Wednesday 12 August 2026 14:00:06 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#Windows malware


When a Familiar Cleaner Becomes the Trapdoor

Published: 12 August 2026 12:39Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A counterfeit CCleaner installer is being tied to a browser-focused payload that researchers describe as GhostDesk, a reminder that trusted software brands can be turned into delivery systems for session theft.

Fake VPN Tests Are Becoming a Quiet Windows Delivery Trick

Published: 12 August 2026 10:46Category: Malware & BotnetsGeo: Europe / RussiaAuthor: SIGNALMONK

A recruitment-style lure that looks like routine onboarding can push a Windows machine into creating a scheduled task and fetching malware, turning hiring workflows into an attack surface.

When a Website, a Browser Prompt, and a Blockchain Join the Same Malware Supply Chain

Published: 11 August 2026 14:30Category: Malware & BotnetsAuthor: SIGNALMONK

ErrTraffic appears to combine compromised WordPress pages, ClickFix-style social engineering, rotating delivery domains, and Polygon smart contracts into a layered route for Windows malware.

Abyssos Puts Windows Control on Two Tracks: Shell Commands and Full Desktop Access

Published: 11 August 2026 10:39Category: Malware & BotnetsAuthor: IRONQUERY

A newly tracked C++ RAT is drawing attention because it combines remote shell access, VNC-style desktop control, and file-system control in a modular Windows malware family.

Fake Zoom Installers, Real Cross-Platform Risk: The Loader Trick Security Teams Keep Missing

Published: 08 August 2026 08:06Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A malware campaign tied to a Zoom-branded installer shows how a familiar software path can be repurposed to move the same threat across macOS and Windows.

QuickFox Installer Turns Into a Backdoor Delivery Route

Published: 05 August 2026 10:59Category: Malware & BotnetsGeo: Asia / ChinaAuthor: NEXUSGUARDIAN

A reported supply-chain compromise on a Windows installer shows how trusted download paths can become the first step in a malware infection.

Passkeys Were Supposed to Kill Password Theft. Malware Found the Device Instead.

Published: 04 August 2026 08:16Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

The risk is no longer just phishing: on a compromised Windows machine, synced passkeys can become part of the attacker’s path to account takeover.

When Passkeys Follow the Device, Malware Follows the Trust

Published: 04 August 2026 08:04Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

A new passkey attack write-up points to a harder truth about passwordless security: if the Windows endpoint is compromised, synced credentials can become part of the attacker’s path.

Passkeys Under Pressure: How a Compromised Windows PC Can Become the Weak Link

Published: 04 August 2026 02:03Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Three reported abuse paths show that passwordless login can still fail when malware already owns the endpoint and the local trust chain.

When a Trusted Installer Turns Hostile: CastleLoader’s Quiet Windows Trick

Published: 28 July 2026 15:21Category: Malware & BotnetsAuthor: IRONQUERY

A malware loader is being described as using signed installers, Mark-of-the-Web removal, and in-memory staging to reduce the warning signs defenders usually rely on.

The Windows Shadow Market Behind Cruciferra

Published: 27 July 2026 14:22Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A crypter called Cruciferra sits at the junction of malware packing, vulnerable-driver abuse, and process ghosting, showing how Windows stealth can be layered rather than improvised.

Ransomware Crew Turns the Browser Into a Hidden Relay

Published: 23 July 2026 19:29Category: Ransomware & ExtortionAuthor: HEXSENTINEL

A Rust implant linked to Chaos was found on a Windows machine moving command traffic through headless Chrome and Edge before encryption began.

TrickBot Hides in a Wireshark-Themed Update While DNS Carries the Noise

Published: 23 July 2026 10:12Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A familiar Windows malware family is being linked to a persistence trick that blends into routine admin work, while its control traffic shifts into DNS and away from the more obvious web channels.

Inside the Shadow Market for Windows Evasion: A Crypter Built to Disappear

Published: 21 July 2026 14:39Category: Malware & BotnetsAuthor: IRONQUERY

A reported Mono-based crypter marketed on underground forums is said to combine BYOVD and process ghosting, a pairing that can make RAT and infostealer delivery harder to spot and slower to investigate.

WebDAV, rundll32, and a Fileless Burglary of Browser and Telegram Secrets

Published: 21 July 2026 10:37Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A Windows delivery path built on trusted components and remote file retrieval is being used to chase passwords, active sessions, and wallet-related data with unusually little on-disk noise.

When a Calendar Becomes a Command Line: The HOLLOWGRAPH Abuse of Microsoft 365

Published: 21 July 2026 08:14Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A Windows malware sample has been tied to a covert Microsoft Graph channel that turns a Microsoft 365 calendar into a hidden rendezvous point for attacker instructions.

When a Calendar Becomes a Spy Channel: HOLLOWGRAPH and the New Abuse of Microsoft 365

Published: 21 July 2026 08:09Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A Windows malware implant is reported to hide its command traffic inside Microsoft 365 calendar activity, showing how trusted collaboration tools can be turned into covert control infrastructure.

The Font That Wasn’t a Font: Why a Simple Email Lure Can Still Reach Windows

Published: 17 July 2026 16:03Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A phishing wave labeled “TTF Trap” uses fake font files to make business-themed emails look routine, reminding defenders that the dangerous part is often the click, not the theme.

The Loader That Hid in Plain Sight: Malware Split Across 364 Windows Variables

Published: 17 July 2026 10:41Category: Malware & BotnetsAuthor: SIGNALMONK

A staged Windows chain used JScript, hidden PowerShell, and in-memory .NET execution to keep its payload off disk and harder to spot.

Old Rootkit, New Shadow: Daxin’s Return Shows How Windows Intrusions Hide in Plain Traffic

Published: 16 July 2026 10:36Category: Malware & BotnetsGeo: Asia / TaiwanAuthor: IRONQUERY

A resurfaced backdoor and a separate DLL implant found on the same Windows host highlight how attackers can combine low-level network manipulation with logon-time persistence.