Frequency
4
occurrences
First Seen
April 27, 2026
Last Seen
July 30, 2026
Related Threat Clusters
-
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing
The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the…
5 articles · Updated July 30, 2026 -
InstallFix Campaign Exploits AI Trust to Deliver Malware via Fake Install Pages
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
53 articles · Updated May 5, 2026 -
macOS textutil and KeePassXC Vulnerabilities in Automated Workflows
Security researchers have identified that macOS's textutil and KeePassXC can be exploited when integrated into automated workflows that process attacker-controlled input. This issue does not stem from traditional…
2 articles · Updated April 27, 2026
Recent Intelligence Reports
- Toy Ghouls’ new toy: the GenieLocker ransomware — Securelist · July 30, 2026
- SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer — Blog.Eclecticiq · May 21, 2026
- Researchers Warn macOS textutil and KeePassXC Can Become Attack Primitives in Automation — Cybersecuritynews · April 27, 2026
- Researchers Warn macOS textutil, KeePassXC Can Fuel Automation Attacks — Gbhackers · April 27, 2026