureLog Stealer’s Quiet Web Trap

Published: 03 July 2026 10:35Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A deceptive file name, compromised websites, and PowerShell show how modern infostealers can lean on trust rather than flashy exploits.

When a PDF Is Not a PDF: The VEIL#DROP Chain Hiding Malware in Plain Sight

Published: 03 July 2026 10:30Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A document-themed JavaScript lure, PowerShell, and Blogspot form a delivery chain that pushes PureLog Stealer into memory, showing how familiar tools can be bent into a stealthy malware pipeline.

When Residential Proxies Become the Mask: A Disruption Hits the Abuse Layer

Published: 03 July 2026 08:22Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

Google said it disrupted a residential proxy botnet used for malware control traffic and password spray attacks, with FBI, Lumen, and other partners involved.

Proxy Shadows: Why a Residential Network Takedown Matters Beyond One Brand

Published: 03 July 2026 08:09Category: Malware & BotnetsGeo: Middle East / IsraelAuthor: NEXUSGUARDIAN

Google, with the FBI, Lumen, and other partners, reportedly moved against NetNut, also tracked as Popa, in a case that spotlights how residential proxy infrastructure can support malware command-and-control.

SharkLoader and the Windows Trapdoor That Can Hide Cobalt Strike in Memory

Published: 03 July 2026 08:05Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

The reported chain turns DLL loading behavior into an execution path, showing how a trusted Windows mechanism can be bent to stage Beacon without obvious on-disk clues.

July 2026