T1027 - Steganography is a mitre_attack tracked across 8 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 2, 2025; most recent activity December 16, 2025.
A new strain of .NET malware has been identified that embeds Lokibot malware within PNG and BMP files, allowing it to bypass traditional detection methods. This sophisticated technique poses risks to users who may…
A campaign named 'GhostPoster' has embedded malicious JavaScript in the icons of 17 Firefox extensions, which have been downloaded over 50,000 times. This malware facilitates browser activity tracking and allows…
The Open VSX registry faced a supply chain attack after access tokens were leaked, allowing threat actors to publish malicious extensions. The GlassWorm malware campaign has returned with new extensions targeting…
The Open VSX registry experienced a security incident where access tokens were leaked by developers in public repositories. This exposure allowed threat actors to publish malicious extensions, affecting projects with…
The ClickFix malware has evolved to utilize videos, timers, and OS-specific tricks to deceive users into self-infection. This campaign leverages social engineering tactics to manipulate victims into executing malicious…
A new wave of ClickFix attacks is utilizing fake Windows Update screens to deceive users into executing malicious commands that install infostealing malware. These attacks employ steganography to hide malware within PNG…
A new variant of .NET malware has been identified, utilizing steganography to conceal Lokibot malware within PNG and BMP files. This advanced evasion technique allows the malware to bypass detection mechanisms, posing…
Xillen Stealer has evolved to version 5, incorporating advanced AI features that enable it to evade detection and target sensitive data from password managers. The malware now includes aggressive capabilities aimed at…