Related Threat Clusters
-
Malicious Background Removal Tool Distributes RATs and Infostealers
A new cyber threat identified by Huntress involves a fake background removal website that tricks users into executing malicious commands. Dubbed BackgroundFix, this site masquerades as a free image-editing service,…
3 articles · Updated May 1, 2026 -
Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App
A malvertising campaign, dubbed FakeAgent, exploited Bing ads to distribute the SectopRAT malware through a fake Claude desktop app. Between July 21 and July 22, 2026, at least 29 organizations were compromised after…
7 articles · Updated July 23, 2026 -
MSHTA Utility Exploited in Ongoing Malware Campaigns
Bitdefender researchers have identified that the Microsoft HTML Application Host (MSHTA) utility is being actively exploited by cybercriminals to deliver a variety of malware, including infostealers and loaders. Despite…
8 articles · Updated May 19, 2026 -
CastleLoader Campaign Uses NeedleStealer to Target Crypto Users
The CastleLoader malware campaign has evolved, deploying the NeedleStealer framework to steal cryptocurrency wallet seed phrases and hijack browser sessions. This operation targets Windows devices through fake software…
2 articles · Updated July 28, 2026 -
Iran's Cyber Response to U.S. Military Strikes Expected Amid Rising Tensions
Following U.S. military strikes on Iran, there is an anticipated increase in cyber warfare activities targeting U.S. operational technology and critical infrastructure. Iran is expected to retaliate with cyber attacks…
767 articles · Updated February 28, 2026 -
CastleLoader Malware Targets U.S. Government Entities
CastleLoader, a sophisticated malware loader, has been identified as a significant threat to U.S. government agencies and critical infrastructure. This malware is designed to facilitate further attacks by loading…
3 articles · Updated January 14, 2026 -
UK Retail Cyber Attacks Show No Seasonal Spike Amid Holiday Concerns
Analysis of cybersecurity incidents in the UK retail and manufacturing sectors reveals that 1,381 breaches occurred between Q3 2024 and Q2 2025, with no significant concentration around major shopping events. Security…
61 articles · Updated November 28, 2025 -
LummaStealer Infections Rise Following CastleLoader Campaigns
LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously…
7 articles · Updated February 11, 2026 -
CastleLoader Malware Expands Operations Targeting Logistics and Hospitality Sectors
GrayBravo, previously known as TAG-150, has expanded its CastleLoader malware deployment across four distinct threat activity clusters since March 2025. The malware targets industries such as logistics and hospitality,…
2 articles · Updated December 11, 2025 -
ClickFix Attack Wave Targets Windows Users with StealC Malware
A new social engineering campaign named ClickFix is targeting Windows users by presenting fake CAPTCHA verification pages. Victims are led to compromised websites that display fraudulent Cloudflare security checks,…
221 articles · Updated February 13, 2026
Recent Intelligence Reports
- Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions — Cybersecuritynews · July 28, 2026
- CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions — Gbhackers · July 28, 2026
- Fake Claude app promoted by Bing ads pushes SectopRAT malware — Bleepingcomputer · July 23, 2026
- Microsoft's MSHTA Legacy Tool Still Powers Malware Campaigns on Windows — Bitdefender · May 19, 2026
- This selfie background editor is a password-stealing trap — Cybernews · May 1, 2026
- ClickFix Removes Your Background but Leaves the Malware — Huntress · April 30, 2026
- Iranian MOIS Actors & the Cyber Crime Connection — Research.Checkpoint · March 10, 2026
- LummaStealer activity spikes post — Securityaffairs.Co · February 12, 2026