A counterfeit CCleaner installer is being tied to a browser-focused payload that researchers describe as GhostDesk, a reminder that trusted software brands can be turned into delivery systems for session theft.
A recruitment-style lure that looks like routine onboarding can push a Windows machine into creating a scheduled task and fetching malware, turning hiring workflows into an attack surface.
ErrTraffic appears to combine compromised WordPress pages, ClickFix-style social engineering, rotating delivery domains, and Polygon smart contracts into a layered route for Windows malware.
A newly tracked C++ RAT is drawing attention because it combines remote shell access, VNC-style desktop control, and file-system control in a modular Windows malware family.
A malware campaign tied to a Zoom-branded installer shows how a familiar software path can be repurposed to move the same threat across macOS and Windows.
A reported supply-chain compromise on a Windows installer shows how trusted download paths can become the first step in a malware infection.
The risk is no longer just phishing: on a compromised Windows machine, synced passkeys can become part of the attacker’s path to account takeover.
A new passkey attack write-up points to a harder truth about passwordless security: if the Windows endpoint is compromised, synced credentials can become part of the attacker’s path.
Three reported abuse paths show that passwordless login can still fail when malware already owns the endpoint and the local trust chain.
A malware loader is being described as using signed installers, Mark-of-the-Web removal, and in-memory staging to reduce the warning signs defenders usually rely on.
A crypter called Cruciferra sits at the junction of malware packing, vulnerable-driver abuse, and process ghosting, showing how Windows stealth can be layered rather than improvised.
A Rust implant linked to Chaos was found on a Windows machine moving command traffic through headless Chrome and Edge before encryption began.
A familiar Windows malware family is being linked to a persistence trick that blends into routine admin work, while its control traffic shifts into DNS and away from the more obvious web channels.
A reported Mono-based crypter marketed on underground forums is said to combine BYOVD and process ghosting, a pairing that can make RAT and infostealer delivery harder to spot and slower to investigate.
A Windows delivery path built on trusted components and remote file retrieval is being used to chase passwords, active sessions, and wallet-related data with unusually little on-disk noise.
A Windows malware sample has been tied to a covert Microsoft Graph channel that turns a Microsoft 365 calendar into a hidden rendezvous point for attacker instructions.
A Windows malware implant is reported to hide its command traffic inside Microsoft 365 calendar activity, showing how trusted collaboration tools can be turned into covert control infrastructure.
A phishing wave labeled “TTF Trap” uses fake font files to make business-themed emails look routine, reminding defenders that the dangerous part is often the click, not the theme.
A staged Windows chain used JScript, hidden PowerShell, and in-memory .NET execution to keep its payload off disk and harder to spot.
A resurfaced backdoor and a separate DLL implant found on the same Windows host highlight how attackers can combine low-level network manipulation with logon-time persistence.