Brokewell Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 6, 2025
Last Seen
July 1, 2026

Brokewell is a malware family tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 1, 2026.

Overview

Brokewell is a malware family noted in the Weekly Intelligence Report dated 7 November 2025. It is characterized as a loader/dropper-style threat that can deliver additional payloads, contributing to ongoing risk for Windows environments and highlighting persistent activity by threat actors in 2025.

Related Threat Clusters

  • Glitch SPY RAT Targets Android Users via Fraudulent Rental Platform

    A new Android Remote Access Trojan (RAT) named Glitch SPY has emerged, exploiting a fraudulent Polish housing rental website to distribute a malicious APK. This malware, delivered through the Brokewell Android Loader,…

    2 articles · Updated July 1, 2026
  • Bactor Ransomware Identified in Cybersecurity Monitoring

    CYFIRMA Research and Advisory Team has identified Bactor Ransomware while monitoring underground forums. This ransomware targets Windows systems and affects multiple industries and technologies. The findings are part of…

    5 articles · Updated November 20, 2025
  • Emergence of New Ransomware Variants: Bactor, ChickenKiller, and Midnight

    Multiple ransomware strains, including Bactor, ChickenKiller, and Midnight, have been identified by CYFIRMA Research and Norton. Bactor and ChickenKiller ransomware target Windows systems, while Midnight ransomware has…

    7 articles · Updated November 27, 2025

Recent Intelligence Reports

  • Rapid Response: Zimperium Delivers Immediate Coverage for Emerging Glitch SPY RAT Campaign — Zimperium · July 1, 2026
  • Weekly Intelligence Report – 07 November 2025 — Cyfirma · November 6, 2025

CVSS v3.1 Breakdown