Sunday 12 July 2026 05:13:49 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

Malware & Botnets / Europe


The Fake 7-Zip Trap That Turns a Download Into a Proxy Network

Published: 09 July 2026 08:33Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

A familiar utility brand, a lookalike domain, and a silent installer chain can be enough to turn a consumer PC into part of someone else’s network abuse.

Kazuar’s Old Trick, New Pressure: Trusted Processes Become the Hideout

Published: 07 July 2026 12:20Category: Malware & BotnetsGeo: Europe / RussiaAuthor: IRONQUERY

The backdoor linked to Turla has resurfaced with a loader chain built around DLL side-loading and PowerShell, a combination that can shrink obvious disk artifacts and complicate basic allowlist-based defenses.

The World Cup T-Shirt Trap: How a Familiar Lure Can Carry Malware

Published: 30 June 2026 18:14Category: Malware & BotnetsGeo: Europe / SwitzerlandAuthor: IRONQUERY

A fake FIFA World Cup 2026 merchandise offer shows how personalized branding and trusted web infrastructure can turn an inbox novelty into a malware delivery path.

SimpleHelp Login Trust Broken, Malware Chain Follows

Published: 30 June 2026 14:38Category: Malware & BotnetsGeo: Europe / United KingdomAuthor: SIGNALMONK

A critical authentication bypass in SimpleHelp’s OIDC flow may have let attackers obtain technician access and deliver two malware families, turning a remote support tool into a high-risk entry point.

STOCKSTAY and the Quiet Art of Looking Legitimate

Published: 29 June 2026 14:07Category: Malware & BotnetsGeo: Europe / RussiaAuthor: IRONQUERY

A .NET backdoor tied to stealthy WebSocket command traffic and environment-based keying shows how modern malware can hide inside ordinary application behavior.

Archive Lure, Secret Harvest: Why a WinRAR-Based Stealer Chain Deserves More Attention

Published: 29 June 2026 10:22Category: Malware & BotnetsGeo: Europe / UkraineAuthor: IRONQUERY

A reported GIFTEDCROOK campaign shows how a seemingly ordinary archive can be turned into a delivery path for browser, vault, VPN, and document theft.

When a Game Mod Becomes the First Stage of a Stealer Chain

Published: 26 June 2026 08:11Category: Malware & BotnetsGeo: Europe / SwedenAuthor: NEXUSGUARDIAN

A reported Minecraft Fabric mod campaign shows how trusted game add-ons can be used as an entry point for session-data theft and blockchain-resident command retrieval.

Operation Endgame Hits the Service Layer Behind Amadey and StealC

Published: 25 June 2026 06:58Category: Malware & BotnetsGeo: Europe / NetherlandsAuthor: IRONQUERY

A coordinated disruption against criminal infrastructure shows how botnets and infostealers depend on fragile command systems, not just malware code.

When a RAR File Becomes a Delivery System for Windows Persistence

Published: 24 June 2026 10:20Category: Malware & BotnetsGeo: Europe / UkraineAuthor: SIGNALMONK

A targeted campaign tied to Ukraine’s UAV ecosystem shows how a booby-trapped archive, a script loader, and a decoy document can turn routine file handling into a foothold.

SocGholish Knocked Back: Why This Takedown Hits the Crimeware Delivery Layer

Published: 23 June 2026 10:30Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

An international operation targeted SocGholish, also known as FakeUpdates, and disrupted an infrastructure described as tied to Evil Corp - a reminder that the front door of cybercrime is often more important than the payload behind it.

Why a Massive WordPress Cleanup Matters More Than a Takedown

Published: 19 June 2026 18:14Category: Malware & BotnetsGeo: Europe / NetherlandsAuthor: IRONQUERY

Dutch-led action against SocGholish-linked infrastructure and 14,971 infected WordPress sites points to a deeper fight over the web delivery layer that attackers rely on.

SocGholish Under Pressure as Police Target Its Malware Network

Published: 19 June 2026 16:26Category: Malware & BotnetsGeo: Europe / RussiaAuthor: SIGNALMONK

An international operation targeted SocGholish infrastructure, a reminder that disrupting a loader can matter as much as stopping the final payload.

SocGholish Hit in a Coordinated Sweep, but the Loader Era Is Not Over

Published: 19 June 2026 08:20Category: Malware & BotnetsGeo: Europe / NetherlandsAuthor: IRONQUERY

A multinational disruption of 106 servers and 101 domains shows how much modern malware depends on fragile web infrastructure, not just code on disk.

The Plugin Trap: How a Helpful AI Tool Can Turn Into a Secret Stealer

Published: 17 June 2026 13:03Category: Malware & BotnetsGeo: Europe / Czech RepublicAuthor: IRONQUERY

A batch of JetBrains add-ons posing as AI coding assistants highlights a familiar weakness in modern development: once a plugin is trusted, it may inherit far more access than users realize.

Fake AI Helpers Turn Developer Trust Into a Credential Trap

Published: 17 June 2026 12:17Category: Malware & BotnetsGeo: Europe / NetherlandsAuthor: SIGNALMONK

Malicious JetBrains plugins and suspicious browser add-ons are putting AI keys and chatbot conversations in the crosshairs, showing how software supply chains can become data-collection pipelines.

Fake Premium Tutorials Turn a Familiar Brand Into a Windows Command Trap

Published: 12 June 2026 10:15Category: Malware & BotnetsGeo: Europe / SwedenAuthor: SIGNALMONK

Short-form videos promising free Spotify Premium have been used as a lure, with Windows users directed toward PowerShell commands that can deliver malware.

C0XMO Turns Router Firmware Into a Fighting Pit

Published: 07 June 2026 18:05Category: Malware & BotnetsGeo: Europe / GermanyAuthor: IRONQUERY

A new Gafgyt variant is drawing attention for one reason that matters to defenders: it does not just infect edge devices, it also appears designed to keep rivals off them.

C0XMO Puts a Modular Face on Old Botnet Tradecraft

Published: 05 June 2026 15:21Category: Malware & BotnetsGeo: Europe / GermanyAuthor: NEXUSGUARDIAN

A reported Gafgyt-family variant combines split-up spread logic with multi-architecture payloads and a DD-WRT flaw, a reminder that commodity malware is becoming more adaptable, not less dangerous.

Tax Season as a Trapdoor: TA4922’s Loader Campaign Pushes into UK and European Workflows

Published: 03 June 2026 16:23Category: Malware & BotnetsGeo: Europe / UKAuthor: SIGNALMONK

A suspected China-aligned cluster is using tax-, payroll-, and benefits-themed lures to deliver SilentRunLoader, a reminder that routine business emails can be weaponized before any visible breach begins.

When Search and Video Became the Delivery Route for a Minecraft Malware Lure

Published: 03 June 2026 08:08Category: Malware & BotnetsGeo: Europe / SwedenAuthor: SIGNALMONK

WeedHack is being circulated through YouTube and SEO poisoning, a reminder that attackers increasingly target the way users discover downloads, not just the files themselves.