A Windows Trojan documented in late 2025 is a reminder that in modern development, project files can become attack surface, not just configuration.
A multi-stage Trojan tied to Visual Studio project files shows how ordinary build logic can turn into a supply-chain attack surface.
A reported Chinese-linked RAT pairs fake software downloads with gRPC-based command traffic, showing how modern delivery and transport choices can make old malware tradecraft harder to spot.
A booking-themed phishing wave aimed at hospitality workflows shows how attackers can stack ordinary tools - cloud sharing, ZIP files, LNK shortcuts, PowerShell, and Node.js - into a delivery chain that is harder to spot and block.
An internet-facing operator box leaked tools, logs, and target lists, turning a mass WordPress campaign into a rare view of how web intrusions are organized.
A staged abuse pattern built on public code hosting, Go, PowerShell, and dead-drop indirection shows how ordinary developer infrastructure can be repurposed for malware delivery.
A macOS infostealer campaign is blending social engineering, AppleScript, and LaunchDaemons to collect credentials and push fake crypto-wallet software onto infected Macs.
The destructive malware described here stands out because it bundles several impact modes into one implant, letting operators switch between wiping and encryption rather than relying on a single blunt tool.
A Windows shortcut, PowerShell, a legitimate Node.js runtime, and TON-based lookup logic point to a campaign built to keep command infrastructure flexible and hard to pin down.
A Golang-based malware family is reported to use a OneDrive-themed scheduled task for persistence, showing how ordinary Windows maintenance patterns can be repurposed for destructive operations.
Microsoft’s warning points to a troubling hybrid: a Go-based backdoor that can keep a foothold, collect data, and pivot into destructive action against Windows systems.
The malware wave tied to Odyssey shows how a Mac infection can move from browser logins to crypto holdings, while still hiding inside ordinary system behavior.
A GodDamn ransomware incident highlights a familiar but dangerous pattern: legitimate Windows tooling, credential harvesting, and rapid internal spread.
A June 3 incident tied to Huntress shows how AI-generated PowerShell can be used for Active Directory enumeration without introducing a new exploit chain.
Nozomi Networks Labs identified Apex2 and c2c/meow, two Golang-based malware families linked to faster IoT botnet attacks and a higher risk profile for OT environments.
A fresh look at RedHook suggests the threat is moving beyond ordinary permission abuse and into a more dangerous trust zone inside Android.
RedHook is being linked to a control-chain abuse pattern that uses Accessibility, Developer Options, and wireless debugging to reach Android shell-level privileges.
A counterfeit VPN installer is being used to seed GoodPersonRAT, a Windows RAT tied to keylogging, proxy abuse, and Telegram theft in a classic trust-hijacking pattern.
A legacy .NET ransomware binary protected with ConfuserEx and featuring Wake-on-LAN capability highlights how modern malware can combine obfuscation with reach-related design choices.
A multi-stage intrusion pattern tied to SNOW shows how attackers can braid together collaboration abuse, browser persistence, and WebSocket tunneling to make a single intrusion look like ordinary office noise.