Cemu Emulator Compromised with Malware in Linux Downloads
Article Content
- •Cemu 2.6 was compromised by a pro-Russian threat actor affecting Linux builds.
- •Malware targets SSH keys and GitHub tokens, facilitating further infections.
- •Users in Israel face an additional risk of filesystem wipe via a specific malware payload.
The Cemu emulator version 2.6 was compromised between May 6 and May 12, 2026, by a pro-Russian threat actor. The attack affected Linux users who downloaded the AppImage and Ubuntu zip files during this period. Windows and macOS users were not impacted, nor were those using Flatpak. The malware primarily aims to steal SSH keys, GitHub tokens, and passwords, potentially allowing further infections. A specific payload targets users in Israel, attempting to play a siren and wipe the filesystem. The compromised files have since been removed from GitHub, and users are advised to delete affected binaries and reset passwords. The developers are still investigating the full extent of the malware's capabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cemu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
KATARU IoT Malware Exploits Linux Vulnerabilities for DDoS Attacks The KATARU malware targets internet-exposed IoT devices using Telnet credential brute-forcing. Once access is gained, it attempts to escalate privileges using public Linux exploits, including CVE-2026-46300, CVE-2026-43284, and CVE-2026-31431. The malware combines Mirai-style DDoS capabilities with encrypted…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…