A newly identified remote access trojan, a multi-stage ClickFix chain, and blockchain-based control suggest a malware path built for persistence and stealth, not just immediate disruption.
A hype-fueled download bait is being used to push password stealers, RATs, and destructive payloads through convincing fake game files.
Fake recruiter outreach and trojanized coding assessments are turning routine hiring conversations into a delivery path for previously undocumented RATs aimed at developer machines.
Trojanized DMG and PKG files are being used to push OtterCookie RAT through a Contagious Interview-linked campaign, turning ordinary software trust into the attack path.
A streaming-themed Android campaign shows how a single accessibility grant, paired with VNC-style control, can turn a consumer phone into an operator-driven device.
A trojanized Exodus wallet installer is being used to drop a modular RAT that focuses on credentials, cookies, and live operator access rather than a quick hit on crypto balances.
Fake coding exercises are being used as a malware lure against developers, with researchers attributing the campaign with high confidence to Mirage Kitten.
A phishing chain tied to the cluster tracked as TA4922 shows how tax-themed email can be turned into a delivery path for a modular RAT, staged loaders, and follow-on access tooling.
A tax-themed lure linked to TA4922 shows how localized phishing and commodity malware can be fused into a repeatable access playbook without proving full compromise.
A malware campaign aimed at Cambodian users and organizations combines social engineering with a vulnerable driver to make endpoint protection harder to trust.
A Russia-focused espionage cluster is now being linked to CoreRAT, a homegrown implant that marks a shift away from borrowed remote-control tools and toward tighter operator control.
A custom remote access trojan linked to Core Werewolf shows how espionage crews can turn infected Windows systems into interactive workspaces for command execution, information gathering, payload downloads, and cleanup.
A campaign tied to two newly named RAT families uses FTP banners as dead drop resolvers, showing how a routine protocol greeting can be turned into a covert routing layer.
Security researchers traced a campaign that hides commands in FTP server banners to help deliver two previously undocumented Windows RATs, E4del and PINHOLE.
A multi-implant intrusion set aimed at government networks shows how modern espionage can be built for persistence, redundancy, and hard-to-trace access.
A Central Asia-focused intrusion cluster linked to seven RAT families shows why defenders should hunt for behavior, not cling to a single malware name.
A lure built around Claude installation help shows how sponsored search, trusted web properties, and macOS prompts can be stacked into one convincing credential-theft chain.
A convincing software-onboarding lure is being used to push Mac users toward MacSync, turning search trust into a route to credential theft and crypto wallet risk.
A fake recruiting flow, a cloud-doc decoy, and a trusted Windows install path formed a chain that could push a target from conversation to compromise without a classic exploit.
A legal-themed email, an SVG file, and two classic Windows trust-abuse techniques show how commodity malware can disappear into ordinary process activity.