Smokeloader is a malware family tracked across 9 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity June 24, 2026.
Smokeloader is a Windows-based loader/malware family that serves as a delivery framework to deploy additional payloads (such as RATs and credential-stealers) onto compromised hosts. Its modular design and ability to fetch and execute extra modules from command-and-control infrastructures make it a significant facilitator in broader malware campaigns and persistence operations.
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
Two phishing campaigns have been identified targeting organizations in Greece, Spain, Slovenia, Bosnia, Croatia, and several South American countries, aiming to deliver the Formbook infostealer malware. The first…
Malware developers have successfully bypassed Google's App-Bound Encryption (ABE) in Chrome, allowing infostealers like VoidStealer to access sensitive data such as session cookies and credentials. This new method…
Researchers have discovered a vulnerability in Notepad's newly added Markdown support that can be exploited for remote code execution (RCE). This flaw, tracked as CVE-2026-20841 with a severity score of 8.8, was…
Recent arrests of cybercriminals in Russia indicate a changing landscape for cybercrime, traditionally tolerated by the state as long as domestic interests were not targeted. The ongoing Operation Endgame, initiated in…
Interpol's Operation Sentinel resulted in the arrest of 574 individuals across several African countries, targeting cybercriminal activities including business email compromise, digital extortion, and ransomware. The…
Law enforcement from nine countries has dismantled over 1,000 servers associated with the Rhadamanthys infostealer, VenomRAT remote access Trojan, and Elysium botnet during Operation Endgame. This operation, coordinated…
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting…
Europol and law enforcement agencies from 11 countries executed Operation Endgame 3.0 from November 10 to 13, 2025, dismantling the infrastructure of three major malware operations: Rhadamanthys, VenomRAT, and Elysium.…