Domingo 12 Julio 2026 17:28:07 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

Malware & Botnets


When a Build File Turns Hostile: The Quiet Malware Risk Inside Visual Studio Projects

Published: 11 July 2026 12:02Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A Windows Trojan documented in late 2025 is a reminder that in modern development, project files can become attack surface, not just configuration.

When a Build File Becomes the Breach Door

Published: 11 July 2026 08:04Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A multi-stage Trojan tied to Visual Studio project files shows how ordinary build logic can turn into a supply-chain attack surface.

Rust, Search Poisoning, and a Quiet C2 Channel: The MODBEACON Problem

Published: 10 July 2026 16:32Category: Malware & BotnetsGeo: Asia / ChinaAuthor: NEXUSGUARDIAN

A reported Chinese-linked RAT pairs fake software downloads with gRPC-based command traffic, showing how modern delivery and transport choices can make old malware tradecraft harder to spot.

Shortcut Trap, Cloud Link, Blockchain Path: A Clean-Looking Email Chain Hides a Dirty Payload

Published: 10 July 2026 14:41Category: Malware & BotnetsAuthor: SIGNALMONK

A booking-themed phishing wave aimed at hospitality workflows shows how attackers can stack ordinary tools - cloud sharing, ZIP files, LNK shortcuts, PowerShell, and Node.js - into a delivery chain that is harder to spot and block.

The Server That Betrayed the Hunters Behind a WordPress Backdoor Wave

Published: 10 July 2026 14:16Category: Malware & BotnetsAuthor: IRONQUERY

An internet-facing operator box leaked tools, logs, and target lists, turning a mass WordPress campaign into a rare view of how web intrusions are organized.

Hundreds of GitHub Repositories, One Malware Chain: The New Shape of Windows Staging

Published: 10 July 2026 13:02Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A staged abuse pattern built on public code hosting, Go, PowerShell, and dead-drop indirection shows how ordinary developer infrastructure can be repurposed for malware delivery.

Mac Malware Learns to Wear a Wallet: How Odyssey Stealer Uses Native macOS Tools for Theft

Published: 10 July 2026 12:38Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A macOS infostealer campaign is blending social engineering, AppleScript, and LaunchDaemons to collect credentials and push fake crypto-wallet software onto infected Macs.

GigaWiper’s Real Threat Is Not Speed - It Is Choice

Published: 10 July 2026 12:26Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

The destructive malware described here stands out because it bundles several impact modes into one implant, letting operators switch between wiping and encryption rather than relying on a single blunt tool.

When Malware Borrows a Blockchain: The TON Trick Behind a Windows Backdoor

Published: 10 July 2026 12:17Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A Windows shortcut, PowerShell, a legitimate Node.js runtime, and TON-based lookup logic point to a campaign built to keep command infrastructure flexible and hard to pin down.

One Drive, One Task, One Wiper: How a Destructive Implant Hides in Plain Sight

Published: 10 July 2026 10:32Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A Golang-based malware family is reported to use a OneDrive-themed scheduled task for persistence, showing how ordinary Windows maintenance patterns can be repurposed for destructive operations.

GigaWiper Turns Windows Access Into a Sabotage Tool

Published: 10 July 2026 10:23Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

Microsoft’s warning points to a troubling hybrid: a Go-based backdoor that can keep a foothold, collect data, and pivot into destructive action against Windows systems.

Odyssey’s macOS Playbook: A Stealer Built to Chase Passwords, Wallets, and Trust

Published: 10 July 2026 10:14Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

The malware wave tied to Odyssey shows how a Mac infection can move from browser logins to crypto holdings, while still hiding inside ordinary system behavior.

When Ransomware Borrows the Admin Desk: PsExec, Password Stores, and the Quiet Road to Encryption

Published: 09 July 2026 18:58Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A GodDamn ransomware incident highlights a familiar but dangerous pattern: legitimate Windows tooling, credential harvesting, and rapid internal spread.

PowerShell Under a Prompt Engine: The AD Recon Report That Changes the Defensive Lens

Published: 09 July 2026 18:45Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A June 3 incident tied to Huntress shows how AI-generated PowerShell can be used for Active Directory enumeration without introducing a new exploit chain.

Go Malware, Faster Bots, and the Quiet Threat Spilling Toward OT

Published: 09 July 2026 15:56Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

Nozomi Networks Labs identified Apex2 and c2c/meow, two Golang-based malware families linked to faster IoT botnet attacks and a higher risk profile for OT environments.

RedHook Returns With a Stranger Trick: Android Debugging Turned Into Malware Control

Published: 09 July 2026 15:53Category: Malware & BotnetsGeo: Asia / VietnamAuthor: NEXUSGUARDIAN

A fresh look at RedHook suggests the threat is moving beyond ordinary permission abuse and into a more dangerous trust zone inside Android.

Android Malware Turns a Safety Feature into a Shell-Access Path

Published: 09 July 2026 14:31Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

RedHook is being linked to a control-chain abuse pattern that uses Accessibility, Developer Options, and wireless debugging to reach Android shell-level privileges.

Fake VPN Lures Are Turning Trust Into a Malware Delivery Channel

Published: 09 July 2026 11:31Category: Malware & BotnetsGeo: Asia / ChinaAuthor: SIGNALMONK

A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.

Everest Sample Hides Its Tracks in .NET, Then Adds Wake-on-LAN to the Mix

Published: 09 July 2026 11:22Category: Malware & BotnetsAuthor: NEXUSGUARDIAN

A legacy .NET ransomware binary protected with ConfuserEx and featuring Wake-on-LAN capability highlights how modern malware can combine obfuscation with reach-related design choices.

Inside SNOW: A Phishing Chain That Hides in Chat, Browsers, and Web Traffic

Published: 09 July 2026 10:31Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A multi-stage intrusion pattern tied to SNOW shows how attackers can braid together collaboration abuse, browser persistence, and WebSocket tunneling to make a single intrusion look like ordinary office noise.