A booking-themed phishing wave aimed at hospitality workflows shows how attackers can stack ordinary tools - cloud sharing, ZIP files, LNK shortcuts, PowerShell, and Node.js - into a delivery chain that is harder to spot and block.
An internet-facing operator box leaked tools, logs, and target lists, turning a mass WordPress campaign into a rare view of how web intrusions are organized.
A staged abuse pattern built on public code hosting, Go, PowerShell, and dead-drop indirection shows how ordinary developer infrastructure can be repurposed for malware delivery.
A macOS infostealer campaign is blending social engineering, AppleScript, and LaunchDaemons to collect credentials and push fake crypto-wallet software onto infected Macs.
The destructive malware described here stands out because it bundles several impact modes into one implant, letting operators switch between wiping and encryption rather than relying on a single blunt tool.
A Windows shortcut, PowerShell, a legitimate Node.js runtime, and TON-based lookup logic point to a campaign built to keep command infrastructure flexible and hard to pin down.
A Golang-based malware family is reported to use a OneDrive-themed scheduled task for persistence, showing how ordinary Windows maintenance patterns can be repurposed for destructive operations.
Microsoft’s warning points to a troubling hybrid: a Go-based backdoor that can keep a foothold, collect data, and pivot into destructive action against Windows systems.
The malware wave tied to Odyssey shows how a Mac infection can move from browser logins to crypto holdings, while still hiding inside ordinary system behavior.