In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Recent investigations revealed two significant cybersecurity incidents involving compromised WordPress sites. The first incident involved a Turkish-speaking threat actor using a fake plugin to drop dual PHP web shells…
The Makop ransomware, a variant of the Phobos family, has been updated to include GuLoader malware for enhanced payload delivery. Recent attacks have primarily targeted Indian businesses, utilizing Remote Desktop…
A new phishing campaign is distributing Guloader malware through emails that appear to be employee performance reports for October 2025. The emails claim to inform recipients about potential dismissals, prompting them…
GuLoader, also known as CloudEyE, has become a persistent threat in cybersecurity, functioning primarily as a downloader for secondary malware payloads. It retrieves and executes various malicious software, including…
ESET's Threat Report for H2 2025 reveals the emergence of AI-driven malware, specifically PromptLock, the first known AI-driven ransomware capable of generating malicious scripts in real-time. This development marks a…