IcedID is a malware family tracked across 8 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity July 1, 2026.
IcedID is a banking Trojan family known for its modular loader and web-inject capabilities, used to steal financial credentials and deploy additional payloads. It has evolved into a versatile platform that can drop and monetize other malware, making it a persistent threat in financial-targeted operations. Its significance lies in combining credential theft, browser web-injects, and loader functionality to enable broader cybercrime campaigns.
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
Malware developers have successfully bypassed Google's App-Bound Encryption (ABE) in Chrome, allowing infostealers like VoidStealer to access sensitive data such as session cookies and credentials. This new method…
Aleksei Volkov, a 26-year-old Russian citizen, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks against U.S. companies, including the Yanluowang group.…
Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…
Law enforcement from nine countries has dismantled over 1,000 servers associated with the Rhadamanthys infostealer, VenomRAT remote access Trojan, and Elysium botnet during Operation Endgame. This operation, coordinated…
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting…
Europol and law enforcement agencies from 11 countries executed Operation Endgame 3.0 from November 10 to 13, 2025, dismantling the infrastructure of three major malware operations: Rhadamanthys, VenomRAT, and Elysium.…