PyArmor is a tool tracked across 5 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed January 2, 2026; most recent activity July 4, 2026.
A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…
The JDownloader website was hacked between May 6 and May 7, 2026, to serve malicious installers for Windows and Linux users. Attackers replaced legitimate download links with malicious payloads, specifically targeting…
Infrawatch's investigation reveals that ProxySmart, a Belarus-based software platform, is enabling the operation of 87 SIM farms across 17 countries, including 94 locations in the U.S., Europe, and South America. These…
VVS Stealer is a Python-based malware designed to steal Discord credentials and tokens. It has been available for purchase on Telegram since at least April 2025, posing a risk to Discord users. Palo Alto Networks…
VVS Stealer, a Python-based malware family, has been marketed on Telegram since April 2025. This malware specifically targets Discord users to exfiltrate sensitive credentials, tokens, and browser data while utilizing…