The Mistic malware, a newly identified Windows backdoor, has been active since April 2026, utilizing DLL sideloading to infiltrate enterprise environments. It exploits a legitimate executable, MpExtMs.exe, to load a…
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…
Cyberattackers have been exploiting DNS TXT records within the ClickFix script to execute malicious PowerShell commands. This tactic has been linked to the KongTuke campaign, which has been active since mid-2025 and…
A malicious campaign named CrashFix has been identified, utilizing a fake ad-blocking browser extension called NexShield to crash users' browsers. This tactic is employed to facilitate ClickFix attacks, delivering a new…