UAC-0184 has deployed a multi-stage malware chain that utilizes the Windows bitsadmin tool and HTA files to deliver obfuscated payloads. This campaign primarily targets Ukrainian military networks, specifically accounts…
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
The DragonForce ransomware group has been observed using a custom malware, Backdoor.Turn, to conceal command-and-control (C&C) traffic within Microsoft Teams' relay infrastructure. This sophisticated technique allows…
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
OnyxC2 Stealer has emerged as a significant Malware-as-a-Service (MaaS) threat, targeting over 210 applications for credential theft and remote access. Sold for as low as $250 per month, it employs sophisticated evasion…
A sophisticated cyber campaign is leveraging compromised websites and a malicious JavaScript file named transcript.pdf.js to deploy PureLog Stealer, a .NET-based infostealer. The attack uses a fileless infection method,…
A cyber campaign has emerged involving a fraudulent trading site named 'TradingClaw', which impersonates the legitimate TradingView platform. This site entices users to download malware known as 'Needle Stealer', an…
A new cryptojacking campaign is targeting high-performance PC users through malicious downloads disguised as trusted utilities. Attackers leverage SEO poisoning and AI chatbot manipulation to direct users to fake…
In May 2026, a malspam campaign utilizing the Google DoubleClick domain was identified, delivering the DesckVB remote access trojan (RAT). The attack begins with an HTML email attachment that redirects users through…