A Russian threat actor known as UAT-11795 has been deploying the Starland RAT and WLDR agent since June 2025, primarily targeting users in the U.S., Germany, Romania, and Venezuela. The group uses trojanized installers…
A new cyber threat identified by Huntress involves a fake background removal website that tricks users into executing malicious commands. Dubbed BackgroundFix, this site masquerades as a free image-editing service,…
A new Windows loader named OXLOADER is delivering the CASTLESTEALER infostealer through malicious Google Ads. This previously undocumented malware employs advanced obfuscation techniques and abuses the Windows .reloc…